Census › Plugin profiles › Disable XML-RPC
Disable XML-RPC
Figures from the Plugin Directory Census · as of 28 Aug 2026
200,000
Active installs, lower bound
Group: 100,000 to 999,999 installs
92
Days since the last release
Group median: 12
4.2
out of 5, from 33 ratings
Group median: 4.7 (10+ ratings)
no threads
Support threads, two months
Group: 68.2%
Full profile on wordpress.orgShow on the mapCompare with your own plugins
What is Disable XML-RPC and who is behind it?
Disable XML-RPC is a WordPress plugin in the “Security” field, made by Phil Erb. It has been listed in the directory since 28 Sept 2012, so for 13 years. It is the only plugin by Phil Erb with at least 10,000 installs. With 200,000 to 299,999 active installs it belongs to the 100,000 to 999,999 installs group; its last release came 92 days before the reference date, and it is tested up to WordPress 7.0.
This is how the author describes the plugin on wordpress.org:
“Disables the XML-RPC API in WordPress 3.5+, which is enabled by default.”
Self-description on wordpress.org, retrieved on 10 Sept 2026
When was Disable XML-RPC last released?
The last release of Disable XML-RPC came 92 days before the reference date; the group median is 12 days.
How many installs does Disable XML-RPC have?
Disable XML-RPC had 200,000 to 299,999 active installs on the reference date. Within its group, 139 plugins had a higher band and 79 plugins the same band.
The API reports installs only as a lower bound with one significant figure: 200,000 means at least 200,000 and at most 299,999.
Which WordPress version is Disable XML-RPC tested with?
No directory notice: tested up to WordPress 7.0, while core stood at 7.1 on the reference date. The notice appears once the field falls below 6.9; that applied to 8.0% of the group.
How does Disable XML-RPC compare with its group?
The group holds 399 listed plugins. 82.5% of them had a more recent last release than Disable XML-RPC; 5.3% had no release for more than 365 days.
| Figure | Disable XML-RPC | Group, 399 plugins |
|---|---|---|
| Days since the last release | 92 | median 12 |
| Rating | 4.2 (33) | median 4.7 (10+ ratings) |
| Support threads marked resolved | not stated | 68.2% |
| Tested up to | 7.0 | 47.6% on 7.1 |
| Requires PHP | not stated | most often 7.4 (41.6%) |
All values on the reference date
| Slug | disable-xml-rpc |
|---|---|
| Author | Phil Erb |
| Active installs | 200,000 to 299,999 |
| Last release | 92 days before the reference date |
| Tested up to | WordPress 7.0 · core on the reference date: 7.1 |
| Requires WordPress | 3.5 |
| Requires PHP | not stated |
| Rating | 4.2 out of 5 from 33 ratings |
| Support threads, two months | none in the window |
| Listed since | 28 Sept 2012 |
| Total downloads | 658,401, updates included |
| Tags | xmlrpc |
Tags
| Tag | Plugins with 10,000+ installs and this tag | Rank by installs | Median days since release |
|---|---|---|---|
| xmlrpc | 2 | 1 | 149 |
Rank 1 has the highest installation band among plugins with 10,000+ installs and this tag; equal bands share a rank.
Class of 2012
Disable XML-RPC has been listed since 28 Sept 2012. Of the 139 plugins with 10,000+ installs added in 2012, 78.4% released within the 365 days before the reference date.
Same group, shared tags
Not a recommendation; the same figures for comparison. Alphabetical.
| Plugin | Active installs | Last release | Rating |
|---|---|---|---|
| Disable XML-RPC-API | 100,000 to 199,999 | 205 days before the reference date | 4.2 (43) |
Do you maintain Disable XML-RPC?
If you maintain Disable XML-RPC, you can link to this profile, for example from your readme or your website. Both snippets show this badge:
HTML
<a href="https://hafenstudios.com/en/census/plugins/disable-xml-rpc/"><img src="https://hafenstudios.com/census/plugins/badge-en.svg" alt="Disable XML-RPC in the Plugin Directory Census 01/2026" width="220" height="40"></a>
Markdown
[](https://hafenstudios.com/en/census/plugins/disable-xml-rpc/)
The image is loaded from hafenstudios.com; as with every request, our server records the usual access data, which is deleted after 14 days. If you prefer not to, use a plain text link.
A value is wrong? Write to moin@hafenstudios.com; a documented correction leads to a new version.
How to cite
hafenstudios (2026): Disable XML-RPC, profile in the Plugin Directory Census 01/2026, reference date 28 Aug 2026. https://hafenstudios.com/en/census/plugins/disable-xml-rpc/
Source and status
All values come from the full pull of the public wordpress.org API on 28 Aug 2026 (reference time 21:56:30 UTC). The analysis and text on this page are available under CC BY 4.0; the raw values come from the public wordpress.org API and are in the raw data. How the count was made is set out in the method, what the fields do not say under limits. hafenstudios builds WordPress plugins itself, see the conflict of interest. Corrections to moin@hafenstudios.com; a documented correction leads to a new version. From issue 02 this page will also show the change since the previous reference date. Collected and prepared by Horst Wenzel.
Plugin names and trademarks belong to their owners. hafenstudios is not affiliated with the authors named here.