Disable XML-RPC

Description: Controls XML-RPC behavior to reduce abuse while keeping compatibility when needed.

How it works: disable_xmlrpc_behavior determines whether XML-RPC is allowed, partially restricted, or denied with an error page.

How to access / configure:

  1. WP Admin → AegisShield → Hardening.
  2. Locate XML-RPC behavior dropdown.
  3. Choose the desired behavior and Save Changes.

Recommended setting: Use “Allow core XML‑RPC but restrict dangerous methods” when compatibility is needed; otherwise deny XML‑RPC on sites that don’t use it.