I have a VM instance that receives a lot of spam/bot traffic attempting to hack the instance such as New Request to /blog/wp-includes/wlwmanifest.xml. Although none of these are successful it adds strain to the instance.

As far as the admin interface URL is concerned, note that this is already exposed via the wp-includes/wlwmanifest.xml file, which also defines a couple other URLs-of-note in relative terms to the xmlrpc.php API endpoint. This would probably be a more natural location to add the login_url, unless there is some move afoot to deprecate the wlwmanifest.xml file. 041b061a72

