How to Enable XML-RPC in WordPress Hosting
XML-RPC is supported on our WordPress hosting platform. If your website or a third-party service needs XML-RPC, you can access and manage your website’s .htaccess file through the hosting control panel and File Manager.
This guide explains how XML-RPC works, where to find the relevant WordPress files, how to allow or restrict XML-RPC requests, and what to check if an XML-RPC connection fails.
Does Our WordPress Hosting Support XML-RPC?
Yes. XML-RPC is supported on our WordPress hosting platform.
Customers have direct access to their website files, including the .htaccess file. This means you can review and manage rules that affect access to xmlrpc.php without needing to request that the hosting team make changes on your behalf.
If XML-RPC is not working, the cause may be within WordPress, a plugin, a security configuration, a firewall or WAF rule, a CDN, an .htaccess rule, authentication, PHP, or the third-party service making the request.
What Is XML-RPC in WordPress?
XML-RPC is a WordPress interface that allows external applications and services to communicate with a WordPress website.
It can be used by applications and services that need to perform actions on a WordPress website remotely, including publishing content, accessing certain WordPress functions and communicating with third-party services.
Some WordPress services and plugins may use XML-RPC, while others use the WordPress REST API instead.
Where Is the WordPress XML-RPC File?
The standard WordPress XML-RPC endpoint is:
/xmlrpc.phpThe file is normally located in the main WordPress installation directory, alongside files such as wp-config.php and directories such as wp-admin, wp-content and wp-includes.
For many websites hosted on our platform, the main website directory is public_html.
Access Your Website’s .htaccess File
You can access your website’s .htaccess file directly through the hosting control panel’s File Manager.
To access your hosting files:
- Log in to your Web Hosting Control Panel.
- Open the hosting service for the website you want to manage.
- Open File Manager.
- Open the
public_htmldirectory, if this is the document root for your website. - Locate the
.htaccessfile.
Files beginning with a full stop are hidden files on many systems. If you cannot see .htaccess, check that hidden files are being displayed in File Manager.
Back Up Your .htaccess File Before Making Changes
Before changing .htaccess, we recommend making a backup of the existing file.
You can download a copy or create a duplicate so that you can restore the previous configuration if a change causes an unexpected problem.
Incorrect rules can affect website access, redirects, security controls and other website functionality, so make changes carefully.
Enable XML-RPC Access
If XML-RPC access has been restricted by an existing configuration, you may need to review your .htaccess rules.
For example, a rule allowing requests to the XML-RPC file can be configured as follows:
<Files "xmlrpc.php">
Require all granted
</Files>This is an example configuration only. Existing website rules, security settings and other configurations should also be checked before adding or changing rules.
Allow XML-RPC from a Specific IP Address
If you only want an authorised service or known IP address to access XML-RPC, you can restrict access to specific IP addresses.
For example:
<Files "xmlrpc.php">
Require ip 203.0.113.25
</Files>Multiple IP addresses can also be specified where required:
<Files "xmlrpc.php">
Require ip 203.0.113.25 198.51.100.10
</Files>Only use IP addresses that you know belong to the service or application that needs access. If the service uses changing IP addresses, an IP-based restriction may prevent legitimate requests from reaching your website.
Allow XML-RPC for a Trusted Service
If a trusted third-party service requires XML-RPC, check its documentation to determine which endpoint, authentication method and access requirements it uses.
If the service provides fixed IP addresses, you may be able to restrict XML-RPC access to those addresses rather than allowing requests from every external address.
Do not add IP addresses simply because a connection is failing. Confirm the addresses with the service provider first.
XML-RPC and Jetpack
Some WordPress services, including Jetpack functionality, may communicate with WordPress websites using XML-RPC.
If Jetpack or another service cannot connect to your website, this does not necessarily mean that XML-RPC is unavailable on the hosting platform.
Check the complete connection path, including WordPress, plugins, .htaccess, security settings, firewall or WAF rules, CDN configuration and authentication.
Check Whether XML-RPC Is Available
The XML-RPC endpoint for a WordPress website is normally:
https://example.co.uk/xmlrpc.phpReplace example.co.uk with your own domain name.
Opening the address in a browser does not always provide a complete test of XML-RPC functionality because XML-RPC requests are normally made using POST requests rather than a standard browser page request.
A response from xmlrpc.php can therefore look different from a normal WordPress page.
Check Whether WordPress Has Disabled XML-RPC
WordPress plugins and custom code can disable or restrict XML-RPC functionality.
Check your active plugins and any custom WordPress configuration if an external service cannot connect.
Security and performance plugins may also contain settings that disable XML-RPC or restrict access to it.
If XML-RPC was previously working and then stopped working following a plugin installation, update or configuration change, check the plugin settings and recent changes first.
Check .htaccess Rules Blocking XML-RPC
Your .htaccess file may contain rules that restrict access to xmlrpc.php.
Look for rules that:
- Block access to
xmlrpc.php. - Restrict access to particular IP addresses.
- Deny external requests.
- Apply security restrictions to PHP files.
