WordPress login pages (/wp-login.php and /wp-admin/) are targeted by bots daily. These bots run automatically around the clock, cycling through common usernames such as admin, administrator, and user paired with millions of popular passwords. If your site uses a weak password or has no limit on login attempts, a bot can guess its way in within hours. This article covers multiple layers of protection you should implement immediately, complete with working .htaccess examples, recommended plugins, and how to spot an attack in progress.
Effective WordPress login protection relies on the principle of Defense in Depth: layering multiple safeguards instead of trusting a single measure. If one layer is breached, others still stand. For example, even if a bot correctly guesses your password, two-factor authentication will still stop it from logging in. In this guide we'll secure your site from the application level (WordPress plugins) all the way down to the web server level (.htaccess).
1. Change the Login URL (Most Important)
By default, WordPress uses /wp-login.php — easy for bots to find. Use the WPS Hide Login plugin to change it to an unpredictable URL:
- Install Plugin: WPS Hide Login
- Go to Settings → WPS Hide Login
- Change Login URL to something custom like
/staff-portal-2026 - Save and remember the new URL
The Complete Login Security Checklist
Before diving into each measure, here's a summary table of everything you should do, along with its priority and setup difficulty. Use it as a checklist so you don't miss any critical step:
| Measure | Priority | Difficulty | Tool |
|---|---|---|---|
| Strong password (16+ characters) | Critical | Easy | Password Manager |
| Enable Two-Factor Authentication (2FA) | Critical | Medium | WP 2FA / Google Authenticator |
| Limit failed login attempts | High | Easy | Limit Login Attempts Reloaded |
| Change / hide the login URL | High | Easy | WPS Hide Login |
| Disable XML-RPC (if unused) | Medium | Easy | .htaccess / Plugin |
| Add CAPTCHA / reCAPTCHA | Medium | Easy | reCAPTCHA / hCaptcha plugin |
| Restrict wp-admin by IP (.htaccess) | High (if static IP) | Medium | .htaccess |
You don't have to do all of these in one day. Start with the items marked "Critical" priority and "Easy" difficulty — set a strong password and enable 2FA — then gradually layer on the remaining measures as appropriate for your site.
2. Limit Failed Login Attempts
Install Limit Login Attempts Reloaded plugin:
- Lock IP after 3-5 failed login attempts
- Increase lockout time on repeated failures
- Email admin notifications when lockouts occur
3. Enable Two-Factor Authentication (2FA)
Install WP 2FA or Google Authenticator plugin:
- Install and activate the plugin
- Go to Users → Profile → Two-Factor Options
- Enable TOTP (Google Authenticator / Authy)
- Scan the QR code with your Authenticator app
4. Use a Strong Admin Password
- At least 16 characters mixing numbers, upper/lowercase, and special characters
- Use a Password Manager like Bitwarden or 1Password
- Never reuse passwords across accounts
5. Block wp-admin with IP Whitelist (.htaccess)
If you have a static IP address, add to .htaccess:
<Files wp-login.php> Order Deny,Allow Deny from all Allow from 1.2.3.4 </Files>
Replace 1.2.3.4 with your actual IP.
6. Disable XML-RPC (If Not Needed)
XML-RPC is exploited for parallel brute force attacks. Add to .htaccess:
<Files xmlrpc.php> Order Deny,Allow Deny from all </Files>
Or use the Disable XML-RPC plugin.
Protecting wp-admin with .htaccess (Deep Dive)
Protecting at the web server level (Apache) with the .htaccess file has a key advantage: it blocks bots before their request ever reaches PHP/WordPress, saving server resources and being more secure than relying on plugins alone. Below are techniques that work in practice.
Restrict wp-admin access by IP
If you manage your site from an office or home with a static IP, you can allow only your IP to access the wp-admin/ directory by creating an .htaccess file directly inside the wp-admin/ folder:
<RequireAll> Require ip 1.2.3.4 Require ip 203.0.113.0/24 </RequireAll>
The first line allows a single IP, while the second allows an entire subnet (useful for offices where the IP changes within a range). ⚠️ Warning: if your IP is dynamic (it changes every time you reset your router), this method can lock you out of your own site. Use 2FA + Limit Login instead.
