Remove XML-RPC Methods

外掛說明

Removes all WordPress methods from the XML-RPC API to increase security. It does more than just using the xmlrpc_enabled hook, because that is only used “To disable XML-RPC methods that require authentication”.

Activating this plugin will also disable pingbacks, trackbacks, and Really Simple Discovery (RSD), because these rely on XML-RPC.

It works with any webserver, because it does not use the .htaccess file.

Testing the plugin

From the command line you can test if the plugin is working correctly using curl. Replace the example.com link to match your website:

curl -d '<?xml version="1.0"?><methodCall><methodName>system.listMethods</methodName><params><param><value><string/></value></param></params></methodCall>' https://example.com/xmlrpc.php

This should only return the following methods:
system.multicall
system.listMethods
system.getCapabilities

安裝方式

  1. Download the plugin and unzip it. Copy the files to the /wp-content/plugins/wee-remove-xmlrpc-methods directory
  2. Activate the plugin through the ‘Plugins’ menu in WordPress

使用者評論

2020 年 5 月 1 日
Seems to work as expected.
閱讀全部 2 則使用者評論

參與者及開發者

以下人員參與了開源軟體〈Remove XML-RPC Methods〉的開發相關工作。

參與者

將〈Remove XML-RPC Methods〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄

變更記錄

1.4.2

  • Updated description
  • Tested WordPress up to version 7.0.

1.4.1

  • Updated description and tags

1.4.0

  • Tested with PHP 8.0
  • Tested WordPress up to version 5.6.

1.3.1

  • Correct description

1.3.0

  • Replace PHP header function with http_response_code.
  • Update readme.txt.
  • Raise minimal supported WordPress version to 4.6.
  • Tested WordPress up to version 5.5.

1.2.0

  • Replace pings_open action function with built-in function.
  • Increase pings_open action priority.
  • Raise minimal supported WordPress version to 4.4.
  • Tested WordPress up to version 5.4.

1.1.0

  • Deactivate pingbacks on install.
  • Remove RSD link reference.