- Redirect requests to another location.
- Return an access denied response.
If you are unsure what a particular rule does, take a backup before changing it and check with the developer or service that added the rule.
XML-RPC and WordPress Security
XML-RPC can be useful for legitimate integrations, but it can also be targeted by automated requests. For this reason, some WordPress security plugins and configurations restrict or disable XML-RPC.
If you need XML-RPC for a legitimate service, check whether your security configuration is preventing the connection.
Where practical, restricting access to known services or trusted IP addresses can reduce unnecessary exposure while still allowing the required integration to operate.
Do not remove security rules without understanding what they do.
XML-RPC vs WordPress REST API
XML-RPC and the WordPress REST API are separate interfaces.
If an application reports that it cannot connect to WordPress, first check which interface it actually requires.
A failure involving the REST API does not necessarily indicate an XML-RPC problem, and an XML-RPC connection failure does not necessarily indicate a REST API problem.
Check the documentation for the application or service to confirm the required endpoint.
Troubleshoot XML-RPC 401 Errors
A 401 response generally indicates an authentication or authorisation problem.
- Check the username and password or authentication credentials.
- Check whether a security plugin is enforcing additional authentication.
- Check whether the external service is using the correct WordPress account.
- Check whether application passwords or another authentication method are required.
- Check whether another security layer is requesting authentication before the XML-RPC request reaches WordPress.
A 401 response does not by itself demonstrate that XML-RPC has been disabled by the hosting platform.
Troubleshoot XML-RPC 403 Errors
A 403 response generally indicates that access to the requested resource has been forbidden.
- Check your
.htaccessrules. - Check WordPress security plugins.
- Check firewall and WAF rules.
- Check CDN security settings.
- Check IP restrictions.
- Check whether the external service’s IP address is permitted.
If a security rule blocks xmlrpc.php, changing that rule may be necessary if the XML-RPC connection is required.
Troubleshoot XML-RPC 500 Errors
A 500 response indicates that an error occurred while processing the request.
Possible causes include:
- A WordPress plugin error.
- A PHP error.
- Invalid or conflicting configuration.
- A problem with custom code.
- A resource-related problem.
- A security plugin or other plugin interfering with the request.
Check the WordPress error logs and PHP error logs where available. If the error began after a recent plugin, theme or configuration change, review that change first.
Troubleshoot XML-RPC Timeouts
A timeout means that the connection did not receive a response within the expected period.
Possible causes include:
- Slow WordPress processing.
- Plugin or theme code taking too long to complete.
- High website resource usage.
- External service connection problems.
- Firewall or WAF inspection.
- CDN or proxy configuration.
- Network connectivity problems.
A timeout does not automatically indicate that XML-RPC is blocked. The complete request path should be checked.
Common Causes of XML-RPC Connection Failures
When troubleshooting an XML-RPC connection, check each part of the connection rather than assuming the hosting platform is the source of the problem.
| What to Check | What to Look For |
|---|---|
| .htaccess | Rules that block, restrict or redirect requests to xmlrpc.php. |
| WordPress | Settings, custom code or configuration that disables or restricts XML-RPC. |
| Security plugins | Security rules that block XML-RPC requests. |
| Firewall or WAF | Rules preventing external XML-RPC requests from reaching the website. |
| CDN | Security, access or caching rules affecting XML-RPC requests. |
| IP restrictions | Whether the external service’s current IP address is permitted. |
| Authentication | Incorrect credentials, authentication restrictions or account permissions. |
| PHP | PHP errors, resource usage or application-level problems. |
| WordPress plugins | Plugin conflicts, security settings or XML-RPC restrictions. |
| Third-party service | Incorrect endpoint, authentication details or connection requirements. |
| REST API | Whether the application actually requires the REST API rather than XML-RPC. |
XML-RPC Is Available on Our WordPress Hosting
XML-RPC is supported on our WordPress hosting platform and customers have direct access to their website configuration.
You can access your website’s .htaccess file through File Manager and review or manage rules affecting XML-RPC access.
This allows you to configure XML-RPC access according to the requirements of your WordPress website, plugins and third-party services.
Important Information About .htaccess Changes
.htaccess is an important website configuration file. Changes can affect access to your website and other website functionality.
- Make a backup before making changes.
- Only change rules that you understand.
- Check existing rules before adding new ones.
- Test the website after making changes.
- Keep a record of configuration changes.
If a change causes an unexpected result, restore your previous configuration and test again.
When to Contact WordPress Hosting Support
Our WordPress hosting support team can help investigate hosting platform issues, including server-side availability, resource allocation and platform-level problems.
When contacting support about an XML-RPC problem, provide as much information as possible, including:
- Your website domain.
- The XML-RPC endpoint being used.
- The external service or application making the request.
- The date and approximate time of the failure.
- The HTTP status code, if available.
- The complete error message.
- Whether the problem affects all requests or only a particular service.
- Any recent changes to WordPress, plugins, themes, security settings or
.htaccess.
