SECURITY FINDING
xmlrpc.php enabled and publicly reachable
What it is
xmlrpc.php is enabled. It's an old WordPress API that's routinely abused for amplified brute-force login attempts (many password guesses hidden inside few requests) and for pingback-based DDoS attacks against other sites.
How to fix it
Disable xmlrpc.php if you don't use it (most sites don't) — the WordPress Plugin's Security tab can block it for you.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.