Notes
Below is the explanation from the Hostiger website. It is also to be found on xmlrpc.html.
xmlrpc.php is a WordPress core file that allows external applications to communicate with your website remotely. It uses the XML-RPC (XML Remote Procedure Call) protocol, which sends XML-formatted requests over HTTP to perform actions such as publishing posts, managing content through mobile apps, and handling pingbacks.
While xmlrpc.php was useful for early WordPress integrations, it is now unnecessary for most modern websites. Most current tools rely on the WordPress REST API instead, which uses JSON and supports more modern authentication workflows. Attackers target XML-RPC for brute-force logins, system.multicall abuse, and pingback floods that overwhelm servers in a DDoS (Distributed Denial of Service) attack, because it relies on older access methods.
For most WordPress site owners, the safest approach is to disable or restrict xmlrpc.php unless a specific plugin, mobile app, or external service still needs it. This can be done with a security plugin, server rules such as .htaccess on Apache, or a web application firewall.
RPC vs. REST
There are many places on the Internet that explain the differences between XMLRPC and REST. This page is my strating point to understand the principles behind both techniques.
Top