plugin-icon

stop XML-RPC Attacks

Secure your site's XML-RPC by removing some methods, while you can still use XML-RPC.
Ratings
5
Last updated
November 18, 2023
Version
1.0.1
Active installations
6K
stop XML-RPC Attacks

Secure your site’s XML-RPC by removing some methods, instead of disabling totally XML-RPC, which is needed by some plugins (eg. Jetpack) and some mobile apps.

Features

Removes the following methods from XML-RPC interface.

  • system.multicall
  • system.listMethods
  • system.getCapabilities
  • pingback.extensions.getPingbacks
  • pingback.ping
  • X-Pingback from HTTP headers

This is not perfect, but it will help prerventing attacks

Requirements

  • WordPress 5.0 or higher.
Freeon Creator plan
Active installations
6K
Tested up to
6.4.4
This plugin is available for download to be used on your WordPress self-hosted installation.