Hi sir, @wfpeter,
I get so many brute-force attack from harcker trying to access mywebsite/xmlrpc.php. although the attempts failed but i have enabled this features from the wordfence “Disable XML-RPC authentication” checkbox in Wordfence > Login Security > Settings. as suggected by you. Hope it will help stop the brute-force and complex attackes on the website.
Thanks.