KakapoWPKakapoWP
Log inTry for free
Kakapo Security

Hardening

Switched off, not hidden.

Three toggles make WordPress smaller: switch off XML-RPC, block user enumeration, lock the file editor. What is off cannot be used by anyone.

Hardening

XML-RPC can be switched off · Author query ?author= is redirected

ActiveSettings

What hardening offers

XML-RPC can be switched off
Author query ?author= gets redirected
REST users list not for anonymous visitors
File editor blocked via capabilities

Here's how it works

1

Set the toggle in the settings

2

The attack surface disappears at once

3

Whatever you still need, you leave on

FAQ about hardening

What's the problem with XML-RPC?
The interface is a well-known surface for brute-force attempts and pingbacks. If you do not need it, switch it off.
What is user enumeration?
Via ?author= with a number and via the REST list of users, the account names of a website can be queried. Kakapo Security redirects the author query and removes the user list for anonymous visitors.
Why block the file editor?
Anyone who gets hold of an account with edit_plugins, edit_themes or edit_files rights can write code straight into your site. The block removes exactly these capabilities.

More security features

Ready?

Try Security free for 24 hours.

No credit card, no risk. Up and running in 2 minutes.

Try it for free now