Shield Security Pro Features

Disable XML-RPC & Anonymous REST API

Disable All Processing Of Unauthenticated REST API And XML-RPC Requests

Disabling requests to the REST API that aren't authenticated (i.e. username/password) eliminates abuse of the API. Disabling XML-RPC eliminates possible credential stuffing attacks and any XML-RPC attack vectors.

Feature Facts

ShieldFREE and ShieldPRO

Available in ShieldFREE and enhanced in ShieldPRO where applicable.

ShieldFREE and ShieldPRO

Availability

ShieldFREE and ShieldPRO

Best for

Brute Force Protection, Lockdown

Automation

Runs automatically with Shield defaults

Setup

Enable Shield and tune options when needed

The REST API is a modern API protocol that comes activated on all WordPress sites. Use Shield to eliminate abuse of it. XML-RPC is an older API protocol that comes activated on all WordPress sites. There’s no good reason to leave XML-RPC attack vector lying open unless we really need to.

Newsletter

ShieldNOTES: Essential WordPress Security News

Stay ahead of security threats with our weekly newsletter.

Get exclusive expert insights, the latest plugin announcements, in-depth tutorials, news, and more delivered to your inbox weekly!

Click to access the login or register cheese