Tai Hoang

How to Disable XML-RPC Protocol in WordPress

XML-RPC is a legacy WordPress protocol that allows remote publishing and app integrations but has since been replaced by the more secure and flexible REST API. Despite this, XML-RPC remains enabled by default and is often exploited for brute-force logins and DDoS amplification. If you’re not using tools like Jetpack or the WordPress mobile app, it’s best to disable XML-RPC to reduce security risks.

Check If XML-RPC is Enabled in Your Website

Go to this address: https://your-website-url.com/xmlrpc.php, for example, https://taiht.dev/xmlrpc.php.

If you see this message:

XML-RPC server accepts POST requests only.Code language: plaintext (plaintext)

Then XML-RPC is enabled in your website.

How to Disable XML-RPC

You can disable XML-RPC in several ways depending on your environment setup. Choose one of the methods below, or combine them for stronger security.

Method 1: Disable XML-RPC in the web server (Nginx or Apache)

For Nginx, add this code to the server block:

## Block all requests to /xmlrpc.php
location = /xmlrpc.php {
    deny all;
    access_log off;
    log_not_found off;
}
Code language: Nginx (nginx)

For Apache, add this code to .htaccess file:

<Files "xmlrpc.php">
    Require all denied
</Files>Code language: Apache (apache)

Method 2: Block all requests to XML-RPC on Cloudflare

If your site sits behind Cloudflare, you can block all requests to xmlrpc.php file at the edge. This method not only improves security but also reduces server load. To do this, go to your Cloudflare dashboard, then:

  1. Choose your website → Security → Security rules.
  2. Hit the Create rule button → Custom rules.
  3. Set up the rule as in the picture below:
    • Field: URI Path
    • Operator: contains
    • Value: xmlrpc.php
    • Then take action: Block
Block xmlrpc on cloudflare

With this rule in place, any request containing xmlrpc.php in the URL will be blocked instantly before it reaches your server. Now your site is protected from XML-RPC attacks and also saving server resources, which help improving overall performance.

Reply via email