Security snapshot
Across the 11 disable-xml-rpc-pingback sites we've scanned, compared to the all-WordPress average.
Grade A 0%
Grade B 0%
Grade C 0%
Grade D 0%
Grade F 100%
Fail the header check (F)100%vs 82.6% avg
Leak usernames9%vs 38.5% avg
Expose a sensitive file0%vs 1.8% avg
Use HTTPS73%vs 96.1% avg
Disable XML-RPC Pingback
Stops abuse of your site’s XML-RPC by simply removing some methods used by attackers. While you can use the rest of XML-RPC methods.
This is more friendly than disabling totally XML-RPC, that it’s needed by some plugins and apps (I.e. Mobile apps or some Jetpack’s modules).
- The original one.
- Simple and effective.
- No marketing buzz.
- Maintained and updated when needed since 2014.
- 100% compliant with WordPress coding standards which makes it fail safe.
- 60,000+ active installations can’t be wrong.
If you’re happy with the plugin please don’t forget to give it a good rating, it will motivate me to keep sharing and improving this plugin (and others).
Features
Removes the following methods from XML-RPC interface.
- pingback.ping
- pingback.extensions.getPingbacks
- X-Pingback from HTTP headers. This will hopefully stops some bots from trying to hit your xmlrpc.php file.
Requirements
- WordPress 3.8.1 or higher.
| Domain | Exposures | Headers | Last Checked |
|---|---|---|---|
| r*g*n*y*6*.com (WP 6.8.8) | F | Sep 6, 2026 | |
| e*s*x*o*n*y*o*e*w*s*.com (WP 6.0.14) | F | Sep 3, 2026 | |
| e*i*e*e*u*y*e*a*l*.com | F | Aug 24, 2026 | |
| j*n*l*n*s*a*f*n*.com | F | Aug 24, 2026 | |
| p*c*a*w*b.com | F | Aug 24, 2026 | |
| b*n*r*p*c*r*d*e*r.com | F | Aug 16, 2026 | |
| b*n*r*p*c*b*n*y*i*l*.com | F | Aug 16, 2026 | |
| s*l*s*a*g.com | F | Jul 30, 2026 | |
| m*s*o*a*r*p*i*s.com | F | Jul 25, 2026 | |
| k*t*y*a*t*a*.com | F | Jul 18, 2026 | |
| k*t*y*a*a*d*i*a*.com | F | Jul 18, 2026 |
Page 1 of 1