Skip to content

XML-RPC

XML-RPC is an older way for outside programs to work with a WordPress site, through the file xmlrpc.php. Jetpack and the mobile apps still use it. Its calls that need a login carry a username and password, which makes the file a target for password guessing.

By
WP Ministry
Published

In short

  • XML-RPC in WordPress is one file, xmlrpc.php. It is on unless code, a plugin or the host switches it off.
  • Jetpack and the mobile apps use it. Check what depends on it before you close it.
  • It is separate from the REST API. Closing xmlrpc.php does not touch the REST API, which the block editor needs.

XML-RPC is an older way for one program to give instructions to another over the web. The name is short for Extensible Markup Language-Remote Procedure Call. The caller sends an HTTP POST request whose body is a small XML document naming a procedure to run, and the answer comes back as XML.

In WordPress it is one file, xmlrpc.php, in the site's main folder. Through it an outside program can work with posts, media, comments, users and settings, each through a named method such as wp.newPost. The file also takes pingbacks, which need no login.

It is on unless something switches it off. WordPress once had a setting for it. Since version 3.5 there is a filter in code and no setting.

The REST API does the same kind of job in a newer format. It sends and receives JSON, and WordPress's handbook calls it the foundation of the block editor. The two are separate. Closing xmlrpc.php does not touch the REST API.

Where you meet it

  • In the access log, as requests that read POST /xmlrpc.php.
  • In Jetpack and the mobile apps. Jetpack's documentation says it uses the protocol to connect a site to WordPress.com, and WordPress's own guidance gives both as examples of what needs the file.
  • In a security plugin or at your host, as a setting that disables it. Jetpack's documentation notes that some security plugins and host firewalls block the file entirely.

What goes wrong

  • Passwords are guessed through it. Every call that needs a login carries a username and password, so every call is a chance to try one. WordPress's guidance calls the file a frequent target. How to protect WordPress from brute force attacks covers it beside the login page.
  • The requests themselves are the problem. The same guidance says that even unsuccessful attempts can overwhelm a site. If the log shows the load on a different file, see admin-ajax.php high CPU usage.
  • It is closed and something stops. Jetpack's documentation says blocking the file breaks the Jetpack connection.
  • The usual snippets do less than they claim. The xmlrpc_enabled filter, by WordPress's own reference, switches off only the methods that need a login. Pingbacks stay on. Advice to remove system.multicall through the xmlrpc_methods filter does nothing, because that method is added by the server underneath, outside the list the filter receives. How to disable XML-RPC in WordPress has what does work, and when to leave the file open.

How to look at yours

Open https://example.com/xmlrpc.php in a browser, with your own domain, or ask from a terminal.

bash
curl -s https://example.com/xmlrpc.php

"XML-RPC server accepts POST requests only." means the file is open. An error page from the server, such as 403 Forbidden, means a rule at the server, a plugin or the host has closed it.

The answer is the same whether or not a filter has switched off the login methods, so it does not show that.

Common questions

Is XML-RPC the same as the REST API?

No. Both let outside programs work with a site, but they are separate interfaces, and blocking one leaves the other as it was. Do not block the REST API along with xmlrpc.php: the block editor is built on it.

Should I turn XML-RPC off?

If nothing you use calls it, yes. WordPress's guidance is to disable it when you do not use it and, when you do, to restrict it and limit how often it can be called. Find out first whether Jetpack or a mobile app depends on it.

PHP 8 removed XML-RPC. Does that affect WordPress?

No. What left PHP's standard bundle in version 8.0 is a separate extension with the same name. Jetpack's documentation says Jetpack does not use it, and WordPress's xmlrpc.php runs on its own code. The file answers on a server that does not have the extension installed.

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.