{"id":6152,"date":"2025-07-01T06:48:56","date_gmt":"2025-06-30T23:48:56","guid":{"rendered":"https:\/\/saidwp.com\/blog\/?p=6152"},"modified":"2025-07-08T06:51:20","modified_gmt":"2025-07-07T23:51:20","slug":"xmlrpc-wordpress-serangan","status":"publish","type":"post","link":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/","title":{"rendered":"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan?"},"content":{"rendered":"\n<p class=\"cta-quote\">Kalau kamu udah lama pakai WordPress, pasti pernah denger soal file <a href=\"https:\/\/www.php.net\/manual\/en\/book.xmlrpc.php\">xmlrpc.php<\/a>. Mau websitenya kosong, isinya dummy, atau sudah live produksi\u2014file ini selalu aja disamperin bot dan attacker. Kenapa bisa begitu, padahal kadang kita sendiri gak pakai fitur ini?<\/p>\n\n\n\n<p>Di artikel ini, kita bahas tuntas alasan xmlrpc.php WordPress jadi incaran, dan gimana cara aman menanganinya.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Apa Itu xmlrpc.php WordPress?<\/strong><\/h2>\n\n\n\n<p>xmlrpc.php adalah file bawaan WordPress yang digunakan untuk komunikasi jarak jauh. Misalnya:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Posting artikel lewat aplikasi WordPress mobile<br><\/li>\n\n\n\n<li>Sinkronisasi dengan Jetpack<br><\/li>\n\n\n\n<li>Mengelola komentar secara remote<br><\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress.webp\" alt=\"xmlrpc.php WordPress\" class=\"wp-image-6153\" srcset=\"https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress.webp 1024w, https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress-400x400.webp 400w, https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress-150x150.webp 150w, https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress-768x768.webp 768w, https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress-300x300.webp 300w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Semua itu dilakukan lewat XML-RPC (Remote Procedure Call berbasis XML).Tapi masalahnya? File ini <strong>sering terbuka default<\/strong> tanpa proteksi tambahan. Dan di situlah awal mula petaka.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Kenapa <\/strong><strong>xmlrpc.php WordPress<\/strong><strong> Jadi Target Serangan?<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Bisa Dipakai Buat Login<\/strong><\/h3>\n\n\n\n<p>File ini bisa dipakai buat login ke WordPress tanpa lewat \/wp-login.php. Jadi attacker bisa brute-force login tanpa ketahuan plugin keamanan biasa.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Dukung Brute-Force Massal<\/strong><\/h3>\n\n\n\n<p>Fitur system.multicall di dalam xmlrpc.php bisa kirim banyak permintaan sekaligus dalam satu kali POST. Ibaratnya, bot bisa nyerang 500 password dalam satu tembakan.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. Dipakai Buat DDoS Website Lain<\/strong><\/h3>\n\n\n\n<p>Ada fitur bernama pingback.ping yang sering disalahgunakan buat DDoS. Caranya? Bot nyuruh puluhan ribu situs WordPress ngirim request ke target yang sama. Hasilnya: server target down, dan kamu gak sadar situsmu ikut jadi zombie DDoS.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. Sumber Enum Username<\/strong><\/h3>\n\n\n\n<p>Bot bisa tebak-tebakan username dari sini. Kalau berhasil nebak admin, lanjut deh brute force password.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>5. Gak Terlindungi CAPTCHA &amp; Rate Limit<\/strong><\/h3>\n\n\n\n<p>Berbeda dengan wp-login.php, di xmlrpc.php:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Gak bisa pakai CAPTCHA<br><\/li>\n\n\n\n<li>Gak ada limit percobaan login<br><\/li>\n\n\n\n<li>Gak semua plugin keamanan ngeblok ini<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\ud83d\udd0d Kenapa Situs Kosong Juga Diserang?<\/strong><\/h2>\n\n\n\n<p>Karena yang nyerang bukan manusia. Ini kerja bot otomatis yang:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Scan semua situs acak<br><\/li>\n\n\n\n<li>Cek ada xmlrpc.php atau gak<br><\/li>\n\n\n\n<li>Langsung coba brute force atau pingback exploit<br><\/li>\n<\/ul>\n\n\n\n<p>Mereka gak peduli isi webmu. Bahkan domain kosong tapi pakai WordPress tetap kena.