WordPress powers millions of websites around the world, but its popularity also makes it an attractive target for automated attacks, malicious bots and cybercriminals. One WordPress feature that deserves particular attention from a security perspective is XML-RPC.
XML-RPC has been part of WordPress for many years and allows external applications to communicate remotely with a WordPress website. While there are situations where this functionality can be useful, many modern WordPress websites simply don’t need it.
If your website doesn’t require XML-RPC, blocking it can help reduce the number of potential routes attackers can use against your WordPress installation.
At Birch Hosting, we take this additional security precaution for our customers by blocking XML-RPC as standard on our cPanel hosting platform. This forms part of our security-focused approach to hosting WordPress and other websites.
What Is WordPress XML-RPC?
XML-RPC is a remote communication protocol. In WordPress, it is normally accessed through the xmlrpc.php file located within the WordPress installation.
Its purpose is to allow external applications and services to perform certain actions on your WordPress website remotely. Historically, this was particularly useful for applications that needed to publish or manage WordPress content without accessing the normal WordPress administration area.
The problem is that functionality designed to allow remote access can also provide another endpoint for attackers to target.
Modern WordPress websites often use alternative technologies, including the WordPress REST API, meaning many website owners may have XML-RPC enabled without actually needing it.
Why Can XML-RPC Be a WordPress Security Risk?
Leaving unnecessary services available increases the potential attack surface of a website.
XML-RPC has historically been associated with several types of malicious activity, including automated authentication attempts and abuse of WordPress functionality.
Attackers frequently use automated systems containing huge lists of usernames and passwords, sometimes obtained from previous data breaches. If a website owner has reused a password or chosen a weak password, automated attacks can potentially result in an account being compromised.
XML-RPC has also historically been abused through WordPress pingback functionality. This can allow vulnerable or compromised WordPress websites to be misused when generating unwanted traffic towards other websites.
For many WordPress websites, therefore, there is a simple question worth asking:
If your website doesn’t need XML-RPC, why leave an unnecessary remote-access endpoint exposed to the internet?
Birch Hosting Blocks XML-RPC as Standard
When you host your WordPress website on a Birch Hosting cPanel hosting account, XML-RPC is blocked as standard.
We don’t expect every customer to be a WordPress security expert or to know that an older WordPress feature could potentially increase their website’s attack surface.
Instead, we take a security-focused approach at hosting level.
Blocking XML-RPC as standard helps reduce unnecessary access to the WordPress XML-RPC endpoint before it becomes another potential route for automated attacks.
This is an important distinction because website security shouldn’t rely entirely on individual website owners remembering to change every WordPress security setting themselves.
If a customer has a legitimate requirement for XML-RPC functionality, they can contact our support team to discuss their requirements.
WordPress Security Goes Beyond XML-RPC
Blocking XML-RPC is only one part of protecting a WordPress website.
Website owners should also:
- Keep WordPress core, themes and plugins updated.
- Remove plugins and themes that are no longer required.
- Use strong and unique passwords.
- Enable two-factor authentication where available.
- Avoid installing themes or plugins from unknown sources.
- Maintain reliable website backups.
- Regularly review WordPress administrator accounts.
- Choose a hosting provider that takes security seriously.
The last point is particularly important.
You can carefully secure WordPress itself, but your website still relies on the hosting environment underneath it.
Security-Focused UK cPanel Hosting
At Birch Hosting, security is an important part of how we operate our cPanel hosting platform.
In addition to blocking WordPress XML-RPC as standard, our hosting environment uses technologies including CloudLinux and Imunify360 to provide additional layers of protection around hosted websites.
CloudLinux helps isolate individual hosting accounts and manage server resources. This isolation is particularly important in a shared hosting environment because each hosting account operates within its own controlled environment.
Imunify360 provides additional security capabilities designed specifically for web hosting environments, including malware protection and proactive defence against malicious activity.
Combined with sensible WordPress security practices, these technologies provide a layered approach to website security.
What Are the Benefits of cPanel Hosting?
Security isn’t the only reason Birch Hosting uses cPanel.
cPanel is one of the world’s most established web hosting control panels, providing website owners with an easy-to-use interface for managing important parts of their hosting account.
Depending on your hosting package, cPanel provides straightforward management of:
Email accounts – Create and manage professional email addresses using your own domain name.
Domains and subdomains – Manage domains and associated website configurations.
Website files – Access and manage your website files using cPanel File Manager.
Databases – Create and manage MySQL databases used by WordPress and other content management systems.
PHP – Access PHP versions, extensions and configuration options without needing to administer your own server.
Backups – Backup and restoration facilities can make recovering website data considerably easier.
For WordPress users, cPanel provides considerable control over their hosting without requiring them to become a Linux server administrator.
Fast and Secure WordPress Hosting
Security should not come at the expense of website performance.
Birch Hosting’s cPanel hosting platform combines NVMe storage, LiteSpeed web server technology, CloudLinux and Imunify360 to provide an environment designed around performance, reliability and security.
WordPress websites can also benefit from LiteSpeed caching, while selected premium hosting accounts can take advantage of Redis object caching.
Add our policy of blocking XML-RPC as standard, and customers benefit from another layer of protection without having to configure it themselves.
This combination can be particularly valuable for business websites, where slow performance, downtime or a compromised website can affect customers, enquiries, search rankings and your company’s reputation.
Secure Your WordPress Website with Birch Hosting
WordPress security shouldn’t depend on one plugin, one password or one security setting.
It works best as a layered approach.
At Birch Hosting, XML-RPC is blocked as standard on our cPanel hosting accounts, helping reduce unnecessary exposure of WordPress websites to XML-RPC-based attacks.
Combine that with Imunify360, CloudLinux, LiteSpeed, NVMe storage and our UK-based support, and you have a hosting platform designed with both security and performance in mind.
If you’re looking for fast, secure UK cPanel hosting, explore our cPanel Website Hosting and cPanel Business Hosting packages.
Don’t just secure WordPress. Start with hosting that’s designed with security in mind.
Choose Birch Hosting for fast, secure UK cPanel hosting – with WordPress XML-RPC blocked as standard.

