WordPress sites with XML-RPC enabled, which can be exploited for DDoS amplification and brute-force attacks.
13,140sites with XML-RPC enabled
Security Risk: XML-RPC (xmlrpc.php) can be exploited for DDoS amplification attacks, brute-force password attacks via the system.multicall method, and pingback abuse. Consider disabling it if not needed.