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\ud83d\udee1\ufe0f Cara Mengamankan <\/strong><strong>xmlrpc.php WordPress<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\ud83d\udd12 1. Nonaktifkan Jika Gak Dipakai<\/strong><\/h3>\n\n\n\n<p><strong>Kalau kamu gak pakai Jetpack atau aplikasi mobile WordPress, blok aja file ini. Di Nginx:<\/strong><\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:flex;align-items:center;padding:10px 0px 10px 16px;margin-bottom:-2px;width:100%;text-align:left;background-color:#2b2b2b;color:#c7c7c7\">Bash<\/span><span role=\"button\" tabindex=\"0\" style=\"color:#D4D4D4;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>location = \/xmlrpc.php {\n    deny all;\n}<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki dark-plus\" style=\"background-color: #1E1E1E\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #DCDCAA\">location<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #CE9178\">=<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #CE9178\">\/xmlrpc.php<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #CE9178\">{<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #DCDCAA\">deny<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #CE9178\">all<\/span><span style=\"color: #D4D4D4\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">}<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>Atau di .htaccess Apache:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:flex;align-items:center;padding:10px 0px 10px 16px;margin-bottom:-2px;width:100%;text-align:left;background-color:#2b2b2b;color:#c7c7c7\">Bash<\/span><span role=\"button\" tabindex=\"0\" style=\"color:#D4D4D4;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>&lt;Files xmlrpc.php>\n    Order Deny,Allow\n    Deny from all\n&lt;\/Files><\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki dark-plus\" style=\"background-color: #1E1E1E\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #D4D4D4\">&lt;Files xmlrpc.php&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #DCDCAA\">Order<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #CE9178\">Deny,Allow<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #DCDCAA\">Deny<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #CE9178\">from<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #CE9178\">all<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">&lt;\/Files&gt;<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>&nbsp;2. Gunakan Plugin Khusus<\/strong><\/h3>\n\n\n\n<p>Contohnya:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Disable XML-RPC<\/li>\n\n\n\n<li>Wordfence (setting: disable XML-RPC authentication)<br><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\ud83d\udd10 3. Pakai WAF<\/strong><\/h3>\n\n\n\n<p>Kalau server kamu kuat, tambahkan Web Application Firewall (WAF) seperti:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Imunify360<\/li>\n\n\n\n<li>Cloudflare (page rule khusus \/xmlrpc.php)<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Haruskah Dimatikan Selamanya?<\/strong><\/h2>\n\n\n\n<p>Kalau kamu gak pakai fitur XML-RPC, <strong>ya matikan saja<\/strong>. Tapi kalau Jetpack, app mobile, atau plugin tertentu butuh ini, kamu bisa:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Bolehkan akses hanya dari IP tertentu<br><\/li>\n\n\n\n<li>Tetap aktifkan tapi log semua aktivitasnya<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Penutup<\/strong><\/h2>\n\n\n\n<p>xmlrpc.php WordPress memang fitur lama, tapi justru karena itulah jadi pintu masuk yang banyak dilupakan. Jangan sampai jadi celah buat serangan brutal cuma gara-gara satu file gak penting buatmu.<\/p>\n\n\n\n<p>Kalau kamu butuh bantuan setup VPS, bikin landing page, bikin web, set up keamanan WordPress, hardening, audit keamanan website kamu, dan mengatasi masalah WordPress, <strong>aku bisa bantuin<\/strong>.<\/p>\n\n\n\n<p>\ud83d\udc49 Cek layanan lengkapnya di sini:<\/p>\n\n\n\n<p class=\"has-text-align-center has-white-color has-text-color has-background has-link-color wp-elements-20101b72eb4f6e76907b0c59e35759d4\" style=\"background-color:#272590\"><strong><a href=\"https:\/\/saidwp.com\/jasa\/\" target=\"_blank\" rel=\"noreferrer noopener\">    &#8211; Order Jasa SaidWP &#8211; <\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kalau kamu udah lama pakai WordPress, pasti pernah denger soal file xmlrpc.php. Mau websitenya kosong, isinya dummy, atau sudah live produksi\u2014file ini selalu aja disamperin bot dan attacker. Kenapa bisa begitu, padahal kadang kita sendiri gak pakai fitur ini? Di artikel ini, kita bahas tuntas alasan xmlrpc.php WordPress jadi incaran, dan gimana cara aman menanganinya. