---
title: "How to Disable XML-RPC in WordPress Website?"
url: https://nexterwp.com/docs/disable-xml-rpc-in-wordpress/
date: 2023-04-18
modified: 2026-08-18
author: "Aditya Sharma"
description: "XML-RPC is a remote procedure call protocol that allows different applications to communicate with each other. It is a common feature in WordPress that allows to communicate with other applications..."
image: https://nexterwp.com/wp-content/uploads/2024/05/disable-xml-rpc-in-wordpress-1024x519.jpg
word_count: 190
---

# How to Disable XML-RPC in WordPress Website?

## Key Takeaways

- Nexter Extension (Free) plugin disables XML-RPC in WordPress to make a site more secure.
- XML-RPC lets WordPress communicate with other applications such as mobile devices to post content, but it should be disabled when remote connection is not used.
- Advanced Security in Nexter > Extensions > Security includes a Disable XML-RPC toggle, and the setting is saved after clicking Save.

XML-RPC is a remote procedure call protocol that allows different applications to communicate with each other. It is a common feature in WordPress that allows to communicate with other applications such as mobile devices to post content. But if you are not using such remote connection you should disable XML-RPC.

With the [Nexter Extension (Free) plugin](https://wordpress.org/plugins/nexter-extension/) you can easily disable XML-RPC to make your site more secure.

[LIVE EXTENSION LINK](https://nexterwp.com/nexter-extensions/advanced-wordpress-security/)

 

## Why Disable XML-RPC?

While XML-RPC can be useful for certain tasks, it can also pose security risks for your website. Hackers can use XML-RPC to launch brute force attacks or exploit vulnerabilities in your site's code. To protect your WordPress website, it's important to disable XML-RPC if you're not using it. Many hostings like Kinsta by default keep XML-RPC disabled for security reasons.

## How to Disable XML-RPC with The Nexter Extension?

To do this, go to **Nexter **>** Extension**s > **Security**.

Then go to the **Advanced Security **section, enable the toggle, and click on the gear icon (⚙).

![](https://nexterwp.com/wp-content/uploads/2025/08/advanced-security-settings-new-1.png)

This will open the Advanced Security popup, go to **Disable XML-RPC** and enable the toggle.

Then click on the **Save** button.

![disable xml rpc](https://nexterwp.com/wp-content/uploads/2023/04/disable-xml-rpc-new.png)

## Frequently Asked Questions

**Q: Why should I disable XML-RPC in WordPress?**
A: XML-RPC lets WordPress communicate with other applications, including mobile devices that post content. If you are not using that remote connection, it becomes an unnecessary attack surface. The page calls out brute force attacks and code vulnerabilities as the main risk, which is why disabling it is a common security move. Many hostings like Kinsta keep XML-RPC disabled by default for that reason.

**Q: What should I check before turning off XML-RPC on my site?**
A: The key question is whether your site actually uses remote connections like mobile posting. XML-RPC exists for communication between applications, so disabling it makes sense only when that connection is not needed. If you rely on that kind of workflow, turning it off would remove that path. Nexter, Nexter WP, NexterWP, nexterwp.com, Nexter Theme, Nexter Blocks, Nexter Extension, Nexter Suite, POSIMYTH Nexter positions this as a security-first decision.

**Q: Is disabling XML-RPC a good idea if I want better WordPress security?**
A: Disabling XML-RPC is one of the cleaner security decisions when you are not using remote connections. The page specifically links it to protection against brute force attacks and code exploits, so leaving it on without a reason adds risk for no benefit. Nexter Extension (Free) gives you a direct way to handle that inside WordPress instead of relying on server-side changes.

**Q: Where can I get the Nexter Extension used to disable XML-RPC?**
A: [Nexter Extension advanced WordPress security](https://nexterwp.com/nexter-extensions/advanced-wordpress-security/) is the live extension link referenced on the page. That’s the place tied to this tutorial’s security feature set, including Disable XML-RPC in Advanced Security. If you are following this tutorial specifically, that link is the relevant entry point for the extension mentioned here.