This information can help identify whether the issue is related to the hosting platform, WordPress configuration, a plugin, a security rule, an external service or another part of the connection.
Default XML-RPC Request Flow
An XML-RPC request passes through several layers before it reaches the WordPress XML-RPC endpoint. The hosting platform allowing the request does not necessarily mean that WordPress will accept or process it.
A typical XML-RPC request flow looks like this:
External Service
↓
Hosting Platform
↓
Website Security / Firewall / WAF
↓
.htaccess Rules
↓
WordPress Application
↓
WordPress Plugins / Security Configuration
↓
WordPress XML-RPC Handler
↓
/xmlrpc.php
↓
Requested XML-RPC Action1. External Service Sends the XML-RPC Request
The process starts when an external application or service sends a request to your WordPress website’s XML-RPC endpoint.
https://example.co.uk/xmlrpc.phpThe external service may be a WordPress application, plugin, integration or another third-party service that uses XML-RPC.
2. The Request Reaches the Hosting Platform
The request first reaches the hosting infrastructure for the website. If XML-RPC access is available on the hosting platform, the request can continue through to the website.
Our WordPress hosting platform supports XML-RPC requests. However, allowing the request at the hosting level does not guarantee that the request will ultimately be accepted by WordPress.
3. Security and Access Controls Are Checked
Depending on the website configuration, the request may then be evaluated by security and access controls such as firewall or WAF rules, CDN security settings and website access rules.
If one of these layers blocks the request, the request may never reach the WordPress application.
4. .htaccess Rules Are Applied
The website’s .htaccess configuration can also affect whether the request is permitted to continue.
For example, an existing rule could restrict access to xmlrpc.php, allow only specific IP addresses or deny the request entirely.
Customers have direct access to their website’s .htaccess file through File Manager, allowing these rules to be reviewed and managed.
5. The Request Reaches the WordPress Application
If the request passes the hosting and website-level access controls, it can reach the WordPress application.
At this stage, WordPress and its installed plugins can still affect how the request is handled.
6. WordPress Plugins and Security Configuration Can Affect the Request
Plugins can modify WordPress behaviour and may disable, restrict, authenticate or otherwise process XML-RPC requests.
Security plugins are particularly relevant because they may apply additional rules to XML-RPC requests. A plugin can therefore prevent an XML-RPC request from reaching the final WordPress handler even when the hosting platform allows the request.
7. The Request Reaches the XML-RPC Endpoint
If the request passes the previous layers, WordPress can process the request through its XML-RPC functionality at:
/xmlrpc.phpThe XML-RPC handler then processes the requested action and returns a response to the service that originally made the request.
Why the Request Flow Matters
This layered request flow is important when troubleshooting XML-RPC connection problems. A request can be permitted by the hosting platform but still be blocked or rejected at a later stage.
| Layer | What Can Happen |
|---|---|
| Hosting platform | The request is accepted or rejected by the hosting infrastructure. |
| Firewall / WAF / CDN | Security or access rules can block or challenge the request. |
| .htaccess | Website rules can allow, restrict, redirect or deny the request. |
| WordPress | WordPress processes the incoming request. |
| Plugins | A plugin can modify, restrict or block XML-RPC functionality. |
| XML-RPC handler | The request reaches /xmlrpc.php and the requested action is processed. |
For this reason, an XML-RPC connection failure should be investigated across the complete request path rather than assuming that the hosting platform is the source of the problem.
Frequently Asked Questions
Yes. XML-RPC is supported on our WordPress hosting platform.
XML-RPC is supported on our platform. If a particular website cannot connect using XML-RPC, check the website’s WordPress configuration, plugins, security settings, .htaccess, firewall or WAF rules, CDN configuration and the third-party service making the request.
Yes. Customers can access their website files through the hosting control panel’s File Manager, including the .htaccess file where it is present.
Yes. You can configure access rules to permit specific IP addresses where this is appropriate for the service you are using.
Jetpack and other WordPress services may use XML-RPC for certain functionality. If a connection fails, check the complete connection path and the requirements of the service.
No. A 403 response can be caused by website configuration, .htaccess, a security plugin, a firewall, WAF rules, CDN configuration or IP restrictions. These should be checked before identifying the cause.
No. A 500 response indicates that an error occurred while processing the request. WordPress plugins, PHP errors, custom code, configuration problems and resource issues can all contribute to a 500 response.
Yes. Plugins can modify or restrict XML-RPC behaviour, apply security rules, introduce PHP errors or otherwise interfere with external requests.
Yes. Where appropriate, access can be restricted using website configuration rules, security settings or other access controls. Make sure any restriction still permits the authorised service that needs to connect.
Check recent changes first. Review WordPress plugins, security settings, .htaccess, firewall or WAF rules, CDN settings, authentication details and any changes made by the external service.
If the problem remains, provide the relevant error message, status code, endpoint and timing information when contacting hosting support.
Need assistance?
Our team can help you with getting this done. Please join our live chat, and one of our agents will provide step-by-step instructions on how to enable xml-rpc in WordPress Hosting
