Index / Questions / Should you disable xmlrpc.php in WordPre

Should you disable xmlrpc.php in WordPress?

Answer

Yes, unless you use remote publishing. In 2019 XML-RPC was effectively a backdoor that hackers attacked with brute force and special commands. I disabled it entirely, with the Disable XML-RPC plugin or a webserver rule in .htaccess.

Sources