=== Fixora Disable XML-RPC ===
Contributors: 0322lf
Tags: disable xml-rpc, xmlrpc, disable xmlrpc, pingback
Requires at least: 6.4
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Fixora disable xml-rpc and xmlrpc pingback with a blocked-attempt log—see recent blocks in Settings.

== Description ==

Fixora Disable XML-RPC helps you disable xml-rpc, disable xmlrpc abuse, and reduce pingback exposure on your WordPress site.

* **Disable XML-RPC entirely** — turns off XML-RPC and blocks direct access to `xmlrpc.php` (unless Jetpack is allowed).
* **Blocked-attempt log** — records blocked XML-RPC requests (time, remote IP, and method name only). View the count and recent entries under **Settings → Fixora Disable XML-RPC**. Stores up to the last 50 entries in a single option.
* **Remove X-Pingback and pingback link discovery** — when protection is active.
* **Pingback-only mode** — blocks only `pingback.ping` while leaving other XML-RPC methods available.
* **Allow Jetpack** — optional checkbox so Jetpack can keep using XML-RPC when the plugin is active.
* **Admin status check** — requests `xmlrpc.php` from the settings screen and reports whether it appears blocked.

This plugin does not provide firewall lists or additional hardening beyond the features above.

== Installation ==

1. Upload the `fixora-disable-xml-rpc` folder to `/wp-content/plugins/`.
2. Activate the plugin through the **Plugins** screen. XML-RPC is disabled immediately (full block mode) without opening settings.
3. Optional: go to **Settings → Fixora Disable XML-RPC** to switch to pingback-only, allow Jetpack, or turn protection off.

== Frequently Asked Questions ==

= Will this break Jetpack? =

Enable **Allow Jetpack** on the settings page. When Jetpack is active, full XML-RPC blocking is skipped so Jetpack can continue to work.

= What is pingback-only mode? =

XML-RPC stays enabled, but `pingback.ping` is removed from the available methods. Pingback headers and discovery links are still removed.

= What does the blocked-attempt log store? =

Only the time of the block, the remote IP address, and the XML-RPC method name when it can be read from the request. It does not store request bodies, headers, cookies, or credentials.

== Screenshots ==

1. Settings → Fixora Disable XML-RPC: choose the protection mode (Off, Disable XML-RPC entirely, or Block only pingback.ping), optionally allow Jetpack, and review the blocked-attempt log and status check on one screen.
2. Blocked XML-RPC attempts log showing the time, remote IP address, and XML-RPC method of recent blocked requests (up to the last 50 entries).
3. XML-RPC status check: the "Check xmlrpc.php now" button requests your site's xmlrpc.php and reports whether it appears blocked.

== Changelog ==

= 1.0.1 =
* Add blocked-attempt log (time, IP, method) with a 50-entry cap on the settings screen.

= 1.0.0 =
* Initial release.
