Skip to main content
< All Topics
Print

How to Enable XML-RPC in WordPress Hosting

On this page:

XML-RPC is supported on our WordPress hosting platform. If your website or a third-party service needs XML-RPC, you can access and manage your website’s .htaccess file through the hosting control panel and File Manager.

This guide explains how XML-RPC works, where to find the relevant WordPress files, how to allow or restrict XML-RPC requests, and what to check if an XML-RPC connection fails.

Does Our WordPress Hosting Support XML-RPC?

Yes. XML-RPC is supported on our WordPress hosting platform.

Customers have direct access to their website files, including the .htaccess file. This means you can review and manage rules that affect access to xmlrpc.php without needing to request that the hosting team make changes on your behalf.

If XML-RPC is not working, the cause may be within WordPress, a plugin, a security configuration, a firewall or WAF rule, a CDN, an .htaccess rule, authentication, PHP, or the third-party service making the request.

What Is XML-RPC in WordPress?

XML-RPC is a WordPress interface that allows external applications and services to communicate with a WordPress website.

It can be used by applications and services that need to perform actions on a WordPress website remotely, including publishing content, accessing certain WordPress functions and communicating with third-party services.

Some WordPress services and plugins may use XML-RPC, while others use the WordPress REST API instead.

Where Is the WordPress XML-RPC File?

The standard WordPress XML-RPC endpoint is:

/xmlrpc.php

The file is normally located in the main WordPress installation directory, alongside files such as wp-config.php and directories such as wp-admin, wp-content and wp-includes.

For many websites hosted on our platform, the main website directory is public_html.

Access Your Website’s .htaccess File

You can access your website’s .htaccess file directly through the hosting control panel’s File Manager.

To access your hosting files:

  1. Log in to your Web Hosting Control Panel.
  2. Open the hosting service for the website you want to manage.
  3. Open File Manager.
  4. Open the public_html directory, if this is the document root for your website.
  5. Locate the .htaccess file.

Files beginning with a full stop are hidden files on many systems. If you cannot see .htaccess, check that hidden files are being displayed in File Manager.

Back Up Your .htaccess File Before Making Changes

Before changing .htaccess, we recommend making a backup of the existing file.

You can download a copy or create a duplicate so that you can restore the previous configuration if a change causes an unexpected problem.

Incorrect rules can affect website access, redirects, security controls and other website functionality, so make changes carefully.

Enable XML-RPC Access

If XML-RPC access has been restricted by an existing configuration, you may need to review your .htaccess rules.

For example, a rule allowing requests to the XML-RPC file can be configured as follows:

<Files "xmlrpc.php">
    Require all granted
</Files>

This is an example configuration only. Existing website rules, security settings and other configurations should also be checked before adding or changing rules.

Allow XML-RPC from a Specific IP Address

If you only want an authorised service or known IP address to access XML-RPC, you can restrict access to specific IP addresses.

For example:

<Files "xmlrpc.php">
    Require ip 203.0.113.25
</Files>

Multiple IP addresses can also be specified where required:

<Files "xmlrpc.php">
    Require ip 203.0.113.25 198.51.100.10
</Files>

Only use IP addresses that you know belong to the service or application that needs access. If the service uses changing IP addresses, an IP-based restriction may prevent legitimate requests from reaching your website.

Allow XML-RPC for a Trusted Service

If a trusted third-party service requires XML-RPC, check its documentation to determine which endpoint, authentication method and access requirements it uses.

If the service provides fixed IP addresses, you may be able to restrict XML-RPC access to those addresses rather than allowing requests from every external address.

Do not add IP addresses simply because a connection is failing. Confirm the addresses with the service provider first.

XML-RPC and Jetpack

Some WordPress services, including Jetpack functionality, may communicate with WordPress websites using XML-RPC.

If Jetpack or another service cannot connect to your website, this does not necessarily mean that XML-RPC is unavailable on the hosting platform.

