xmlrpc.php is WordPress’s endpoint for XML-RPC requests: remote method calls used by some apps and integrations. Disable it if your site does not rely on it; if you need it for Jetpack, a mobile app, or remote publishing, keep the required functionality and restrict and rate-limit access. Its presence alone does not mean your site has been compromised.
What xmlrpc.php does
XML-RPC lets software outside your WordPress dashboard call supported methods on your site. Some integrations use those calls for tasks such as publishing or connecting to a mobile app. The endpoint is commonly available as https://example.com/xmlrpc.php, with your own site’s domain in place of example.com.
WordPress identifies XML-RPC as a frequent brute-force target, particularly the system.multicall method, which can bundle multiple calls into one request. That is a reason to assess and control the endpoint—not evidence that every site is under attack or that seeing the file means a site is compromised. WordPress publishes no attack percentage or incident count in its guidance. WordPress: Brute Force Attacks
Should you disable XML-RPC?
| Choice | When it fits | Compatibility and security implications |
|---|---|---|
| Block the endpoint | Your site does not use XML-RPC-dependent apps or integrations. | Best aligned with WordPress guidance for an unused endpoint. Use a server, host, or WAF control that blocks the requests and methods you intend to deny; verify that it does not disrupt a feature you need. |
| Keep it with controls | A required integration uses XML-RPC. | Preserve the methods needed by legitimate clients while restricting unwanted access and enforcing rate limits. Test the controls because overly broad rules can break integrations. |
WordPress’s Advanced Administration Handbook puts the advice plainly: “If you don’t use XML‑RPC, disable it. If you do (e.g., Jetpack, mobile apps), restrict it (WAF rules) and rate‑limit aggressively.” The handbook page says it was last updated February 25, 2026. Read the WordPress guidance.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
Will disabling it break Jetpack or other features?
It can. WordPress support notes that Jetpack and some apps or services rely on xmlrpc.php. Disabling the endpoint may also affect remote publishing or pingbacks, depending on the site’s setup. The older support response is not a guarantee of how every current version or configuration behaves, so check the integrations you actually use before applying a block. WordPress support: Disabling XML-RPC
A plugin-directory listing for Disable XML-RPC – Dashboard Control says its blocked mode affects remote publishing, mobile app access, pingbacks and trackbacks, method discovery, and potentially Jetpack. These are the plugin author’s stated effects, not a universal compatibility guarantee. Plugin listing
How to disable or restrict it safely
- Inventory dependencies. Identify whether your site uses Jetpack, a WordPress mobile app, remote publishing, pingbacks, or another service that calls XML-RPC. If you are unsure, ask your host or the integration provider before blocking it.
- Test in staging when possible. Apply the proposed server, host, WAF, or plugin rule to a staging copy. WordPress cautions that server and proxy examples vary by environment and should be tested before production changes.
- Choose a control that matches the goal. If XML-RPC is unused, block the endpoint comprehensively at an appropriate server, hosting, or WAF layer, or use a maintained tool whose current behavior you understand. If a client needs it, restrict access and enforce rate limits rather than relying on logging alone. Check that the rules cover the methods and requests you mean to control.
- Verify the site’s actual workflows. Check relevant publishing, mobile app, Jetpack, and pingback behavior after the change. If a required feature fails, revise or remove the rule and ask your host or WAF provider for a narrower mitigation.
WordPress support gives Cloudflare and Sucuri as examples of WAFs that can block unwanted traffic before it reaches a site. That is not a comparison or endorsement; confirm the current product capabilities and configuration with the provider. WordPress support: WAF and host mitigation
Why the xmlrpc_enabled hook is not a complete block
The name of WordPress’s xmlrpc_enabled filter can be misleading. The official reference says it controls XML-RPC methods that require authentication, such as publishing methods; it does not fully turn off XML-RPC. Pingbacks and other unauthenticated custom endpoints are outside its scope. Therefore, adding add_filter( 'xmlrpc_enabled', '__return_false' ); is not a comprehensive block of all XML-RPC requests. WordPress hook reference: xmlrpc_enabled
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
For narrower method or request controls, the reference points to xmlrpc_methods and xmlrpc_element_limit. Choose an approach based on the methods you need to allow or deny, and verify its coverage; a complete block requires a control that addresses the requests and methods you intend to stop.
When a plugin is an option
A plugin can offer a dashboard control, but confirm what it blocks, whether it applies rate limits or only records activity, and whether it is maintained for your WordPress version. The listing for Disable XML-RPC – Dashboard Control describes a dashboard toggle and rate limiting. At the time the directory page was consulted, it showed version 1.0.4, 10+ active installations, and testing up to WordPress 7.1.2. Those figures can change and do not establish independent security quality or broad adoption. Check the current plugin listing
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

