3 min read
In this age of AI where every Tom Dick and Harry has become a developer, so too have they become hackers.
WordPress security needs to be taken seriously. Even if you think you have done everything, hackers will find a way around it.
Website Squadron incorporates all the known best practices for WordPress security. The most valuable things you can do for your website are to keep your plugins up to date and licensed, use a modern security plugin like Defender Pro, and use a CDN like Cloudflare.
And even with all those, there are still tweaks and nuances one needs to be aware of, like creating a rule to block access to the xmlrpc.php file.
If you are tired of watching your WordPress server waste precious CPU and RAM on endless bot attacks, this small action can go a long way.
We shows you exactly how to block WordPress XMLRPC requests before they hit your website, using Cloudflare’s Web Application Firewall (WAF), so malicious traffic never reaches your origin server.
You’ll get zero PHP execution, no WordPress bootstrap overhead, cleaner security logs, and noticeable performance gains, all while keeping Jetpack or mobile app functionality intact with smart Managed Challenge options.
If you run a WordPress site, you’ve likely noticed repeated hits to /xmlrpc.php in your security logs. These requests come from bots probing for weaknesses, often trying brute-force logins or launching DDoS-style amplification attacks.
Even a simple “Access Denied” or “Forbidden” response from your server still uses CPU and RAM. When thousands of these requests arrive daily, they add up to real resource waste, slower performance, and cluttered logs.
Blocking this file at the edge with Cloudflare changes everything. Cloudflare stops the requests before they ever reach your origin server, no PHP execution, no WordPress loading, and zero extra load on your hosting.
This simple move delivers immediate benefits: cleaner logs, lower resource usage, and one less attack vector.
The xmlrpc.php file is a legacy WordPress feature for remote publishing and pingbacks. While the modern REST API has largely replaced it, the old endpoint remains active by default on most sites.
Attackers love it because:
Security plugins like Defender Pro often log “IXR Class Error” entries when these bots arrive. By the time you see the log, the damage (in the form of wasted resources) has already happened.
Moving the block to Cloudflare’s Web Application Firewall (WAF) fixes this at the network level.
Cloudflare makes this straightforward, even on free plans.
Log in to Cloudflare and select the domain you want to protect.
Go to Security > Security Rules
Click Create rule.
Give it a clear name, such as “Block XMLRPC Attacks”.
Set the matching condition:
Choose the action:
Click Deploy.
Cloudflare now handles these requests at the edge.
Some tools still rely on xmlrpc.php:
A full block may break these features. In those cases:
If you’re unsure whether you need XML-RPC, test after deploying. Most modern sites function perfectly without it.
Visit https://yourwebsite.com/xmlrpc.php in a private browser window.
With the rule active, you should see a Cloudflare block or challenge page instead of the default message “XML-RPC server accepts POST requests only” or any WordPress error.
Check your security plugin logs (such as Defender Pro). You should see a sharp drop in IXR-related alerts because the requests never reach your server.
Site owners who implement this report:
One well-known WordPress expert recently highlighted seeing 70k requests to xmlrpc.php in a single day on a site before blocking it.
If you’re not actively using XMLRPC for remote publishing, there’s almost no reason to leave it open.
Blocking /xmlrpc.php directly in Cloudflare WAF prevents malicious traffic from ever reaching your WordPress server. You save resources, reduce log noise, and cut off an entire category of automated attacks.
For most sites, a simple Block rule on the URI path does the job. If you use Jetpack or the mobile app, opt for a Managed Challenge or add targeted allow conditions instead.
Conclusion
What some of our customers had to say:
EXCELLENT
Based on 38 reviews
Posted on Google![]()
Denis Cojocaru13/02/2026Trustindex verifies that the original source of the review is Google.
Cea mai bună agenție SEO din București, Sector 6. Staful știe ce face, am avut rezultate foarte bune cu ei!Posted on Google![]()
Georg Wittb25/01/2026Trustindex verifies that the original source of the review is Google.
