[WordPress] 外掛分享: Disable XML-RPC – Dashboard Control

首頁外掛目錄 › Disable XML-RPC – Dashboard Control
WordPress 外掛 Disable XML-RPC – Dashboard Control 的封面圖片
全新外掛
安裝啟用
尚無評分
5 天前
最後更新
問題解決
WordPress 5.0+ PHP 7.4+ v1.0.4 上架:2026-01-23

內容簡介

此外掛允許用戶快速在控制台上開啟或關閉 XML-RPC 功能,並在安裝後預設禁用該功能。它顯示當前的啟用/禁用狀態,幫助用戶避免不必要的訪問,並提供 XML-RPC 的速率限制功能以增強安全性。

【主要功能】
• 快速開關 XML-RPC 功能
• 顯示當前狀態於控制台
• 預設禁用 XML-RPC 功能
• 提供速率限制保護
• 不收集或傳輸用戶數據

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.0.4) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Disable XML-RPC – Dashboard Control」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

This plugin allows you to quickly toggle on/off XML-RPC functionality from the Dashboard
On initial installation and activation, XML-RPC will be disabled,
It displays the current enabled/disabled status in the dashboard, helping users avoid leaving access on unnecessarily.
It features XML-RPC rate limiting functionality, providing some protection to users while XML-RPC is on.
Rate limiting is on by default, but can be turned off. Note that it’s not perfect security however, and we recommend XML-RPC is disabled after use.

Why Control XML-RPC?
XML-RPC is a WordPress feature that allows remote access to your site. While useful for legitimate applications like mobile apps and remote publishing, it’s frequently exploited for:

Brute force password attacks
DDoS amplification attacks via pingbacks
Spam distribution
Resource exhaustion

Rate Limiting Protection
When enabled, the plugin automatically limits:

Failed Authentication – Maximum 5 failed login attempts per hour per IP
High-Risk Methods – Limits on pingback.ping, system.multicall, and other abuse-prone methods
IP Validation – Validates addresses and processes proxy headers correctly. Sites where the client connects directly are protected against IP spoofing automatically; sites behind a reverse proxy or CDN can declare their proxies via the xmlrpc_control_trusted_proxies filter so forwarded headers are only trusted from those addresses

Privacy
This plugin does not collect, store, or transmit any user data outside your WordPress installation. All rate limiting data is stored temporarily using WordPress transients and is automatically cleaned up.
Additional Information
Support
For support, feature requests, or bug reports, please visit the plugin’s support forum.
Contributing
Feedback is welcome.
Security
If you discover a security vulnerability, please report it responsibly via the WordPress security team or directly to the plugin author.

延伸相關外掛

文章
Filter
Mastodon