Should you disable xmlrpc.php in WordPress?AnswerYes, unless you use remote publishing. In 2019 XML-RPC was effectively a backdoor that hackers attacked with brute force and special commands. I disabled it entirely, with the Disable XML-RPC plugin or a webserver rule in .htaccess.SourcesDisabling XML-RPC in WordPress (snippet, the answer above is its summary)https://willem.com/en/2019-03-31_wordpress-10-tips-to-secure-your-website/ (full article)