Check the complete connection path, including WordPress, plugins, .htaccess, security settings, firewall or WAF rules, CDN configuration and authentication.

Check Whether XML-RPC Is Available

The XML-RPC endpoint for a WordPress website is normally:

https://example.co.uk/xmlrpc.php

Replace example.co.uk with your own domain name.

Opening the address in a browser does not always provide a complete test of XML-RPC functionality because XML-RPC requests are normally made using POST requests rather than a standard browser page request.

A response from xmlrpc.php can therefore look different from a normal WordPress page.

Check Whether WordPress Has Disabled XML-RPC

WordPress plugins and custom code can disable or restrict XML-RPC functionality.

Check your active plugins and any custom WordPress configuration if an external service cannot connect.

Security and performance plugins may also contain settings that disable XML-RPC or restrict access to it.

If XML-RPC was previously working and then stopped working following a plugin installation, update or configuration change, check the plugin settings and recent changes first.

Check .htaccess Rules Blocking XML-RPC

Your .htaccess file may contain rules that restrict access to xmlrpc.php.

Look for rules that:

  • Block access to xmlrpc.php.
  • Restrict access to particular IP addresses.
  • Deny external requests.
  • Apply security restrictions to PHP files.
  • Redirect requests to another location.
  • Return an access denied response.

If you are unsure what a particular rule does, take a backup before changing it and check with the developer or service that added the rule.

XML-RPC and WordPress Security

XML-RPC can be useful for legitimate integrations, but it can also be targeted by automated requests. For this reason, some WordPress security plugins and configurations restrict or disable XML-RPC.

If you need XML-RPC for a legitimate service, check whether your security configuration is preventing the connection.

Where practical, restricting access to known services or trusted IP addresses can reduce unnecessary exposure while still allowing the required integration to operate.

Do not remove security rules without understanding what they do.

XML-RPC vs WordPress REST API

XML-RPC and the WordPress REST API are separate interfaces.

If an application reports that it cannot connect to WordPress, first check which interface it actually requires.

A failure involving the REST API does not necessarily indicate an XML-RPC problem, and an XML-RPC connection failure does not necessarily indicate a REST API problem.

Check the documentation for the application or service to confirm the required endpoint.

Troubleshoot XML-RPC 401 Errors

A 401 response generally indicates an authentication or authorisation problem.

  • Check the username and password or authentication credentials.
  • Check whether a security plugin is enforcing additional authentication.
  • Check whether the external service is using the correct WordPress account.
  • Check whether application passwords or another authentication method are required.
  • Check whether another security layer is requesting authentication before the XML-RPC request reaches WordPress.

A 401 response does not by itself demonstrate that XML-RPC has been disabled by the hosting platform.

Troubleshoot XML-RPC 403 Errors

A 403 response generally indicates that access to the requested resource has been forbidden.

  • Check your .htaccess rules.
  • Check WordPress security plugins.
  • Check firewall and WAF rules.
  • Check CDN security settings.
  • Check IP restrictions.
  • Check whether the external service’s IP address is permitted.

If a security rule blocks xmlrpc.php, changing that rule may be necessary if the XML-RPC connection is required.

Troubleshoot XML-RPC 500 Errors

A 500 response indicates that an error occurred while processing the request.

Possible causes include:

  • A WordPress plugin error.
  • A PHP error.
  • Invalid or conflicting configuration.
  • A problem with custom code.
  • A resource-related problem.
  • A security plugin or other plugin interfering with the request.

Check the WordPress error logs and PHP error logs where available. If the error began after a recent plugin, theme or configuration change, review that change first.

Troubleshoot XML-RPC Timeouts

A timeout means that the connection did not receive a response within the expected period.

Possible causes include:

  • Slow WordPress processing.
  • Plugin or theme code taking too long to complete.
  • High website resource usage.
  • External service connection problems.
  • Firewall or WAF inspection.
  • CDN or proxy configuration.
  • Network connectivity problems.

