About this question
Quite often when I find resources about XML-RPC vulnerabilities with respect to the xmlrpc.php file commonly found exposed on WordPress sites, I find alongside the recommendation to remove or block the xmlrpc.php file that it is also recommended to remove the wlwmanifest.xml (Windows Live Writer Manifest link in WordPress. So far as I can tell wlwmanifest.xml does not offer up any WordPress version information, nor does wlwmanifest.xml seem able to be leveraged for testing username/password credentials as xmlrpc.php does.
Most of the content in the sources below states, in summary, "remove code if not using as it is unnecessary." Can anyone be clear as to why the wlwmanifest.xml file should also be removed/blocked? If this is not a security concern, is this just simply an optimization?
Thanks. Sources (that recomment removal/block of wlwmanifest.xml): https://bestwebsoft.com/what-is-xml-rpc/ https://codeless.co/how-to-remove-wordpress-unnecessary-tags/ https://perfmatters.io/docs/remove-wlwmanifest-link-wordpress/