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":6153,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[160],"tags":[179,162],"class_list":["post-6152","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-panduan","tag-security","tag-wordpress"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan? - Blog | SaidWP<\/title>\n<meta name=\"description\" content=\"File xmlrpc.php WordPress sering jadi sasaran serangan. Kenapa ini terjadi dan bagaimana cara melindungi website kamu dari potensi bahaya.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan?\" \/>\n<meta property=\"og:description\" content=\"File xmlrpc.php WordPress sering jadi sasaran serangan. Kenapa ini terjadi dan bagaimana cara melindungi website kamu dari potensi bahaya.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog | SaidWP\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-30T23:48:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-07T23:51:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"SaidWP - Post\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan?\" \/>\n<meta name=\"twitter:description\" content=\"File xmlrpc.php WordPress sering jadi sasaran serangan. Kenapa ini terjadi dan bagaimana cara melindungi website kamu dari potensi bahaya.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress.webp\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"SaidWP - Post\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/\"},\"author\":{\"name\":\"SaidWP - Post\",\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/#\\\/schema\\\/person\\\/fd2527877c2f4049e1f118c039ed4f8d\"},\"headline\":\"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan?\",\"datePublished\":\"2025-06-30T23:48:56+00:00\",\"dateModified\":\"2025-07-07T23:51:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/\"},\"wordCount\":479,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/s3.nevaobjects.id\\\/saidwp-blog\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/01064657\\\/saidwp-xmlrpc-wordpress.webp\",\"keywords\":[\"Security\",\"WordPress\"],\"articleSection\":[\"Panduan WordPress\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/\",\"url\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/\",\"name\":\"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan? - Blog | SaidWP\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/s3.nevaobjects.id\\\/saidwp-blog\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/01064657\\\/saidwp-xmlrpc-wordpress.webp\",\"datePublished\":\"2025-06-30T23:48:56+00:00\",\"dateModified\":\"2025-07-07T23:51:20+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/#\\\/schema\\\/person\\\/fd2527877c2f4049e1f118c039ed4f8d\"},\"description\":\"File xmlrpc.php WordPress sering jadi sasaran serangan. Kenapa ini terjadi dan bagaimana cara melindungi website kamu dari potensi bahaya.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/#primaryimage\",\"url\":\"https:\\\/\\\/s3.nevaobjects.id\\\/saidwp-blog\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/01064657\\\/saidwp-xmlrpc-wordpress.webp\",\"contentUrl\":\"https:\\\/\\\/s3.nevaobjects.id\\\/saidwp-blog\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/01064657\\\/saidwp-xmlrpc-wordpress.webp\",\"width\":1024,\"height\":1024,\"caption\":\"xmlrpc.php WordPress\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/panduan\\\/xmlrpc-wordpress-serangan\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/\",\"name\":\"Blog | SaidWP\",\"description\":\"Jasa WP-nya si Said\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/#\\\/schema\\\/person\\\/fd2527877c2f4049e1f118c039ed4f8d\",\"name\":\"SaidWP - Post\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4253b93fa2ef3d268d63a481385921f1985a291cfbe522e59724772966193f17?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4253b93fa2ef3d268d63a481385921f1985a291cfbe522e59724772966193f17?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4253b93fa2ef3d268d63a481385921f1985a291cfbe522e59724772966193f17?s=96&d=mm&r=g\",\"caption\":\"SaidWP - Post\"},\"url\":\"https:\\\/\\\/saidwp.com\\\/blog\\\/author\\\/saidwp-post\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan? - Blog | SaidWP","description":"File xmlrpc.php WordPress sering jadi sasaran serangan. Kenapa ini terjadi dan bagaimana cara melindungi website kamu dari potensi bahaya.