• Skip to primary navigation
  • Skip to main content
  • Skip to footer
WPSecurityLock – Malware removal & WordPress security services

WPSecurityLock – Malware removal & WordPress security services

WordPress security, malware removal, repair, backups, ongoing maintenance, installation, site migration & support services – WP Security Lock.

  • Facebook
  • LinkedIn
  • Twitter
  • Home
  • About
    • About Us
    • Speaker Information
    • Contact Us by Phone, Email or Live Chat
    • Testimonials
  • Security Services
    • Malware / Virus Removal
    • WordPress Security and Installation Services
    • Monthly Security Packages
    • SSL Conversion Service (HTTP to HTTPS)
  • Blog
  • Resources
  • Contact
  • SafeWP

Using Trackbacks? Be Cautious!

February 19, 2015 By Angie Newton Leave a Comment

How to disable trackbacksWhat is a trackback?

A trackback and pingback notifies you that your blog has been linked to from another blog on the web. Trackbacks will show up in the comment moderation section of your WordPress blog with content, a pingback is a link with no content. Most are just spam although you might get legitimate ones too. A lot of WordPress bloggers use them. A LOT.

Many of our team has used them too but not any longer. Trackbacks and pingbacks pose a serious threat.

If you have trackbacks enabled, it would be in your best interest to totally remove them. The threat is still there if all you do is disable trackbacks. In a nutshell using the script that runs trackbacks poses an ongoing security risk.

Things that could potentially happen:

  • Hackers attack using the trackback feature.
  • Trackbacks have been known to cause massive distributed denial-of-service attack (DDoS) attacks.
  • Other clean WordPress sites can be used by the hacker to do their dirty work. Simply scary!

and more!

Why risk getting hacked?

On a personal note, I would much rather turn off these notifications and keep my site from a potential hacking rather than the minor benefit of having someone else possibly see my link on someone else's blog. Plus it's my understanding that WordPress has automatically set nofollow on trackbacks, pingbacks and comment links. So it's a total no brainer for me.

How to disable trackbacks?

You can disable them by going to your WordPress dashboard and clicking on Settings—>Discussion then uncheck the box that says “allow link notifications from other blogs (pingbacks and trackbacks)”. Then scroll to the bottom of the page and click the Save Changes button. See an example below:

Discussion Settings for Trackbacks

Completing this step only works for future posts. You will need to then disable trackbacks on current posts that already exist on your WordPress blog. You can do this by digging in to your cPanel and phpMyAdmin or use the iThemes Security Pro plugin. See below…

How to disable trackbacks for all WordPress pages?

It's easy with iThemes Security Pro. All you need to do is disable XMLRPC completely unless another plugin you use requires it then only choose disable trackbacks in the plugin.

Go to Security—> Settings—> WordPress Tweaks. And then save your changes. Yep that's all.

If you need help going over iThemes Security settings or have any WordPress questions set up a consultation with us.

Filed Under: WordPress Security Tips Tagged With: pingbacks, safety, trackbacks

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Let’s work together:

Get in touch with us and send some basic info about your project. Don't be shy, we can help with just about anything.

Contact Us!

Footer

  • Facebook
  • LinkedIn
  • Twitter

Contact

Call 815-600-7270
Contact
Mo,Tu,We,Th,Fr 9:00 am – 5:00 pm

Get WordPress Help Now

Chat With Us!
Submit A Support Ticket

Copyright © 2025 | WP Security Lock, Inc