Add a second password layer (HTTP Basic Auth)
Another highly effective technique is to password-protect wp-login.php at the server level. Bots will hit a browser popup asking for a username/password before they even reach WordPress's login page. First create an .htpasswd file (ideally outside the document root), then add this to the .htaccess at your site root:
<Files wp-login.php> AuthType Basic AuthName "Restricted Area" AuthUserFile /home/user/.htpasswd Require valid-user </Files>
Create the .htpasswd file with the command htpasswd -c /home/user/.htpasswd myadmin on the server, or use an online htpasswd generator. This stops brute force attacks almost completely, because typical bots cannot get past the HTTP Basic Auth layer.
Block requests with no Referer (filter fake POSTs)
Most bots fire POST requests directly at wp-login.php without a valid HTTP Referer. You can block these with a mod_rewrite rule:
RewriteEngine On
RewriteCond %{REQUEST_METHOD} POST
RewriteCond %{HTTP_REFERER} !^https://(www\.)?yoursite\.com [NC]
RewriteRule ^(.*)?wp-login\.php(.*)$ - [F]
Replace yoursite.com with your real domain. This rule blocks only POST requests (login form submissions) that don't originate from your own site, without affecting normal users.
7. Install a Security Plugin
- Wordfence Security — WAF + Malware Scanner + Login Security
- Solid Security (iThemes) — 30+ security measures combined
- All-In-One Security (AIOS) — Free and beginner-friendly
Use only one security plugin at a time — don't install several simultaneously, as they can conflict and slow down your site or break login. If you use Wordfence or Solid Security, Limit Login and 2FA features are usually built in, so you won't need separate plugins for them.
Signs of a Brute Force Attack and How to Respond
Catching an attack early lets you respond before an account is compromised. Here are the warning signs that your WordPress login page is under attack:
- Unusually slow site or high CPU usage — bots fire rapid requests that strain the server, sometimes enough that the host temporarily suspends the account.
- A flood of lockout notification emails — if Limit Login Attempts is set up, you'll receive far more IP-lockout emails than usual.
- Strange IPs repeatedly attempting to log in — check the Wordfence log and you'll see foreign IPs trying to log in as
adminhundreds of times. - New user accounts you didn't create — a sign the site may already be breached. Respond immediately.
- Files modified for no apparent reason — check with Wordfence's File Integrity Scanner.
How to respond when you find an attack:
- Change every admin password immediately and force-logout all sessions.
- Enable 2FA if you haven't — it stops brute force instantly even if a password has leaked.
- Block the attacking IP via Wordfence or
.htaccess(Require not ip 1.2.3.4). - If the attack is heavy, enable Cloudflare's "Under Attack Mode" to filter bots at the CDN level before they reach your server.
- Scan the entire site for malware with Imunify360 or Wordfence to ensure no backdoor remains.
Frequently Asked Questions (FAQ)
Is changing the login URL secure enough on its own?
Changing the login URL is "security through obscurity" — it greatly reduces the number of bots hitting your site, but it doesn't provide 100% protection if an attacker discovers the new URL. Always combine it with 2FA and a strong password; never rely on this method alone.
Should I disable XML-RPC, and will it break anything?
If you don't use Jetpack, the WordPress mobile app, or external services that require XML-RPC, you can disable it to close off a parallel brute force vector (XML-RPC can test many passwords in a single request). But if you manage your site via the mobile app, use a plugin that limits XML-RPC methods instead of disabling it entirely.
Which is more important, 2FA or Limit Login Attempts?
They serve different roles and should be used together. Limit Login slows bots down and blocks IPs that fail too often, while 2FA is the final barrier that stops an attacker even after your password has leaked. If you must pick one, 2FA offers stronger protection — but in practice, enable both.
Can hosting help protect against brute force too?
Yes. Good hosting includes server-level protection such as Imunify360, which automatically detects and blocks IPs that repeatedly fail login, plus a WAF (Web Application Firewall) that filters malicious requests before they reach WordPress — giving you an extra layer even without configuring plugins yourself.
Priority Summary: (1) Change Login URL → (2) Limit attempts → (3) Enable 2FA → (4) Strong password → (5) Security Plugin. Doing all 5 reduces risk by over 95%.
Hosting with Built-In WordPress Security
AsiaGB Hosting includes cPGuard Security, SpamAssassin, and Imunify360 for automatic malware protection.
View Hosting Plans