XML-RPC
XML-RPC is an older WordPress interface that, if left enabled and unused, can be abused for brute-force and amplification attacks.
What it is
XML-RPC is a remote interface that predates the modern WordPress REST API. It let external applications interact with a site — posting content, fetching data — through a single endpoint at /xmlrpc.php.
Most modern setups no longer need it, but it's often left enabled by default, quietly offering attackers a useful entry point.
Why it matters
XML-RPC has two well-known abuses. Its system.multicall method lets an attacker try many password combinations in a single request, making brute-force attacks far more efficient. And its pingback feature can be used to bounce attacks off your site against others. If you don't use XML-RPC, disabling it removes both risks.
How Pentrawl checks it
Pentrawl checks whether /xmlrpc.php is active on your site. If it responds, we flag it as a warning, since it's an interface most sites can safely disable.
How to fix it
If you don't rely on XML-RPC, disable it. A security plugin can turn it off with one setting, or you can block the endpoint at the server level.
location = /xmlrpc.php { deny all; return 404; }