Manage XML-RPC
View on WordPress.orgScores higher than 1% of indexed plugins
About
Enable/Disable XML-RPC for all or based on IP list, also you can control pingback and Unset X-Pingback from HTTP headers.
What It Does
Manage XML-RPC lets administrators globally enable or disable WordPress's xmlrpc.php endpoint, restrict access by IP address, and remove the X-Pingback header to suppress pingback-based abuse. In practice, it is a single-purpose hardening tool aimed at closing a long-standing brute force and DDoS amplification vector on sites that do not need remote publishing or pingback functionality.
Who It's For
This plugin fits security-focused administrators on small to medium WordPress sites that do not rely on the WordPress mobile app, Jetpack, or remote blogging tools, and who want a lightweight, targeted fix for xmlrpc.php attacks. It also suits multi-author blogs tired of pingback spam and operators wanting IP-level allowlisting without deploying a full firewall.
Who Should Skip It
Anyone already running a modern security suite such as Wordfence, Really Simple Security, or All-In-One Security should skip this plugin since those tools ship XML-RPC controls alongside brute force protection, malware scanning, and firewalls. Sites that legitimately use Jetpack, the WordPress mobile app, or pingbacks for legitimate cross-linking should also avoid disabling the endpoint entirely.
The Bottom Line
Manage XML-RPC is a small, focused utility that does one job and was updated recently, but its 45.14 overall quality score, near-empty ratings pool, and zero support history make it hard to recommend over mainstream suites. Use it only if you want the lightest possible toggle for xmlrpc.php without pulling in a full security plugin.
Related Plugins
Pick this if you want XML-RPC controls bundled with broader SSL and hardening features and a far larger install base of 3 million.
Pick this if you need a full firewall, malware scanning, and login throttling alongside XML-RPC blocking, with 5 million installs backing the ecosystem.
Pick this if your site actually uses Jetpack or the WordPress mobile app and you still want managed security, since disabling XML-RPC would break Jetpack.
Pick this if you want a free, full-featured security plugin with login lockdown, firewall rules, and XML-RPC controls without a paid tier.
Listed as a category alternative here only loosely; Safe SVG addresses a different problem (SVG sanitization) and would not be a substitute.