
Unless you are using the API, disable XML-RPC. Even if you are using it. Identify it you can limit access to a static IP address or range. This prevents script execution from remote sources attempting to gain access to your WordPress instance. The easiest way to disable XML-RPC is to add the following to .htaccess in the root of your website.
AI-generated from public information. Please verify against actual business needs.