Turn off XML-RPC in WordPress
xmlrpc.php still answers. Unless Jetpack or a publishing app needs it, block it at the server.
Written by Hamza Ahmad Aslam. Updated . One of the what it leaks guides.
What the checker sees
It requests /xmlrpc.php with a plain GET. A live endpoint answers 405 with the text "XML-RPC server accepts POST requests only." Either of those raises the finding.
Why it matters
XML-RPC is WordPress's old remote-publishing interface, from before the REST API. Its system.multicall method lets one request carry hundreds of login attempts, which slips past limits that count requests. Its pingback method can be used to make your server fetch other people's URLs.
Who still needs it
Jetpack uses it to talk to WordPress.com, and some older publishing apps use it. If neither applies, nothing on the site will notice it has gone.
Block it at the server
This stops the file answering at all, which is what the checker looks for. For nginx:
location = /xmlrpc.php {
deny all;
}For Apache 2.4:
<Files "xmlrpc.php">
Require all denied
</Files>If you have to keep it
The xmlrpc_enabled filter sounds like an off switch but only turns off the methods that need a login. Pingbacks still work, and the checker will still report the endpoint as live. To also drop pingbacks and the header that advertises them:
<?php
add_filter( 'xmlrpc_enabled', '__return_false' );
add_filter( 'xmlrpc_methods', function ( $methods ) {
unset( $methods['pingback.ping'], $methods['pingback.extensions.getPingbacks'] );
return $methods;
} );
add_filter( 'wp_headers', function ( $headers ) {
unset( $headers['X-Pingback'] );
return $headers;
} );For Jetpack, ask your host whether they can allow only Jetpack's servers through to xmlrpc.php.
Check the fix
curl -s -o /dev/null -w "%{http_code}\n" https://example.com/xmlrpc.php403 or 404 means it is blocked. 405 means it still answers.
Check a site for this
Other fixes
- Hide the WordPress version numberThe version shows in the page's generator tag and in the stock readme.html. Both can go in a few minutes.
- Stop the WordPress REST API listing user namesThe users endpoint answers anonymous requests with account slugs, which are usually the login names.
- The WordPress security headers the checker readsFive response headers and HTTPS itself. Set them once at the server or CDN and every page carries them.