X
X
X
X

Knowledge Base

HomepageKnowledge BaseWeb HostingWhat Is XML-RPC in WordPress, and W...

What Is XML-RPC in WordPress, and Why Should You Disable It?

Is your site running slower than it should? Noticing strange login attempts in your logs? Or maybe your hosting provider told you to "disable XML-RPC" without explaining why. In this article, we'll break down what XML-RPC is, why it has become a security liability for most sites, and how to safely turn it off.

What Is XML-RPC?

XML-RPC is an older communication protocol that allows WordPress to "talk" to external applications. In simple terms: normally you log into your site only through your browser, via the WordPress admin dashboard. XML-RPC, on the other hand, acts like a "side door" that lets you publish posts or manage comments through a mobile app or desktop tool, without opening the dashboard at all.

For example, older versions of the WordPress mobile app, along with various third-party publishing tools, used to connect to sites this way.

This file lives at the following address on your site:

yoursite.com/xmlrpc.php

Why Is It a Problem?

XML-RPC was a useful feature when it was designed. But over time, two major problems emerged.

1. It Makes Brute-Force Attacks Easier

Normally, when an attacker tries to guess a login, each password attempt requires a separate request — which is slow and easy to spot. But a function in XML-RPC called system.multicall lets an attacker test hundreds, even thousands, of username/password combinations in a single request. This means:

  • The attack becomes dramatically faster
  • It's much harder to spot in your server logs
  • It can bypass standard security measures (like plugins that "block after 5 failed attempts")

2. It Can Be Used as a Tool in DDoS Attacks

A feature called pingback lets your site send a "someone mentioned you" notification to other sites. Attackers can abuse this feature to turn your site into a tool for sending an attack against another site — entirely without your knowledge or consent. In other words, your site could become part of an attack without you ever realizing it.

3. It Drains Server Resources

Constant requests to XML-RPC — especially from malicious bots — unnecessarily consume your server's CPU and memory. This can cause your site to slow down, or even become temporarily unreachable depending on your hosting plan.

Should Everyone Disable It?

For most sites, the answer is yes. Here's why:

  • Today, WordPress's own mobile app and editor use a more modern, more secure system called the REST APIinstead of XML-RPC.
  • Some plugins, like Jetpack, may still rely on XML-RPC — if you use one of these, check before disabling it.
  • Unless you're using an old desktop publishing tool (like a very old Windows Live Writer setup), you likely have no real use for XML-RPC today.

In short: unless you rely on Jetpack or a similar integration, disabling XML-RPC makes your site both faster and more secure.

How Do You Disable It?

There are several methods depending on your site's technical setup. Let's go from simplest to most advanced.

Method 1: Using a Plugin (Easiest Option)

This is the most practical solution if you're not comfortable with code.

  1. Log into your WordPress admin dashboard
  2. Go to Plugins > Add New
  3. Search for a plugin like "Disable XML-RPC" or "Disable XML-RPC-API"
  4. Install and activate it — most of these plugins work right out of the box, no extra configuration needed

If you're already using a security plugin (like Wordfence, Sucuri, or iThemes Security), check its settings first — many already include a built-in "Disable XML-RPC" option, so you may not need a separate plugin at all.

Method 2: Using .htaccess (For Apache Servers)

Adding the following code to the .htaccess file in your site's root directory will completely block outside access to xmlrpc.php:


Order Deny,Allow
Deny from all

Note: Always back up your .htaccess file before editing it. A mistake here can make your entire site inaccessible.

Method 3: Using functions.php (Theme File)

If you're comfortable adding code, you can also disable XML-RPC by adding this line to your theme's functions.phpfile:

add_filter('xmlrpc_enabled', '__return_false');

Note: We recommend using a child theme so this change isn't lost the next time your theme updates.

Method 4: For Nginx Servers

If your server runs Nginx, add the following block to your server configuration file:

location = /xmlrpc.php {
    deny all;
}

You'll need to reload the Nginx service after making this change.

How to Test That It's Disabled

After making the change, visit the following address in your browser:

yoursite.com/xmlrpc.php
  • If you see a message like "XML-RPC server accepts POST requests only," XML-RPC is still active.
  • If you get a 403 Forbidden error or a connection error, it has been successfully disabled.

Summary

Situation Recommendation
I don't use Jetpack or a plugin that requires XML-RPC Disable it
I use an old desktop publishing tool Review your actual needs first
My site is slow, or I'm seeing suspicious traffic Make disabling it a priority

XML-RPC is a feature that most modern WordPress sites no longer need, yet leaving it open gives attackers an easy way in. Pick whichever method above fits your setup, and you can protect your site from these risks in just a few minutes.

If you're not sure, or want to check whether a specific plugin depends on XML-RPC, feel free to reach out to our hosting support team.

Frequently Asked Questions

Will my WordPress site be affected if I disable XML-RPC?

No. Most sites today do not need XML-RPC. Only some older mobile apps or certain plugins such as Jetpack may use this feature; if you do not use them, it is safe to disable it.

Why is XML-RPC a security risk?

XML-RPC is an interface that is frequently abused in brute-force attacks and in pingback requests used for DDoS. Disabling it closes this attack surface.

How can I disable XML-RPC?

You can block access to the xmlrpc.php file through a security plugin (e.g. Wordfence) or with a few lines of code added to your .htaccess or functions.php file.

Can't find the information you are looking for?

Create a Support Ticket
Did you find it useful?
(88 times viewed / 0 people found it helpful)

Powered by WISECP
Top