On This Page
On This Page
Disable XML-RPC
Overview
Closes XML-RPC: blocks xmlrpc.php, empties methods, and removes RSD/WLW links and X-Pingback. Fine for most modern sites. Skip if you rely on Jetpack, legacy mobile apps, or remote publishing that needs XML-RPC—the enable confirm warns about that. Soft overlap with Disable Trackbacks/Pingbacks (ping subset) and Limit Login Attempts (still covers XML-RPC if left open).

- Most modern sites as a free baseline
- Teams reducing password-guessing surface
- Not Jetpack-dependent or legacy remote-publishing installs
Features
Block xmlrpc.php
Empty methods
Discovery cleanup
Enable confirmation
Zero ongoing settings
Use Cases
- Brute-force surface reductionClose XML-RPC on brochure and content sites.
- Agency hardening packDefault-on for clients not using Jetpack.
- Pair with Limit Login AttemptsIf you must keep XML-RPC, rate-limit failures instead.
Frequently Asked Questions
What does Disable XML-RPC do in WP PowerSuite?
It closes the old XML-RPC channel many password-guessing tools still target.
How do I enable Disable XML-RPC in WP PowerSuite?
Enable the module after confirming you do not need Jetpack, legacy apps, or remote publishing over XML-RPC.
Who should use Disable XML-RPC?
Most modern WordPress sites that do not rely on XML-RPC integrations.
Will it break Jetpack?
It can. Skip this module if Jetpack or similar tools need XML-RPC.
Is Disable XML-RPC a free or Pro module in WP PowerSuite?
It is included (free) with WP PowerSuite.