A timeout does not automatically indicate that XML-RPC is blocked. The complete request path should be checked.

Common Causes of XML-RPC Connection Failures

When troubleshooting an XML-RPC connection, check each part of the connection rather than assuming the hosting platform is the source of the problem.

What to CheckWhat to Look For
.htaccessRules that block, restrict or redirect requests to xmlrpc.php.
WordPressSettings, custom code or configuration that disables or restricts XML-RPC.
Security pluginsSecurity rules that block XML-RPC requests.
Firewall or WAFRules preventing external XML-RPC requests from reaching the website.
CDNSecurity, access or caching rules affecting XML-RPC requests.
IP restrictionsWhether the external service’s current IP address is permitted.
AuthenticationIncorrect credentials, authentication restrictions or account permissions.
PHPPHP errors, resource usage or application-level problems.
WordPress pluginsPlugin conflicts, security settings or XML-RPC restrictions.
Third-party serviceIncorrect endpoint, authentication details or connection requirements.
REST APIWhether the application actually requires the REST API rather than XML-RPC.

XML-RPC Is Available on Our WordPress Hosting

XML-RPC is supported on our WordPress hosting platform and customers have direct access to their website configuration.

You can access your website’s .htaccess file through File Manager and review or manage rules affecting XML-RPC access.

This allows you to configure XML-RPC access according to the requirements of your WordPress website, plugins and third-party services.

Important Information About .htaccess Changes

.htaccess is an important website configuration file. Changes can affect access to your website and other website functionality.

  • Make a backup before making changes.
  • Only change rules that you understand.
  • Check existing rules before adding new ones.
  • Test the website after making changes.
  • Keep a record of configuration changes.

If a change causes an unexpected result, restore your previous configuration and test again.

When to Contact WordPress Hosting Support

Our WordPress hosting support team can help investigate hosting platform issues, including server-side availability, resource allocation and platform-level problems.

When contacting support about an XML-RPC problem, provide as much information as possible, including:

  • Your website domain.
  • The XML-RPC endpoint being used.
  • The external service or application making the request.
  • The date and approximate time of the failure.
  • The HTTP status code, if available.
  • The complete error message.
  • Whether the problem affects all requests or only a particular service.
  • Any recent changes to WordPress, plugins, themes, security settings or .htaccess.

This information can help identify whether the issue is related to the hosting platform, WordPress configuration, a plugin, a security rule, an external service or another part of the connection.

Default XML-RPC Request Flow

An XML-RPC request passes through several layers before it reaches the WordPress XML-RPC endpoint. The hosting platform allowing the request does not necessarily mean that WordPress will accept or process it.

A typical XML-RPC request flow looks like this:

External Service
      ↓
Hosting Platform
      ↓
Website Security / Firewall / WAF
      ↓
.htaccess Rules
      ↓
WordPress Application
      ↓
WordPress Plugins / Security Configuration
      ↓
WordPress XML-RPC Handler
      ↓
/xmlrpc.php
      ↓
Requested XML-RPC Action

1. External Service Sends the XML-RPC Request

The process starts when an external application or service sends a request to your WordPress website’s XML-RPC endpoint.

https://example.co.uk/xmlrpc.php

The external service may be a WordPress application, plugin, integration or another third-party service that uses XML-RPC.

2. The Request Reaches the Hosting Platform

The request first reaches the hosting infrastructure for the website. If XML-RPC access is available on the hosting platform, the request can continue through to the website.

Our WordPress hosting platform supports XML-RPC requests. However, allowing the request at the hosting level does not guarantee that the request will ultimately be accepted by WordPress.

3. Security and Access Controls Are Checked

Depending on the website configuration, the request may then be evaluated by security and access controls such as firewall or WAF rules, CDN security settings and website access rules.

If one of these layers blocks the request, the request may never reach the WordPress application.

4. .htaccess Rules Are Applied

The website’s .htaccess configuration can also affect whether the request is permitted to continue.

