How to Disable XML-RPC in WordPress to Stop Attacks (3 Methods)

If your WordPress website experiences random CPU spikes, high memory load, or constant login attempts in your access logs, there is an 80% chance that an outdated legacy feature is to blame: XML-RPC.
XML-RPC (via the xmlrpc.php file in your root directory) was introduced in WordPress 3.5 to enable remote communication between WordPress and third-party mobile apps. However, with the launch of the modern, secure WordPress REST API, XML-RPC has become virtually obsolete.
Today, automated hacker bots and script kiddies abuse XML-RPC to launch massive DDoS attacks and amplified brute-force attacks—testing hundreds of passwords in a single HTTP request.
In this guide, we will show you three simple methods to disable XML-RPC in WordPress and protect your server from unnecessary load.
Why You Should Disable XML-RPC Immediately
The biggest security flaw of XML-RPC is its system.multicall method. This function allows a hacker to test 500 different username and password combinations in a single API call.
Standard WordPress login pages (wp-login.php) trigger security plugins like Wordfence after 5 failed attempts. But through XML-RPC, bots can attempt 10,000 passwords in minutes without triggering standard login throttles, causing your web server CPU to spike to 100%.
Unless you actively use the legacy Jetpack plugin or outdated desktop publishing tools from 2012, you do not need XML-RPC enabled.
Method 1: Block XML-RPC via .htaccess (Most Efficient Method)
Blocking XML-RPC at the server level via .htaccess is the best approach because it rejects malicious requests before WordPress even boots up PHP, saving 100% of your server memory.
- Log in to your cPanel, open File Manager, and go to your
public_htmlroot directory. - Edit your .htaccess file.
- Paste the following snippet at the top of the file:
<Files xmlrpc.php> order deny,allow deny from all </Files>
Click Save Changes. Anyone attempting to access yourdomain.com/xmlrpc.php will now receive an instant 403 Forbidden response.
Method 2: Disable XML-RPC via functions.php
If you prefer using a PHP filter inside your active theme without modifying web server rewrite rules:
- In your WordPress dashboard, navigate to Appearance > Theme File Editor.
- Open your active theme’s functions.php file.
- Add this single line of code at the bottom:
add_filter( 'xmlrpc_enabled', '__return_false' );
This disables all XML-RPC endpoints while keeping your core files completely standard.
Method 3: Disable XML-RPC Using a Free Plugin
If you do not want to touch code or server files, you can achieve the same protection with a lightweight security plugin.
- Go to Plugins > Add New.
- Search for Disable XML-RPC by Philip Erb.
- Click Install Now, then Activate.
The plugin requires zero configuration; as soon as it is activated, XML-RPC requests are disabled automatically.
How to Verify XML-RPC Is Disabled
To verify that your protection is working:
- Visit a free online tool like XML-RPC Validator (
xmlrpc.eritreo.it). - Enter your website URL and click Check.
- If the validator reports an error or 403 Forbidden, your site is completely shielded!
For more essential WordPress speed and security tutorials, read our guides on fixing the failed to write file to disk error and expanding limits for 413 request entity too large issues.
Wrapping Up
Disabling XML-RPC is one of the highest-yield security steps you can take for your WordPress website. Shutting down this obsolete backdoor eliminates thousands of automated brute-force attacks and keeps your server fast and stable.
Did blocking XML-RPC lower your server CPU usage? Let us know in the comments below!




