Block WordPress xmlrpc.php access

3 min read

In this age of AI where every Tom Dick and Harry has become a developer, so too have they become hackers. 

WordPress security needs to be taken seriously. Even if you think you have done everything, hackers will find a way around it. 

Website Squadron incorporates all the known best practices for WordPress security. The most valuable things you can do for your website are to keep your plugins up to date and licensed, use a modern security plugin like Defender Pro, and use a CDN like Cloudflare. 

And even with all those, there are still tweaks and nuances one needs to be aware of, like creating a rule to block access to the xmlrpc.php file. 

 

 

Table of Contents

Inroduction

If you are tired of watching your WordPress server waste precious CPU and RAM on endless bot attacks, this small action can go a long way. 

We shows you exactly how to block WordPress XMLRPC requests before they hit your website, using Cloudflare’s Web Application Firewall (WAF), so malicious traffic never reaches your origin server.

You’ll get zero PHP execution, no WordPress bootstrap overhead, cleaner security logs, and noticeable performance gains, all while keeping Jetpack or mobile app functionality intact with smart Managed Challenge options.

If you run a WordPress site, you’ve likely noticed repeated hits to /xmlrpc.php in your security logs. These requests come from bots probing for weaknesses, often trying brute-force logins or launching DDoS-style amplification attacks.

Even a simple “Access Denied” or “Forbidden” response from your server still uses CPU and RAM. When thousands of these requests arrive daily, they add up to real resource waste, slower performance, and cluttered logs.

Blocking this file at the edge with Cloudflare changes everything. Cloudflare stops the requests before they ever reach your origin server, no PHP execution, no WordPress loading, and zero extra load on your hosting.

This simple move delivers immediate benefits: cleaner logs, lower resource usage, and one less attack vector.

Why xmlrpc.php Attracts? 

The xmlrpc.php file is a legacy WordPress feature for remote publishing and pingbacks. While the modern REST API has largely replaced it, the old endpoint remains active by default on most sites.

Attackers love it because:

  • It supports system.multicall, letting them test hundreds of username/password combinations in a single request.
  • Pingback functionality can amplify traffic in DDoS attacks.
  • Bots hit it constantly, even if you’ve disabled the feature inside WordPress.

Security plugins like Defender Pro often log “IXR Class Error” entries when these bots arrive. By the time you see the log, the damage (in the form of wasted resources) has already happened.

Moving the block to Cloudflare’s Web Application Firewall (WAF) fixes this at the network level.

Cloudflare Custom Rule

Cloudflare makes this straightforward, even on free plans.

  1. Log in to Cloudflare and select the domain you want to protect.

  2. Go to Security > Security Rules

  3. Click Create rule.

  4. Give it a clear name, such as “Block XMLRPC Attacks”.

  5. Set the matching condition:

    • Field: URI Path
    • Operator: equals (or contains for broader coverage)
    • Value: /xmlrpc.php 
  6. Choose the action:

    • Block, for maximum protection if you don’t need the endpoint.
  7. Click Deploy.

Cloudflare now handles these requests at the edge.

Jetpack and Mobile App Users

Some tools still rely on xmlrpc.php:

  • Jetpack uses it for certain connections (especially with the ?for=jetpack query string).
  • The official WordPress mobile app can also depend on it for some functions.

A full block may break these features. In those cases:

  • Switch the action to Managed Challenge instead of Block.
  • Or create a more advanced rule that allows specific Jetpack IP ranges while blocking everything else. Cloudflare already has built-in protection (managed rule WP0007) that whitelists genuine Jetpack traffic.

If you’re unsure whether you need XML-RPC, test after deploying. Most modern sites function perfectly without it.

Confirm the Rule

Visit https://yourwebsite.com/xmlrpc.php in a private browser window.

With the rule active, you should see a Cloudflare block or challenge page instead of the default message “XML-RPC server accepts POST requests only” or any WordPress error.

Check your security plugin logs (such as Defender Pro). You should see a sharp drop in IXR-related alerts because the requests never reach your server.

Extra Tips to Maximize Protection

  • Combine this rule with other common WordPress hardening steps, such as rate limiting on /wp-login.php.
  • If you want to redirect instead of block, some users forward /xmlrpc.php* to the homepage via a Page Rule (though a direct block is usually cleaner).
  • Monitor Cloudflare analytics for blocked requests to confirm the volume you’re stopping.

Impact You’ll Notice

Site owners who implement this report:

  • Fewer spikes in CPU/RAM usage during attack waves.
  • Much cleaner security logs with fewer false alerts.
  • Overall snappier site performance because the origin server stays focused on real visitors.

One well-known WordPress expert recently highlighted seeing 70k requests to xmlrpc.php in a single day on a site before blocking it.

