=== Disable XML-RPC ===
Contributors: storeprose
Donate link: https://ko-fi.com/storeprose
Tags: disable xml-rpc, xmlrpc
Requires at least: 5.0
Tested up to: 6.7.1
Stable tag: 1.0.2
Requires PHP: 7.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html
WordShield is a lightweight plugin that disables XML-RPC, hides generator tags and disables PHP editors to secure WordPress. Supports Jetpack.
== Description ==
WordShield Security is a comprehensive WordPress security plugin that protects your website from the most common vulnerabilities and cyber attacks. It is a lightweight plugin that disables XML-RPC, hides generator tags, and disables PHP editors to secure WordPress.
**Live Demo** - You can preview the complete plugin functionality in the WordPress Playground using the Live Preview button.
##Why do you need a Security Plugin for WordPress?
If you are online, you are vulnerable to cyber-attacks and threats. However since WordPress is the leading CMS available today, bad players are always looking for ways to exploit a website powered by WordPress.
Automated attacks by bots or manual attacks singled on your website or business make your site vulnerable. This is why you need a comprehensive security plugin like WordShield Security to protect your digital assets.
## What is the difference between WordShield Security and other Security plugins?
Every WordPress plugin adds some overhead to the website and impacts its performance. We know this, so we have coded this WordPress security plugin carefully and cautiously.
Some of the key features of this plugin are:
🔥 WordShield security has absolutely **zero** bloat.
🔥 WordShield Security is lightweight and ultrafast. ***It added only 0.001 seconds of execution time in our internal testing.***
🔥 It follows the WordPress best practices and does not modify any Core File.
🔥 WordShield Security never touches your .htaccess. It protects your website in a fail-safe way.
##Features of WordShield Security
You can take care of the following security aspects of your WordPress assets by activating this WordPress Security plugin.
###Disable XML-RPC
Enabling XML-RPC makes your web property vulnerable to remote code injection. An attacker can easily exploit this weakness to execute arbitrary commands or code in the webserver, facilitating various attacks including unauthorized remote access.
XML-RPC is enabled by default in a WordPress installation. You can protect your website from the XML-RPC vulnerability by ticking a checkbox in the plugin's settings.
With this WordPress Security plugin, you can:
✅ Disable XML-RPC API calls completely.
✅ Continue to use **Jetpack** even after disabling the XML RPC on your website.
✅ Add a comma-separated list of Whitelisted IPs and allow access to XML-RPC API for specific apps, plugins, and websites.
###Hide Generator tags
WordPress and WooCommerce include the generator tags by default. However, this has a serious security impact as potential attackers can easily identify the specific version of WordPress (or WooCommerce) you are using. This can expose vulnerabilities and make your site more susceptible to hacking attempts.
Using WordShield Security, you can easily remove the generator tags and mask your website's technical details from public view.
###Disable PHP Editing and Theme Changes
Nobody wants to break a live website by accidentally updating the themes and plugins from the WordPress Admin dashboard.
WordShield Security plugin lets you:
✅ Disable PHP editing to prevent theme and plugin file updates.
✅ Hide the **Appearance Menu** from your WordPress admin area and prevent accidental changes in the theme or front-end.
###Note:
📢 The current version of the WordShield Security plugin does not work in a multisite environment.
##Upcoming Features
Here are some of the upcoming features of this WordPress security plugin:
👉 Limit login attempts.
👉 Add security headers.
👉 Change default login URL.
👉 Username audits.
👉 Enforce password policies.
👉 Stop user enumerations.
👉 Support for multisite.
👉 IP Ban.
👉 Prevent code execution.
👉 Backup & Restore.
👉 Logs, Notifications, and more!
##Maintenance and Support
This extension is well-supported and tested for compatibility with each WordPress upgrade.
== Installation ==
This section describes how to install the plugin and get it working.
1. Install the plugin directly through the WordPress plugin directory.
2. Activate it.
3. Configure the plugin functionality using the Settings panel.
== Frequently Asked Questions ==
= How do I know that XML-RPC is disabled on my website? =
After selecting the appropriate option on the Settings panel to disable XML-RPC on your website, head over to an XML-RPC validation service like xmlrpc.blog. Key in your website URL and test!
= How do I know that Jetpack will work even if XML-RPC is disabled on my website? =
Ensure that you have allowed access to XML-RPC by JetPack in the settings. Then head over to https://jptools.wordpress.com/debug/ and check.
= The changes made in the plugin settings do not seem to reflect. Why? =
This may happen because of some extreme cache mechanisms by your Cache plugin or CDN provider. Please clear the cache and check again.
= Can I use this plugin in a multisite environment? =
The current version of the WordShield Security plugin does not support Multisite.
However, this feature is in our future roadmap.
= Whom to contact for any support? =
Please log a support request on the plugin support page. We will respond as soon as possible.
= I am looking for a new feature. How do I request a new feature for this plugin? =
We would love to hear your ideas on enhancing this WordPress security plugin. Please log a request on the plugin support page. We will respond as soon as possible.
== Screenshots ==
1. XML-RPC settings of the WordShield security plugin.
2. Extra security settings
== Changelog ==
**12 Jan 2025 - Version 1.0.2**
* Whitelist IPs and enable access to XML-RPC API for specific apps, plugins, and websites.
**10 Jan 2025 - Version 1.0.1**
* Enable XML-RPC support for JetPack
* Disable theme switch
**08 Jan 2025 - Version 1.0.0**
* Disable XML-RPC
* Hide WordPress and WooCommerce generator tags
* Disable PHP file editing.
== Upgrade Notice ==
= 1.0.2 =
Enhancement - Whitelist IPs for XML RPC API.
= 1.0.1 =
Enhancement - Support for JetPack XML-RPC calls, Disable theme changes
=1.0.0 =
Initial version - Disable XML-RPC, Hide WordPress/ WooCommerce generator tags, Disable PHP editing