A friend recommended me this seo agency in Bucharest. After working with them I can say, they are very professional & they really understand how it improve your digital presence.Posted on Google![]()
Carmine D'Onofrio25/01/2026Trustindex verifies that the original source of the review is Google.
I was pleasantly surprized to find the best SEO agency în Romania, right here în Sector 6 of all places. I highly recommend them.Posted on Google![]()
Mircea Popescu23/01/2026Trustindex verifies that the original source of the review is Google.
Locuiesc in București, sector 6 și am fost surprins să aflu că există o agenție SEO fix lângă casă.Posted on Google![]()
dan albu10/01/2026Trustindex verifies that the original source of the review is Google.
Cea mai buna agentie SEO cu care am colaborat! Recomand cu incredere!!Posted on Google![]()
Mike Meyerson01/11/2025Trustindex verifies that the original source of the review is Google.
It's refreshing to work with an agency that truly understands the latest SEO guidelines and how to implement them effectively with WordPress sites. Their passion for helping clients succeed is evident. We saw impressive results much faster than we had expected. After some mediocre attempts with other providers, we're glad to have found them. Highly recommended!Posted on Google![]()
Enea Ionut21/10/2025Trustindex verifies that the original source of the review is Google.
Mii de multumiri Christiaan!!! Recomand cu incredere Website Squadron! Am colaborat pentru a ne imbunatati vizibilitatea online, iar rezultatele sunt clare. Strategia lor integrata de SEO, implementarea eficienta a campaniilor de Google Ads si optimizrea platformei WordPress au dus la o crestere vizibila a pozitiei noastre in clasamentul Google. Comunicarea fost excelenta, iar expertiza lor in domeniu este de necontestat. Un partener de incredere pentru crestere organica si platita.Posted on Google![]()
Fiona Kertalli09/10/2025Trustindex verifies that the original source of the review is Google.
We found the best seo agency in Bucharest. It is a pleasure to work with these guys.Posted on Google![]()
Buck south Landscaping30/09/2025Trustindex verifies that the original source of the review is Google.
"We get incredible results from this seo agency, sitiated in Romania of all places."Posted on Google![]()
Agustin Sanchez30/09/2025Trustindex verifies that the original source of the review is Google.
⭐️⭐️⭐️⭐️⭐️ “Website Squadron did an outstanding job building my website! They were professional, responsive, and really took the time to understand my business. The design looks clean, modern, and easy to use. I’ve already noticed more customers finding me online thanks to their work. Highly recommend Website Squadron for anyone looking to grow their business with a strong online presence!”
When you hand your WordPress site over to Website Squadron, we take full responsibility for the technical side so you don’t have to. We handle regular plugin and theme updates, perform daily or weekly backups with easy restore options, run security scans and harden your site (including Defender Pro configurations like blocking xmlrpc.php at the edge with Cloudflare), monitor uptime, and keep your site fast with CDN optimization. We act as your dedicated WordPress support squadron, making content changes, fixing issues, and ensuring everything stays secure and up to date, while you focus on running your business.
Yes. As part of managing your WordPress website, we block xmlrpc.php directly at the Cloudflare edge. This stops malicious bots before they reach your server, eliminates unnecessary CPU and RAM usage, and dramatically reduces “IXR Class Error” alerts in Defender Pro. You get a hardened, protected site without lifting a finger. We set up the custom WAF rules, monitor the results, and adjust as needed, so your site stays clean, fast, and secure around the clock.
Almost none. Once you’re on the WordPress Care Package, we become the administrators on your site and handle all the maintenance, updates, security tweaks, and optimizations for you. You simply tell us what changes you want (new pages, text updates, images, or features), and our team makes them happen quickly.
We provide 16/7 (we sleep) human support, regular reports, and peace of mind knowing your site is professionally managed on a secure VPS with free Cloudflare CDN. No technical headaches, no surprise downtime, and no wasted time on WordPress tasks.
This post was written by u/WebsiteCatalyst Hassan on 27 March 2026.
If you have any questions, try our FAQ.
I need an SEO wingman