If you’re not actively using XMLRPC for remote publishing, there’s almost no reason to leave it open.

Summary

Blocking /xmlrpc.php directly in Cloudflare WAF prevents malicious traffic from ever reaching your WordPress server. You save resources, reduce log noise, and cut off an entire category of automated attacks.

For most sites, a simple Block rule on the URI path does the job. If you use Jetpack or the mobile app, opt for a Managed Challenge or add targeted allow conditions instead.

Conclusion

Conclusion

What some of our customers had to say:

Posted on Google Google
Denis Cojocaru profile picture
Denis Cojocaru
13/02/2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Cea mai bună agenție SEO din București, Sector 6. Staful știe ce face, am avut rezultate foarte bune cu ei!
Posted on Google Google
Georg Wittb profile picture
Georg Wittb
25/01/2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
A friend recommended me this seo agency in Bucharest. After working with them I can say, they are very professional & they really understand how it improve your digital presence.
Posted on Google Google
Carmine D'Onofrio profile picture
Carmine D'Onofrio
25/01/2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I was pleasantly surprized to find the best SEO agency în Romania, right here în Sector 6 of all places. I highly recommend them.
Posted on Google Google
Mircea Popescu profile picture
Mircea Popescu
23/01/2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Locuiesc in București, sector 6 și am fost surprins să aflu că există o agenție SEO fix lângă casă.
Posted on Google Google
dan albu profile picture
dan albu
10/01/2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Cea mai buna agentie SEO cu care am colaborat! Recomand cu incredere!!
Posted on Google Google
Mike Meyerson profile picture
Mike Meyerson
01/11/2025
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
It's refreshing to work with an agency that truly understands the latest SEO guidelines and how to implement them effectively with WordPress sites. Their passion for helping clients succeed is evident. We saw impressive results much faster than we had expected. After some mediocre attempts with other providers, we're glad to have found them. Highly recommended!
Posted on Google Google
Enea Ionut profile picture
Enea Ionut
21/10/2025
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Mii de multumiri Christiaan!!! Recomand cu incredere Website Squadron! Am colaborat pentru a ne imbunatati vizibilitatea online, iar rezultatele sunt clare. Strategia lor integrata de SEO, implementarea eficienta a campaniilor de Google Ads si optimizrea platformei WordPress au dus la o crestere vizibila a pozitiei noastre in clasamentul Google. Comunicarea fost excelenta, iar expertiza lor in domeniu este de necontestat. Un partener de incredere pentru crestere organica si platita.
Posted on Google Google
Fiona Kertalli profile picture
Fiona Kertalli
09/10/2025
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
We found the best seo agency in Bucharest. It is a pleasure to work with these guys.
Posted on Google Google
Buck south Landscaping profile picture
Buck south Landscaping
30/09/2025
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
"We get incredible results from this seo agency, sitiated in Romania of all places."
Posted on Google Google
Agustin Sanchez profile picture
Agustin Sanchez
30/09/2025
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
⭐️⭐️⭐️⭐️⭐️ “Website Squadron did an outstanding job building my website! They were professional, responsive, and really took the time to understand my business. The design looks clean, modern, and easy to use. I’ve already noticed more customers finding me online thanks to their work. Highly recommend Website Squadron for anyone looking to grow their business with a strong online presence!”

FAQ

What does Website Squadron actually do when they manage my WordPress website?

When you hand your WordPress site over to Website Squadron, we take full responsibility for the technical side so you don’t have to. We handle regular plugin and theme updates, perform daily or weekly backups with easy restore options, run security scans and harden your site (including Defender Pro configurations like blocking xmlrpc.php at the edge with Cloudflare), monitor uptime, and keep your site fast with CDN optimization. We act as your dedicated WordPress support squadron, making content changes, fixing issues, and ensuring everything stays secure and up to date, while you focus on running your business.

Yes. As part of managing your WordPress website, we block xmlrpc.php directly at the Cloudflare edge. This stops malicious bots before they reach your server, eliminates unnecessary CPU and RAM usage, and dramatically reduces “IXR Class Error” alerts in Defender Pro. You get a hardened, protected site without lifting a finger. We set up the custom WAF rules, monitor the results, and adjust as needed, so your site stays clean, fast, and secure around the clock.

Almost none. Once you’re on the WordPress Care Package, we become the administrators on your site and handle all the maintenance, updates, security tweaks, and optimizations for you. You simply tell us what changes you want (new pages, text updates, images, or features), and our team makes them happen quickly.

We provide 16/7 (we sleep) human support, regular reports, and peace of mind knowing your site is professionally managed on a secure VPS with free Cloudflare CDN. No technical headaches, no surprise downtime, and no wasted time on WordPress tasks.

This post was written by u/WebsiteCatalyst Hassan on 27 March 2026.

If you have any questions, try our FAQ.