Quick answer
What does this usually mean?
XML-RPC can support legitimate integrations, but it is also commonly abused for authentication pressure and amplification-style behavior. The right action depends on whether the site actually needs it.
How to think about XML-RPC exposure on WordPress sites and when it may need review.
01 · Observed signal
XML-RPC can support legitimate integrations, but it is also commonly abused for authentication pressure and amplification-style behavior. The right action depends on whether the site actually needs it.
02 · Evidence to inspect
Confirm whether the site has a legitimate XML-RPC dependency.
03 · Safe next move
Run the free diagnostic to collect evidence before changing live orders or payment settings.
Start here
XML-RPC can support legitimate integrations, but it is also commonly abused for authentication pressure and amplification-style behavior. The right action depends on whether the site actually needs it.
Possible causes
Evidence checks
Decision path
Use the smallest safe step that resolves uncertainty. Implementation comes after the evidence is clear.
Quick answer
XML-RPC can support legitimate integrations, but it is also commonly abused for authentication pressure and amplification-style behavior. The right action depends on whether the site actually needs it.
First check
Confirm whether the site has a legitimate XML-RPC dependency.
Need a human decision?
If XML-RPC exposure appears alongside other public exposure findings, Security Snapshot can document the no-login public surface and recommended fixes. Credential attacks are not included in the default review.