Solved

Best Security Hardening Practices for WordPress XML-RPC & WP-JSON in 2026

โ€ข 15-Sep-2026 10:48 AM (3 weeks ago)
2 Replies
246 Views

Official Verified Solution

Solved by Imran Hossain

Jump to Answer ↓

Add this to your .htaccess root file:

# Block XML-RPC
<Files xmlrpc.php>
Order Deny,Allow
Deny from all
</Files>

# Block Author Enumeration
RewriteCond %{QUERY_STRING} author=([0-9]+) [NC]
RewriteRule ^$ / [R=301,L]

For Nginx, return 403 on location = /xmlrpc.php. This will instantly drop server CPU usage from bot scraping! ๐Ÿ›ก๏ธ๐Ÿ’ป

R
15-Sep-2026 10:48 AM โ€ข 45 Karma

We noticed brute-force bots hitting xmlrpc.php and user enumeration via /wp-json/wp/v2/users. What is the cleanest .htaccess or Nginx snippet to block these completely without breaking Jetpack or mobile app logins?

I
16-Sep-2026 12:48 PM โ€ข 75 Karma

Add this to your .htaccess root file:

# Block XML-RPC
<Files xmlrpc.php>
Order Deny,Allow
Deny from all
</Files>

# Block Author Enumeration
RewriteCond %{QUERY_STRING} author=([0-9]+) [NC]
RewriteRule ^$ / [R=301,L]

For Nginx, return 403 on location = /xmlrpc.php. This will instantly drop server CPU usage from bot scraping! ๐Ÿ›ก๏ธ๐Ÿ’ป

R
17-Sep-2026 11:48 AM โ€ข 45 Karma

Worked like magic! Dropped unauthorized bot requests by 90%. Thanks @imran.hossain! โœ…

Join the Discussion

Please log in to your client account to reply or participate in this conversation.

Log in to Reply
0%