Best Security Hardening Practices for WordPress XML-RPC & WP-JSON in 2026
Official Verified Solution
Solved by Imran Hossain
Add this to your .htaccess root file:
# Block XML-RPC
<Files xmlrpc.php>
Order Deny,Allow
Deny from all
</Files>
# Block Author Enumeration
RewriteCond %{QUERY_STRING} author=([0-9]+) [NC]
RewriteRule ^$ / [R=301,L]
For Nginx, return 403 on location = /xmlrpc.php. This will instantly drop server CPU usage from bot scraping! ๐ก๏ธ๐ป
We noticed brute-force bots hitting xmlrpc.php and user enumeration via /wp-json/wp/v2/users. What is the cleanest .htaccess or Nginx snippet to block these completely without breaking Jetpack or mobile app logins?
Add this to your .htaccess root file:
# Block XML-RPC
<Files xmlrpc.php>
Order Deny,Allow
Deny from all
</Files>
# Block Author Enumeration
RewriteCond %{QUERY_STRING} author=([0-9]+) [NC]
RewriteRule ^$ / [R=301,L]
For Nginx, return 403 on location = /xmlrpc.php. This will instantly drop server CPU usage from bot scraping! ๐ก๏ธ๐ป
Worked like magic! Dropped unauthorized bot requests by 90%. Thanks @imran.hossain! โ
Join the Discussion
Please log in to your client account to reply or participate in this conversation.