Disable pingbacks if you got problem with DDos attacks and server load. Method for functions and method for htaccess. http://www.genesisclub.training/2182/prevent-pingback-attacks-by-disabling-xmlrpc/ http://hackguard.com/xmlrpc-php-ping-backs-hackers-denial-service-attacks https://blog.sucuri.net/2015/10/brute-force-amplification-attacks-against-wordpress-xmlrpc.html http://www.drweb.de/magazin/wordpress-sicherheit-die-xml-rpc-schnittstelle-abschalten-68045/ http://www.wpbeginner.com/plugins/how-to-disable-xml-rpc-in-wordpress/ or use the plugin: https://wordpress.org/plugins/disable-xml-rpc/
// Goes to functions
add_filter( 'wp_headers', function( $headers ) {
unset( $headers['X-Pingback'] );
return $headers;
}, 20);
add_filter( 'xmlrpc_methods', function( $methods ) {
unset( $methods['pingback.ping'] );
unset( $methods['pingback.extensions.getPingbacks'] );
return $methods;
}, 20);
<Files xmlrpc.php>
Order Deny,Allow
Deny from all
Allow from 192.0.64.0/18
Satisfy All
ErrorDocument 403 http://127.0.0.1/
</Files>