The old gate is still open. XML-RPC is a legacy remote access protocol that lets external tools interact with your site. Unfortunately, it's also one of the most commonly exploited attack vectors.
Why This Matters
XML-RPC (xmlrpc.php) allows:
- Brute force amplification — attackers can try hundreds of passwords in a single request using the
system.multicallmethod - DDoS pingback attacks — your site can be used as a weapon to attack other sites
- Credential theft — XML-RPC sends usernames and passwords in plain text (before encryption at the transport layer)
Most modern WordPress sites don't need XML-RPC because:
- The REST API (introduced in WordPress 4.7) replaces its functionality
- The WordPress mobile app now works with the REST API
- Jetpack used to require it, but modern versions use alternative connection methods
How to Check if You Need It
You might still need XML-RPC if you:
- Use an old version of the WordPress mobile or desktop app
- Use plugins that explicitly require it (increasingly rare)
- Use external publishing tools that haven't updated to REST API
If none of these apply, disable it.
How to Fix It
Safe Practice: Before making any technical changes, ensure you have a full backup of your site (files and database) via your hosting control panel or a dedicated plugin like UpdraftPlus.
Method 1: .htaccess (Recommended for Apache)
Add this to your .htaccess file, before the WordPress rewrite rules:
# Apache .htaccess
<Files xmlrpc.php>
Order Deny,Allow
Deny from all
</Files>Method 2: Nginx
Add to your server block:
location = /xmlrpc.php {
deny all;
return 403;
}Method 3: mu-plugin
Create a file at wp-content/mu-plugins/disable-xmlrpc.php:
<?php
/**
* Plugin Name: Dravasite – Disable XML-RPC
* Description: Disables WordPress XML-RPC methods to prevent brute force
* amplification and pingback DDoS attacks.
* Version: 1.0.0
*/
if ( ! defined( 'ABSPATH' ) ) {
exit;
}
// Disable all XML-RPC methods
add_filter( 'xmlrpc_enabled', '__return_false' );Note: This disables XML-RPC methods but the file is still accessible. Methods 1 and 2 are more thorough because they block access at the server level.
New to mu-plugins? Read our guide to adding code snippets safely with mu-plugins.
Method 4: Security Plugin
Most security plugins (Wordfence, iThemes, Sucuri) have an option to disable XML-RPC in their settings.
What to Watch For
- Test after disabling. If you use Jetpack, the WordPress mobile app, or any external publishing tool, test that they still work. If something breaks, re-enable XML-RPC and look for that tool's REST API alternative.
- Some hosting providers already block XML-RPC at the server level. Check with your host before adding redundant rules.
- You can verify XML-RPC is disabled by visiting
yourdomain.com/xmlrpc.php— you should get a 403 Forbidden error instead of the usual "XML-RPC server accepts POST requests only" message.