Is XML-RPC still a security risk?

yes it is a security risk. Should it be disabled? most likely. Is it a OMG BBQ type of emergency? no.

If you have strong passwords for your accounts, it is not more of a security risk than the login form. It is a pointless security risk in the sense that it provides an additional attack vector and it code is probably not well maintained.