XML-RPC: The Legacy Back Door

XML-RPC is WordPress's original remote-control interface, from an era when publishing from a desktop app was a bold idea. It lives at xmlrpc.php and it can do nearly anything an admin can: publish posts, edit settings, and, importantly for attackers, attempt logins. system.multicall lets one request carry hundreds of username and password guesses.

Almost nothing you run needs it anymore. Almost every bot that touches your site knows where it lives. That combination makes it the classic hardening target.

You have three levels to choose from, and the right one depends on one question: do you use Jetpack or the WordPress mobile apps?

Level one: remove the signpost

Remove X-Pingback header deletes the response header that advertises your pingback URL. Bots use it to find XML-RPC endpoints; without the signpost, some of the laziest scanners move on. Nothing breaks. This is the free option.

Level two: defang it

Disable pingback methods strips pingback.ping and its cousins from XML-RPC while leaving the rest of the service running. Two reasons this matters even if you never ping anyone:

  • Pingbacks are a DDoS instrument. An attacker sends pingback requests to thousands of WordPress sites with your URL as the "source," and the swarm floods you.
  • Pingback verification does server-side requests to arbitrary URLs, which attackers use for port scanning your internals.

Choose this level if you use the WordPress mobile apps, MarsEdit, or any tool that authenticates via XML-RPC and you want the rest of it to keep working.

Level three: close the door

Disable XML-RPC entirely (a high-impact toggle, and the warning is real) blocks xmlrpc.php outright with a 403. The brute-force channel, the pingback abuse, the whole legacy surface: gone.

What breaks with it: Jetpack, the WordPress mobile apps, and any remote-publishing or automation tool that speaks XML-RPC. If you depend on Jetpack for CDN, backups, or stats, leave this off and live at level two.

How to check whether you need it at all

Your access logs answer this definitively. Search for xmlrpc.php and look at the user agents: Jetpack by WordPress.com means you have a Jetpack connection; wp-iphone or wp-android means someone uses the mobile app; Mozilla with garbage POST bodies means bots, and bots don't get a vote. Only humans get to keep the door open.

Most membership sites, with no Jetpack and no mobile publishing, should sit at level three. The escalations exist so you can step down gracefully if something you forgot about starts complaining.