42 Quality Score
Active Installs
17/30

About 5,000 active installs is modest but reasonable for a single-purpose utility, reflecting a niche audience that knows it needs this specific fix.

Update Freshness
3/25

Last updated on December 2, 2024 and tested against WordPress 6.7.5, the plugin is actively maintained despite its narrow scope.

User Rating
7/15

A 60 out of 100 rating from only 4 reviewers is a thin sample, so the score signals average satisfaction rather than a meaningful trend.

Support Health
8/15

Zero support threads and zero resolutions mean there is no track record either way, which is a mild concern given how small the install base is.

WP Compatibility
8/15

Tested with WordPress 6.7.5 and compatible back to 4.0, though the unspecified minimum PHP version is a minor transparency gap.

Scores higher than 1% of indexed plugins

About

Enable/Disable XML-RPC for all or based on IP list, also you can control pingback and Unset X-Pingback from HTTP headers.

Active Installs 5k+
Rating ★★★ 3/5
Last Updated 2024-12-02 7:10am GMT
Requires WordPress 4.0+
Tested Up To 6.7.7
✓ No known vulnerabilities

What It Does

Manage XML-RPC lets administrators globally enable or disable WordPress's xmlrpc.php endpoint, restrict access by IP address, and remove the X-Pingback header to suppress pingback-based abuse. In practice, it is a single-purpose hardening tool aimed at closing a long-standing brute force and DDoS amplification vector on sites that do not need remote publishing or pingback functionality.

Who It's For

This plugin fits security-focused administrators on small to medium WordPress sites that do not rely on the WordPress mobile app, Jetpack, or remote blogging tools, and who want a lightweight, targeted fix for xmlrpc.php attacks. It also suits multi-author blogs tired of pingback spam and operators wanting IP-level allowlisting without deploying a full firewall.

Who Should Skip It

Anyone already running a modern security suite such as Wordfence, Really Simple Security, or All-In-One Security should skip this plugin since those tools ship XML-RPC controls alongside brute force protection, malware scanning, and firewalls. Sites that legitimately use Jetpack, the WordPress mobile app, or pingbacks for legitimate cross-linking should also avoid disabling the endpoint entirely.

The Bottom Line

Manage XML-RPC is a small, focused utility that does one job and was updated recently, but its 45.14 overall quality score, near-empty ratings pool, and zero support history make it hard to recommend over mainstream suites. Use it only if you want the lightest possible toggle for xmlrpc.php without pulling in a full security plugin.

Tags

block xml-rpc brute force attacks security xml-rpc pingback xmlrpc.php attack