WP Front Door

Turn off XML-RPC in WordPress

xmlrpc.php still answers. Unless Jetpack or a publishing app needs it, block it at the server.

Written by . Updated . One of the what it leaks guides.

What the checker sees

It requests /xmlrpc.php with a plain GET. A live endpoint answers 405 with the text "XML-RPC server accepts POST requests only." Either of those raises the finding.

Why it matters

XML-RPC is WordPress's old remote-publishing interface, from before the REST API. Its system.multicall method lets one request carry hundreds of login attempts, which slips past limits that count requests. Its pingback method can be used to make your server fetch other people's URLs.

Who still needs it

Jetpack uses it to talk to WordPress.com, and some older publishing apps use it. If neither applies, nothing on the site will notice it has gone.

Block it at the server

This stops the file answering at all, which is what the checker looks for. For nginx:

nginx
location = /xmlrpc.php {
    deny all;
}

For Apache 2.4:

Apache
<Files "xmlrpc.php">
    Require all denied
</Files>

If you have to keep it

The xmlrpc_enabled filter sounds like an off switch but only turns off the methods that need a login. Pingbacks still work, and the checker will still report the endpoint as live. To also drop pingbacks and the header that advertises them:

PHP
<?php
add_filter( 'xmlrpc_enabled', '__return_false' );

add_filter( 'xmlrpc_methods', function ( $methods ) {
	unset( $methods['pingback.ping'], $methods['pingback.extensions.getPingbacks'] );
	return $methods;
} );

add_filter( 'wp_headers', function ( $headers ) {
	unset( $headers['X-Pingback'] );
	return $headers;
} );

For Jetpack, ask your host whether they can allow only Jetpack's servers through to xmlrpc.php.

Check the fix

Shell
curl -s -o /dev/null -w "%{http_code}\n" https://example.com/xmlrpc.php

403 or 404 means it is blocked. 405 means it still answers.

Check a site for this

A domain or a full address. Only public pages are fetched, the way a browser would.