The old gate is still open. XML-RPC is a legacy remote access protocol that lets external tools interact with your site. Unfortunately, it's also one of the most commonly exploited attack vectors.

Why This Matters

XML-RPC (xmlrpc.php) allows:

  • Brute force amplification — attackers can try hundreds of passwords in a single request using the system.multicall method
  • DDoS pingback attacks — your site can be used as a weapon to attack other sites
  • Credential theft — XML-RPC sends usernames and passwords in plain text (before encryption at the transport layer)

Most modern WordPress sites don't need XML-RPC because:

  • The REST API (introduced in WordPress 4.7) replaces its functionality
  • The WordPress mobile app now works with the REST API
  • Jetpack used to require it, but modern versions use alternative connection methods

How to Check if You Need It

You might still need XML-RPC if you:

  • Use an old version of the WordPress mobile or desktop app
  • Use plugins that explicitly require it (increasingly rare)
  • Use external publishing tools that haven't updated to REST API

If none of these apply, disable it.

How to Fix It

Safe Practice: Before making any technical changes, ensure you have a full backup of your site (files and database) via your hosting control panel or a dedicated plugin like UpdraftPlus.

Method 1: .htaccess (Recommended for Apache)

Add this to your .htaccess file, before the WordPress rewrite rules:

# Apache .htaccess
<Files xmlrpc.php>
  Order Deny,Allow
  Deny from all
</Files>

Method 2: Nginx

Add to your server block:

location = /xmlrpc.php {
    deny all;
    return 403;
}

Method 3: mu-plugin

Create a file at wp-content/mu-plugins/disable-xmlrpc.php:

<?php
/**
 * Plugin Name: Dravasite – Disable XML-RPC
 * Description: Disables WordPress XML-RPC methods to prevent brute force
 *              amplification and pingback DDoS attacks.
 * Version:     1.0.0
 */

if ( ! defined( 'ABSPATH' ) ) {
    exit;
}

// Disable all XML-RPC methods
add_filter( 'xmlrpc_enabled', '__return_false' );

Note: This disables XML-RPC methods but the file is still accessible. Methods 1 and 2 are more thorough because they block access at the server level.

New to mu-plugins? Read our guide to adding code snippets safely with mu-plugins.

Method 4: Security Plugin

Most security plugins (Wordfence, iThemes, Sucuri) have an option to disable XML-RPC in their settings.

What to Watch For

  • Test after disabling. If you use Jetpack, the WordPress mobile app, or any external publishing tool, test that they still work. If something breaks, re-enable XML-RPC and look for that tool's REST API alternative.
  • Some hosting providers already block XML-RPC at the server level. Check with your host before adding redundant rules.
  • You can verify XML-RPC is disabled by visiting yourdomain.com/xmlrpc.php — you should get a 403 Forbidden error instead of the usual "XML-RPC server accepts POST requests only" message.