Is your site running slower than it should? Noticing strange login attempts in your logs? Or maybe your hosting provider told you to "disable XML-RPC" without explaining why. In this article, we'll break down what XML-RPC is, why it has become a security liability for most sites, and how to safely turn it off.
XML-RPC is an older communication protocol that allows WordPress to "talk" to external applications. In simple terms: normally you log into your site only through your browser, via the WordPress admin dashboard. XML-RPC, on the other hand, acts like a "side door" that lets you publish posts or manage comments through a mobile app or desktop tool, without opening the dashboard at all.
For example, older versions of the WordPress mobile app, along with various third-party publishing tools, used to connect to sites this way.
This file lives at the following address on your site:
yoursite.com/xmlrpc.php
XML-RPC was a useful feature when it was designed. But over time, two major problems emerged.
Normally, when an attacker tries to guess a login, each password attempt requires a separate request — which is slow and easy to spot. But a function in XML-RPC called system.multicall lets an attacker test hundreds, even thousands, of username/password combinations in a single request. This means:
A feature called pingback lets your site send a "someone mentioned you" notification to other sites. Attackers can abuse this feature to turn your site into a tool for sending an attack against another site — entirely without your knowledge or consent. In other words, your site could become part of an attack without you ever realizing it.
Constant requests to XML-RPC — especially from malicious bots — unnecessarily consume your server's CPU and memory. This can cause your site to slow down, or even become temporarily unreachable depending on your hosting plan.
For most sites, the answer is yes. Here's why:
In short: unless you rely on Jetpack or a similar integration, disabling XML-RPC makes your site both faster and more secure.
There are several methods depending on your site's technical setup. Let's go from simplest to most advanced.
This is the most practical solution if you're not comfortable with code.
If you're already using a security plugin (like Wordfence, Sucuri, or iThemes Security), check its settings first — many already include a built-in "Disable XML-RPC" option, so you may not need a separate plugin at all.
Adding the following code to the .htaccess file in your site's root directory will completely block outside access to xmlrpc.php:
Order Deny,Allow
Deny from all
Note: Always back up your
.htaccessfile before editing it. A mistake here can make your entire site inaccessible.
If you're comfortable adding code, you can also disable XML-RPC by adding this line to your theme's functions.phpfile:
add_filter('xmlrpc_enabled', '__return_false');
Note: We recommend using a child theme so this change isn't lost the next time your theme updates.
If your server runs Nginx, add the following block to your server configuration file:
location = /xmlrpc.php {
deny all;
}
You'll need to reload the Nginx service after making this change.
After making the change, visit the following address in your browser:
yoursite.com/xmlrpc.php
| Situation | Recommendation |
|---|---|
| I don't use Jetpack or a plugin that requires XML-RPC | Disable it |
| I use an old desktop publishing tool | Review your actual needs first |
| My site is slow, or I'm seeing suspicious traffic | Make disabling it a priority |
XML-RPC is a feature that most modern WordPress sites no longer need, yet leaving it open gives attackers an easy way in. Pick whichever method above fits your setup, and you can protect your site from these risks in just a few minutes.
If you're not sure, or want to check whether a specific plugin depends on XML-RPC, feel free to reach out to our hosting support team.
No. Most sites today do not need XML-RPC. Only some older mobile apps or certain plugins such as Jetpack may use this feature; if you do not use them, it is safe to disable it.
XML-RPC is an interface that is frequently abused in brute-force attacks and in pingback requests used for DDoS. Disabling it closes this attack surface.
You can block access to the xmlrpc.php file through a security plugin (e.g. Wordfence) or with a few lines of code added to your .htaccess or functions.php file.