Knowledgebase

Blocking Brute-Force Attacks on wp-login.php Print

  • wordpress, php, bruteforce, password, plugins, resourcelimits, security, firewall, twofactor, htaccess
  • 0

Automated bots hammer /wp-login.php and /xmlrpc.php on every WordPress site on the internet. Even when they never guess the password, the requests themselves consume your account's CPU and entry processes.

1. Limit login attempts

Install Limit Login Attempts Reloaded or use the equivalent feature in Wordfence. Set 4 allowed retries and a lockout of 60 minutes, escalating on repeat offences.

2. Enable two-factor authentication

A stolen password is useless without the second factor. Wordfence, Solid Security and the official Two Factor plugin all work well.

3. Change the login URL

Plugins such as WPS Hide Login move the login page to a path only you know. This stops the vast majority of untargeted bot traffic outright.

4. Protect the directory at server level

For the strongest protection, add HTTP authentication in front of wp-admin — see our Directory Privacy article. Bots then never reach PHP at all.

5. Block xmlrpc.php if unused

Add this to public_html/.htaccess:

<Files xmlrpc.php>
Require all denied
</Files>

Skip this if you use the WordPress mobile app, Jetpack, or remote publishing tools.

6. Use Cloudflare

A firewall rule that rate-limits or challenges requests to /wp-login.php stops the traffic before it reaches our server at all.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot