WP Clinic
Log in Sign up

SECURITY FINDING

xmlrpc.php enabled and publicly reachable

What it is

xmlrpc.php is enabled. It's an old WordPress API that's routinely abused for amplified brute-force login attempts (many password guesses hidden inside few requests) and for pingback-based DDoS attacks against other sites.

How to fix it

Disable xmlrpc.php if you don't use it (most sites don't) — the WordPress Plugin's Security tab can block it for you.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.