CensusPlugin profiles › Disable XML-RPC-API

Disable XML-RPC-API

Figures from the Plugin Directory Census · as of 28 Aug 2026

100,000

Active installs, lower bound

Group: 100,000 to 999,999 installs

205

Days since the last release

Group median: 12

4.2

out of 5, from 43 ratings

Group median: 4.7 (10+ ratings)

no threads

Support threads, two months

Group: 68.2%

Full profile on wordpress.orgShow on the mapCompare with your own plugins

What is Disable XML-RPC-API and who is behind it?

Disable XML-RPC-API is a WordPress plugin in the “Security” field, made by Amin Nazemi. It has been listed in the directory since 1 Oct 2020, so for 5 years. It is the only plugin by Amin Nazemi with at least 10,000 installs. With 100,000 to 199,999 active installs it belongs to the 100,000 to 999,999 installs group; its last release came 205 days before the reference date, and it is tested up to WordPress 6.9.

This is how the author describes the plugin on wordpress.org:

“A simple and lightweight plugin to disable XML-RPC API, X-Pingback and pingback-ping in WordPress 3.5+ for a faster and more secure website”

Self-description on wordpress.org, retrieved on 10 Sept 2026

When was Disable XML-RPC-API last released?

The last release of Disable XML-RPC-API came 205 days before the reference date; the group median is 12 days.

Disable XML-RPC-API · 205 days today1 month3 months1 year3 years10 years
Each dot is a plugin in the 100,000 to 999,999 installs group, placed horizontally by days since its last release, on a logarithmic scale. The dashed line marks 365 days.

How many installs does Disable XML-RPC-API have?

Disable XML-RPC-API had 100,000 to 199,999 active installs on the reference date. Within its group, 219 plugins had a higher band and 179 plugins the same band.

The API reports installs only as a lower bound with one significant figure: 100,000 means at least 100,000 and at most 199,999.

Which WordPress version is Disable XML-RPC-API tested with?

No directory notice: tested up to WordPress 6.9, while core stood at 7.1 on the reference date. The notice appears once the field falls below 6.9; that applied to 8.0% of the group.

How does Disable XML-RPC-API compare with its group?

The group holds 399 listed plugins. 91.0% of them had a more recent last release than Disable XML-RPC-API; 5.3% had no release for more than 365 days.

FigureDisable XML-RPC-APIGroup, 399 plugins
Days since the last release205median 12
Rating4.2 (43)median 4.7 (10+ ratings)
Support threads marked resolvednot stated68.2%
Tested up to6.947.6% on 7.1
Requires PHPnot statedmost often 7.4 (41.6%)

All values on the reference date

Slugdisable-xml-rpc-api
AuthorAmin Nazemi
Active installs100,000 to 199,999
Last release205 days before the reference date
Tested up toWordPress 6.9 · core on the reference date: 7.1
Requires WordPress5.0
Requires PHPnot stated
Rating4.2 out of 5 from 43 ratings
Support threads, two monthsnone in the window
Listed since1 Oct 2020
Total downloads822,819, updates included
Tagsdisable-xml-rpc, disable-xmlrpc, pingback, stop-brute-force-attacks, xmlrpc

Tags

TagPlugins with 10,000+ installs and this tagRank by installsMedian days since release
disable-xml-rpc11205
disable-xmlrpc11205
pingback42107
stop-brute-force-attacks11205
xmlrpc22149

Rank 1 has the highest installation band among plugins with 10,000+ installs and this tag; equal bands share a rank.

Class of 2020

Disable XML-RPC-API has been listed since 1 Oct 2020. Of the 150 plugins with 10,000+ installs added in 2020, 87.3% released within the 365 days before the reference date.

Same group, shared tags

Not a recommendation; the same figures for comparison. Alphabetical.

PluginActive installsLast releaseRating
Disable XML-RPC200,000 to 299,99992 days before the reference date4.2 (33)
Disable XML-RPC Pingback60,000 to 69,999277 days before the reference date3.9 (14)
No Self Ping10,000 to 19,9998 days before the reference date4.5 (14)
SiteGuard WP Plugin600,000 to 699,9999 days before the reference date4.3 (15)

Do you maintain Disable XML-RPC-API?

If you maintain Disable XML-RPC-API, you can link to this profile, for example from your readme or your website. Both snippets show this badge:

Disable XML-RPC-API in the Plugin Directory Census 01/2026

HTML

<a href="https://hafenstudios.com/en/census/plugins/disable-xml-rpc-api/"><img src="https://hafenstudios.com/census/plugins/badge-en.svg" alt="Disable XML-RPC-API in the Plugin Directory Census 01/2026" width="220" height="40"></a>

Markdown

[![Disable XML-RPC-API in the Plugin Directory Census 01/2026](https://hafenstudios.com/census/plugins/badge-en.svg)](https://hafenstudios.com/en/census/plugins/disable-xml-rpc-api/)

The image is loaded from hafenstudios.com; as with every request, our server records the usual access data, which is deleted after 14 days. If you prefer not to, use a plain text link.

A value is wrong? Write to moin@hafenstudios.com; a documented correction leads to a new version.

How to cite

hafenstudios (2026): Disable XML-RPC-API, profile in the Plugin Directory Census 01/2026, reference date 28 Aug 2026. https://hafenstudios.com/en/census/plugins/disable-xml-rpc-api/

Source and status

All values come from the full pull of the public wordpress.org API on 28 Aug 2026 (reference time 21:56:30 UTC). The analysis and text on this page are available under CC BY 4.0; the raw values come from the public wordpress.org API and are in the raw data. How the count was made is set out in the method, what the fields do not say under limits. hafenstudios builds WordPress plugins itself, see the conflict of interest. Corrections to moin@hafenstudios.com; a documented correction leads to a new version. From issue 02 this page will also show the change since the previous reference date. Collected and prepared by Horst Wenzel.

Plugin names and trademarks belong to their owners. hafenstudios is not affiliated with the authors named here.