XML-RPC controls affect remote publishing clients and other integrations that communicate with WordPress through the XML-RPC endpoint. Disable XML-RPC version 1.0.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65709. The review focused on plugin bootstrap behavior, filter registration, XML-RPC availability, activation state, compatibility with the WordPress request path, and the absence of unnecessary user input surfaces.

Name ofDisable XML-RPC
Version1.0.1
Active installations200,000+
DescriptionDisables the WordPress XML-RPC API through the built-in xmlrpc_enabled filter while the plugin is active, without adding an administration interface.
SecuritySuccessfully tested for:
SQL Injection (SQLi)
Cross-Site Scripting (XSS) – Stored and Reflected
Cross-Site Request Forgery (CSRF)
Authentication Vulnerabilities
Authentication Bypass Exploits
Privilege Escalation
Buffer Overflow
Denial-of-Service (DoS) vectors
Data Leakage Vulnerabilities
Insecure Dependency Usage
Remote Code Execution (RCE) Risks
Unauthorized File Access
Insufficient Injection Protection
Information Disclosure via Misconfigured Endpoints
CleanTalk CertificationProudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards.
Additional InformationUse Disable XML-RPC with confidence backed by the “Plugin Security Certification” (PSC). Confirm that remote publishing, mobile applications, and other integrations do not depend on XML-RPC before activation, then retest after changes to themes or other security plugins.
Plugin Security Certification by CleanTalk
Logo of the plugin

Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.

PSC by Cleantalk

Key Features

Disable XML-RPC uses the built-in WordPress xmlrpc_enabled filter to disable XML-RPC methods while the plugin is active. It has no settings screen and requires no configuration. Deactivating the plugin restores the normal WordPress behavior unless another plugin, a theme function, or the web server also changes access to XML-RPC.

Security Assurance

The CleanTalk Plugin Security Certification evaluation examined the plugin bootstrap path, callback registration, the value returned through the WordPress filter, behavior during XML-RPC requests, activation and deactivation expectations, and the deliberately minimal surface with no settings forms, stored options, uploads, or visitor supplied parameters.

The plugin has been successfully tested for:

✅ Information Leakage Vulnerabilities

✅ SQL Injection Vulnerabilities

✅ Cross-Site Scripting (XSS) Attacks

✅ Cross-Site Request Forgery (CSRF) Attacks

✅ Authentication and Authentication Bypass Vulnerabilities

✅ Privilege Escalation Vulnerabilities

✅ Buffer Overflow Vulnerabilities

✅ Denial-of-Service (DoS) Vulnerabilities

✅ Data Leakage Vulnerabilities

✅ Insecure Dependencies

✅ Code Execution Vulnerabilities

✅ File Unauthorized Access Vulnerabilities

✅ Insufficient Injection Protection

Conclusion

With PSC-2026-65709, Disable XML-RPC version 1.0.1 demonstrates a strong security baseline for its focused task of disabling WordPress XML-RPC methods. The certification covers plugin loading, filter behavior, activation state, the XML-RPC request path, and the absence of extra input or administration surfaces. Site owners should verify dependent clients before activation and remember that server rules or other code can independently affect the endpoint.

Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.

Plugin Security Certification (PSC-2026-65709): “Disable XML-RPC” – Version 1.0.1

Dmitrii I

Pentester with 5 years of hands-on experience securing WordPress and web applications, holding OSWE, OSEP, OSCP, and OSWP certifications. Author of 450 published CVEs, including 35 disclosed within the last month. Specializes in discovering and validating high-impact vulnerabilities in WordPress plugins/themes / Custom WEB applications and delivering actionable remediation guidance to harden production sites.

Visit Author's Website

See all posts by dmitrii-ignatyev

Leave a Reply

Your email address will not be published. Required fields are marked *