Opens in a new tab
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background
[wpps_ai_summarize]
On This Page
Last updated: 01/09/2026

Disable Trackbacks/Pingbacks

Stops old-style trackbacks and pingbacks that often bring spam or junk alerts.

Overview

Disable WordPress trackbacks and pingbacks when your website does not use legacy blog-to-blog notifications.

Disable Trackbacks/Pingbacks stops incoming trackbacks and pingbacks, prevents WordPress from sending outbound ping notifications, removes the related XML-RPC pingback methods, blocks direct trackback requests, and cleans up pingback discovery and editing interfaces.

Unlike completely disabling XML-RPC, this module targets only trackback and pingback functionality. Other XML-RPC features remain available if your website still needs them.

Disable Trackbacks/Pingbacks is a Free security module in WP PowerSuite.

Solid black square
Solid black square
Who is this for?
  • WordPress websites that do not use trackbacks or pingbacks
  • Blogs that want to reduce unwanted pingback and trackback activity
  • Agencies removing unnecessary legacy WordPress functionality from client sites
  • Sites that still need XML-RPC but do not need its pingback methods
  • Security-conscious administrators reducing unused public WordPress endpoints

Features

Disable Incoming Pingbacks & Trackbacks
Prevent WordPress posts from accepting new pingbacks and trackbacks while the module is active.
Block wp-trackback.php
Direct requests to the WordPress wp-trackback.php endpoint receive an immediate HTTP 403 response.
Disable XML-RPC Pingback Methods
Remove pingback.ping and pingback.extensions.getPingbacks without disabling unrelated XML-RPC functionality.
Remove Pingback Discovery
Prevent WordPress from advertising or discovering its pingback endpoint and remove X-Pingback response headers.

What Are WordPress Trackbacks and Pingbacks?

Trackbacks and pingbacks are older WordPress features designed to let websites notify each other when one site links to content on another.
The original idea was useful for blogging communities. If another website referenced one of your articles, WordPress could receive a notification and potentially display that reference alongside the post's comments. Likewise, when you linked to another compatible website, WordPress could notify that site automatically.
Pingbacks automated much of this process through XML-RPC, while trackbacks provided an older, more manual notification mechanism.
For websites that still intentionally use this form of blog-to-blog communication, the functionality can remain useful. However, many modern business sites, WooCommerce stores, portfolios, publications, and even ordinary blogs no longer depend on trackbacks or pingbacks at all.
When your website has no use for them, Disable Trackbacks/Pingbacks removes the functionality at the WordPress level instead of simply hiding a Discussion setting.

Stop Incoming and Outgoing Pingback Activity

Completely disabling trackbacks and pingbacks requires handling both directions of communication.
For incoming requests, WP PowerSuite forces ping support closed so WordPress does not accept new pingbacks or trackbacks on posts. Direct requests to the legacy wp-trackback.php endpoint are also blocked with an HTTP 403 response instead of being allowed to reach the normal trackback handler.
For outgoing activity, WP PowerSuite clears the list of URLs WordPress would normally attempt to ping after content is published. This prevents your website from automatically contacting other sites merely because you linked to one of their pages.
The result is a more complete shutdown of the feature. Your site stops accepting these notifications and also stops generating them for other websites.

Reduce Pingback Spam and Unnecessary Requests

Pingbacks were created as a legitimate publishing feature, but public pingback functionality can also attract automated and unwanted requests.
Sites may receive low-value pingback notifications, spam, or requests that have little relationship to meaningful discussion around the original content. Even when these requests never become visible to visitors, WordPress still has to process the functionality associated with them.
If your site does not participate in pingback-based publishing, disabling the feature removes an unnecessary path for that traffic.
There have also historically been security concerns around abuse of WordPress pingback functionality. Disabling an unused pingback interface can therefore be a sensible hardening measure, particularly when there is no business or publishing requirement for it.
This should not be presented as a replacement for a firewall or broader WordPress security. It is simply a focused way to remove legacy functionality that your website does not need.

Remove Pingback Discovery From WordPress

Blocking incoming requests is more important than merely hiding information about the endpoint, but WordPress also exposes pingback-related discovery information that becomes unnecessary once the feature is disabled.
WP PowerSuite prevents pingback server discovery and strips the X-Pingback HTTP response header that WordPress can use to advertise its XML-RPC pingback endpoint.
This keeps the site's public response consistent with its actual configuration. If pingbacks have intentionally been turned off, there is little reason to continue advertising where a pingback request would normally be sent.
The module handles this cleanup automatically, with no separate discovery setting to configure.

Use Cases

  • Disable Pingbacks on a WordPress Blog
    Stop incoming and outgoing pingback notifications when they are no longer part of your publishing workflow.
  • Reduce Trackback and Pingback Spam
    Remove an unused public feature that may otherwise receive unwanted automated requests.

Frequently Asked Questions

Related Modules

Closes the old XML-RPC channel many password-guessing tools still target. Fine for most sites; skip if you rely on legacy apps or...
Disabled
Slow down password-guessing bots by locking out repeated failed logins for increasing cool-off periods—simple protection for your sign-in form.
Disabled
Always open your dashboard and login screen over a secure https:// link. Anyone using the old http:// address is sent to the...
Disabled
Allow or block visitors by IP address—ideal for office-only dashboards or shutting out known troublemakers. Rules apply site-wide, including wp-admin and login.
Disabled
Automatically protects visible email addresses and mailto links from basic spam bots by safely encoding them while keeping them clickable for visitors.
Disabled
Bot protection with Cloudflare Turnstile on logins, forms, comments, and WooCommerce—low hassle for real people.
Disabled
Keep a clear record of important dashboard activity—who logged in, what changed, and when—so you can investigate issues or stay audit-ready without...
Disabled
Remove the dashboard screens that let anyone edit theme or plugin code from the browser—one less disaster if an account is compromised.
Disabled
Put your whole site behind one shared password—ideal for staging, client previews, or a soft launch before you go public.
Disabled
Blocks risky default usernames during registration so bots have fewer easy targets.
Disabled