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/","og_locale":"en_US","og_type":"article","og_title":"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan?","og_description":"File xmlrpc.php WordPress sering jadi sasaran serangan. Kenapa ini terjadi dan bagaimana cara melindungi website kamu dari potensi bahaya.","og_url":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/","og_site_name":"Blog | SaidWP","article_published_time":"2025-06-30T23:48:56+00:00","article_modified_time":"2025-07-07T23:51:20+00:00","og_image":[{"width":1024,"height":1024,"url":"https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress.webp","type":"image\/webp"}],"author":"SaidWP - Post","twitter_card":"summary_large_image","twitter_title":"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan?","twitter_description":"File xmlrpc.php WordPress sering jadi sasaran serangan. Kenapa ini terjadi dan bagaimana cara melindungi website kamu dari potensi bahaya.","twitter_image":"https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress.webp","twitter_misc":{"Written by":"SaidWP - Post","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/#article","isPartOf":{"@id":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/"},"author":{"name":"SaidWP - Post","@id":"https:\/\/saidwp.com\/blog\/#\/schema\/person\/fd2527877c2f4049e1f118c039ed4f8d"},"headline":"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan?","datePublished":"2025-06-30T23:48:56+00:00","dateModified":"2025-07-07T23:51:20+00:00","mainEntityOfPage":{"@id":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/"},"wordCount":479,"commentCount":0,"image":{"@id":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/#primaryimage"},"thumbnailUrl":"https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress.webp","keywords":["Security","WordPress"],"articleSection":["Panduan WordPress"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/","url":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/","name":"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan? - Blog | SaidWP","isPartOf":{"@id":"https:\/\/saidwp.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/#primaryimage"},"image":{"@id":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/#primaryimage"},"thumbnailUrl":"https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress.webp","datePublished":"2025-06-30T23:48:56+00:00","dateModified":"2025-07-07T23:51:20+00:00","author":{"@id":"https:\/\/saidwp.com\/blog\/#\/schema\/person\/fd2527877c2f4049e1f118c039ed4f8d"},"description":"File xmlrpc.php WordPress sering jadi sasaran serangan. Kenapa ini terjadi dan bagaimana cara melindungi website kamu dari potensi bahaya.","breadcrumb":{"@id":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/#primaryimage","url":"https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress.webp","contentUrl":"https:\/\/s3.nevaobjects.id\/saidwp-blog\/blog\/wp-content\/uploads\/2025\/07\/01064657\/saidwp-xmlrpc-wordpress.webp","width":1024,"height":1024,"caption":"xmlrpc.php WordPress"},{"@type":"BreadcrumbList","@id":"https:\/\/saidwp.com\/blog\/panduan\/xmlrpc-wordpress-serangan\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/saidwp.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Kenapa xmlrpc.php WordPress Selalu Jadi Target Serangan?"}]},{"@type":"WebSite","@id":"https:\/\/saidwp.com\/blog\/#website","url":"https:\/\/saidwp.com\/blog\/","name":"Blog | SaidWP","description":"Jasa WP-nya si Said","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/saidwp.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/saidwp.com\/blog\/#\/schema\/person\/fd2527877c2f4049e1f118c039ed4f8d","name":"SaidWP - Post","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4253b93fa2ef3d268d63a481385921f1985a291cfbe522e59724772966193f17?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4253b93fa2ef3d268d63a481385921f1985a291cfbe522e59724772966193f17?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4253b93fa2ef3d268d63a481385921f1985a291cfbe522e59724772966193f17?s=96&d=mm&r=g","caption":"SaidWP - Post"},"url":"https:\/\/saidwp.com\/blog\/author\/saidwp-post\/"}]}},"_links":{"self":[{"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/posts\/6152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/comments?post=6152"}],"version-history":[{"count":2,"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/posts\/6152\/revisions"}],"predecessor-version":[{"id":6169,"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/posts\/6152\/revisions\/6169"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/media\/6153"}],"wp:attachment":[{"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/media?parent=6152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/categories?post=6152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/saidwp.com\/blog\/wp-json\/wp\/v2\/tags?post=6152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}