
Blockinator Security & Risk Analysis
wordpress.org/plugins/blockinatorThis plugin will remove script and version numbers from the source of your pages.
Is Blockinator Safe to Use in 2026?
Generally Safe
Score 85/100Blockinator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "blockinator" plugin v1.0.0 exhibits an exceptionally strong security posture. The complete absence of any identified attack surface, including AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits potential entry points for attackers. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions, file operations, or external HTTP requests. All SQL queries are correctly prepared, and all output is properly escaped. The lack of any taint analysis findings further reinforces the impression of well-sanitized code.
Blockinator Security Vulnerabilities
Blockinator Code Analysis
Blockinator Attack Surface
WordPress Hooks 10
Maintenance & Trust
Blockinator Maintenance & Trust
Maintenance Signals
Community Trust
Blockinator Alternatives
Disable XML-RPC
disable-xml-rpc
Disables the XML-RPC API in WordPress 3.5+, which is enabled by default.
Disable XML-RPC-API
disable-xml-rpc-api
A simple and lightweight plugin to disable XML-RPC API, X-Pingback and pingback-ping in WordPress 3.5+ for a faster and more secure website
Remove & Disable XML-RPC Pingback
remove-xmlrpc-pingback-ping
Prevent pingback, XML-RPC and denial of service DDOS attacks by disabling the XML-RPC pingback functionality.
Manage XML-RPC
manage-xml-rpc
Enable/Disable XML-RPC for all or based on IP list, also you can control pingback and Unset X-Pingback from HTTP headers.
Stop XML-RPC Attacks
stop-xml-rpc-attacks
Blocks dangerous XML-RPC methods while preserving Jetpack, WooCommerce, and mobile apps compatibility.
Blockinator Developer Profile
1 plugin · 10 total installs
How We Detect Blockinator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
blockinator/style.css?ver=blockinator/script.js?ver=HTML / DOM Fingerprints
wrapblockinator_options Blockinator Settings (This disables the function) (This removes the script from the html code of your pages) REMOVE XMLRPC FROM HEADERS +2 morename="blockinator_options[xmlrpc_disable_enable_checkbox]"name="blockinator_options[xmlrpc_disable_headers_checkbox]"name="blockinator_options[remove_version_numbers_checkbox]"name="blockinator_options[remove_shortlinks_checkbox]"name="blockinator_options[remove_feedslinks_checkbox]"name="blockinator_options[remove_dns_prefetch_checkbox]"