The lock set is complete: WP Pro Admin 2.1.0

View as Markdown

Three more locks — Registration Lockdown, Disable XML-RPC and Disable File Editing — complete the promise: nothing appears on your site without you.

WP Pro Admin 2.1.0 adds the last three locks. The set now covers the whole promise: no new comments, no new plugins, no new versions, no new users, no remote write API, no code edits.

All three ship switched off. Nothing changes on your site until you turn one on.

Registration Lockdown

Creating a rogue administrator is what an attacker does first, because it outlives the backdoor they came in through.

The full walkthrough is in how to stop spam user registration in WordPress.

Disable XML-RPC

Closes xmlrpc.php and removes every method, including pingback.ping and system.multicall — the one that lets a single request carry hundreds of password guesses. The X-Pingback header and RSD discovery link go too, so the site stops advertising the API.

If you use the Jetpack mobile app or a legacy remote publishing tool, leave this off. More in should you disable XML-RPC?

Disable File Editing

Removes the built-in plugin and theme file editors. A stolen administrator session is otherwise one click away from running arbitrary PHP.

It’s the natural pair to Installation Lockdown: that stops new code arriving, this stops the code already there being rewritten. It’s a capability filter rather than the DISALLOW_FILE_EDIT constant, so it’s always reversible from the settings screen.

What’s next

2.2.0 brings the content tools: Duplicate, Live Draft, Keep URL, Order and Replace Media — the everyday editing jobs that should have been built into WordPress. The guides already cover how each one will work.

Download the latest release, or read the installation docs to get started. This release ships with 146 tests and 546 assertions.

Install it, lock it, forget it.

A free WordPress plugin — GPL, instantly reversible, and updates come to you.

Type to search the whole site.