For example, an existing rule could restrict access to xmlrpc.php, allow only specific IP addresses or deny the request entirely.

Customers have direct access to their website’s .htaccess file through File Manager, allowing these rules to be reviewed and managed.

5. The Request Reaches the WordPress Application

If the request passes the hosting and website-level access controls, it can reach the WordPress application.

At this stage, WordPress and its installed plugins can still affect how the request is handled.

6. WordPress Plugins and Security Configuration Can Affect the Request

Plugins can modify WordPress behaviour and may disable, restrict, authenticate or otherwise process XML-RPC requests.

Security plugins are particularly relevant because they may apply additional rules to XML-RPC requests. A plugin can therefore prevent an XML-RPC request from reaching the final WordPress handler even when the hosting platform allows the request.

7. The Request Reaches the XML-RPC Endpoint

If the request passes the previous layers, WordPress can process the request through its XML-RPC functionality at:

/xmlrpc.php

The XML-RPC handler then processes the requested action and returns a response to the service that originally made the request.

Why the Request Flow Matters

This layered request flow is important when troubleshooting XML-RPC connection problems. A request can be permitted by the hosting platform but still be blocked or rejected at a later stage.

LayerWhat Can Happen
Hosting platformThe request is accepted or rejected by the hosting infrastructure.
Firewall / WAF / CDNSecurity or access rules can block or challenge the request.
.htaccessWebsite rules can allow, restrict, redirect or deny the request.
WordPressWordPress processes the incoming request.
PluginsA plugin can modify, restrict or block XML-RPC functionality.
XML-RPC handlerThe request reaches /xmlrpc.php and the requested action is processed.

For this reason, an XML-RPC connection failure should be investigated across the complete request path rather than assuming that the hosting platform is the source of the problem.

Frequently Asked Questions

Is XML-RPC supported on your WordPress hosting?

Yes. XML-RPC is supported on our WordPress hosting platform.

Is XML-RPC blocked by default?

XML-RPC is supported on our platform. If a particular website cannot connect using XML-RPC, check the website’s WordPress configuration, plugins, security settings, .htaccess, firewall or WAF rules, CDN configuration and the third-party service making the request.

Can I edit my .htaccess file?

Yes. Customers can access their website files through the hosting control panel’s File Manager, including the .htaccess file where it is present.

Can I allow XML-RPC from specific IP addresses?

Yes. You can configure access rules to permit specific IP addresses where this is appropriate for the service you are using.

Can XML-RPC be used with Jetpack?

Jetpack and other WordPress services may use XML-RPC for certain functionality. If a connection fails, check the complete connection path and the requirements of the service.

Does a 403 error mean the hosting platform has disabled XML-RPC?

No. A 403 response can be caused by website configuration, .htaccess, a security plugin, a firewall, WAF rules, CDN configuration or IP restrictions. These should be checked before identifying the cause.

Does a 500 error mean XML-RPC is blocked?

No. A 500 response indicates that an error occurred while processing the request. WordPress plugins, PHP errors, custom code, configuration problems and resource issues can all contribute to a 500 response.

Can WordPress plugins cause XML-RPC connection failures?

Yes. Plugins can modify or restrict XML-RPC behaviour, apply security rules, introduce PHP errors or otherwise interfere with external requests.

Can I restrict XML-RPC access?

Yes. Where appropriate, access can be restricted using website configuration rules, security settings or other access controls. Make sure any restriction still permits the authorised service that needs to connect.

What should I check if XML-RPC suddenly stops working?

Check recent changes first. Review WordPress plugins, security settings, .htaccess, firewall or WAF rules, CDN settings, authentication details and any changes made by the external service.
If the problem remains, provide the relevant error message, status code, endpoint and timing information when contacting hosting support.

Need assistance?

Our team can help you with getting this done. Please join our live chat, and one of our agents will provide step-by-step instructions on how to enable xml-rpc in WordPress Hosting