Securing WordPress login and wp-admin from hackers

WordPress login pages (/wp-login.php and /wp-admin/) are targeted by bots daily. These bots run automatically around the clock, cycling through common usernames such as admin, administrator, and user paired with millions of popular passwords. If your site uses a weak password or has no limit on login attempts, a bot can guess its way in within hours. This article covers multiple layers of protection you should implement immediately, complete with working .htaccess examples, recommended plugins, and how to spot an attack in progress.

Effective WordPress login protection relies on the principle of Defense in Depth: layering multiple safeguards instead of trusting a single measure. If one layer is breached, others still stand. For example, even if a bot correctly guesses your password, two-factor authentication will still stop it from logging in. In this guide we'll secure your site from the application level (WordPress plugins) all the way down to the web server level (.htaccess).

1. Change the Login URL (Most Important)

By default, WordPress uses /wp-login.php — easy for bots to find. Use the WPS Hide Login plugin to change it to an unpredictable URL:

  1. Install Plugin: WPS Hide Login
  2. Go to Settings → WPS Hide Login
  3. Change Login URL to something custom like /staff-portal-2026
  4. Save and remember the new URL

The Complete Login Security Checklist

Before diving into each measure, here's a summary table of everything you should do, along with its priority and setup difficulty. Use it as a checklist so you don't miss any critical step:

Measure Priority Difficulty Tool
Strong password (16+ characters) Critical Easy Password Manager
Enable Two-Factor Authentication (2FA) Critical Medium WP 2FA / Google Authenticator
Limit failed login attempts High Easy Limit Login Attempts Reloaded
Change / hide the login URL High Easy WPS Hide Login
Disable XML-RPC (if unused) Medium Easy .htaccess / Plugin
Add CAPTCHA / reCAPTCHA Medium Easy reCAPTCHA / hCaptcha plugin
Restrict wp-admin by IP (.htaccess) High (if static IP) Medium .htaccess

You don't have to do all of these in one day. Start with the items marked "Critical" priority and "Easy" difficulty — set a strong password and enable 2FA — then gradually layer on the remaining measures as appropriate for your site.

2. Limit Failed Login Attempts

Install Limit Login Attempts Reloaded plugin:

3. Enable Two-Factor Authentication (2FA)

Install WP 2FA or Google Authenticator plugin:

  1. Install and activate the plugin
  2. Go to Users → Profile → Two-Factor Options
  3. Enable TOTP (Google Authenticator / Authy)
  4. Scan the QR code with your Authenticator app

4. Use a Strong Admin Password

5. Block wp-admin with IP Whitelist (.htaccess)

If you have a static IP address, add to .htaccess:

<Files wp-login.php>
  Order Deny,Allow
  Deny from all
  Allow from 1.2.3.4
</Files>

Replace 1.2.3.4 with your actual IP.

6. Disable XML-RPC (If Not Needed)

XML-RPC is exploited for parallel brute force attacks. Add to .htaccess:

<Files xmlrpc.php>
  Order Deny,Allow
  Deny from all
</Files>

Or use the Disable XML-RPC plugin.

Protecting wp-admin with .htaccess (Deep Dive)

Protecting at the web server level (Apache) with the .htaccess file has a key advantage: it blocks bots before their request ever reaches PHP/WordPress, saving server resources and being more secure than relying on plugins alone. Below are techniques that work in practice.

Restrict wp-admin access by IP

If you manage your site from an office or home with a static IP, you can allow only your IP to access the wp-admin/ directory by creating an .htaccess file directly inside the wp-admin/ folder:

<RequireAll>
  Require ip 1.2.3.4
  Require ip 203.0.113.0/24
</RequireAll>

The first line allows a single IP, while the second allows an entire subnet (useful for offices where the IP changes within a range). ⚠️ Warning: if your IP is dynamic (it changes every time you reset your router), this method can lock you out of your own site. Use 2FA + Limit Login instead.

Add a second password layer (HTTP Basic Auth)

Another highly effective technique is to password-protect wp-login.php at the server level. Bots will hit a browser popup asking for a username/password before they even reach WordPress's login page. First create an .htpasswd file (ideally outside the document root), then add this to the .htaccess at your site root:

<Files wp-login.php>
  AuthType Basic
  AuthName "Restricted Area"
  AuthUserFile /home/user/.htpasswd
  Require valid-user
</Files>

Create the .htpasswd file with the command htpasswd -c /home/user/.htpasswd myadmin on the server, or use an online htpasswd generator. This stops brute force attacks almost completely, because typical bots cannot get past the HTTP Basic Auth layer.

Block requests with no Referer (filter fake POSTs)

Most bots fire POST requests directly at wp-login.php without a valid HTTP Referer. You can block these with a mod_rewrite rule:

RewriteEngine On
RewriteCond %{REQUEST_METHOD} POST
RewriteCond %{HTTP_REFERER} !^https://(www\.)?yoursite\.com [NC]
RewriteRule ^(.*)?wp-login\.php(.*)$ - [F]

Replace yoursite.com with your real domain. This rule blocks only POST requests (login form submissions) that don't originate from your own site, without affecting normal users.

7. Install a Security Plugin

Use only one security plugin at a time — don't install several simultaneously, as they can conflict and slow down your site or break login. If you use Wordfence or Solid Security, Limit Login and 2FA features are usually built in, so you won't need separate plugins for them.

Signs of a Brute Force Attack and How to Respond

Catching an attack early lets you respond before an account is compromised. Here are the warning signs that your WordPress login page is under attack:

How to respond when you find an attack:

  1. Change every admin password immediately and force-logout all sessions.
  2. Enable 2FA if you haven't — it stops brute force instantly even if a password has leaked.
  3. Block the attacking IP via Wordfence or .htaccess (Require not ip 1.2.3.4).
  4. If the attack is heavy, enable Cloudflare's "Under Attack Mode" to filter bots at the CDN level before they reach your server.
  5. Scan the entire site for malware with Imunify360 or Wordfence to ensure no backdoor remains.

Frequently Asked Questions (FAQ)

Is changing the login URL secure enough on its own?

Changing the login URL is "security through obscurity" — it greatly reduces the number of bots hitting your site, but it doesn't provide 100% protection if an attacker discovers the new URL. Always combine it with 2FA and a strong password; never rely on this method alone.

Should I disable XML-RPC, and will it break anything?

If you don't use Jetpack, the WordPress mobile app, or external services that require XML-RPC, you can disable it to close off a parallel brute force vector (XML-RPC can test many passwords in a single request). But if you manage your site via the mobile app, use a plugin that limits XML-RPC methods instead of disabling it entirely.

Which is more important, 2FA or Limit Login Attempts?

They serve different roles and should be used together. Limit Login slows bots down and blocks IPs that fail too often, while 2FA is the final barrier that stops an attacker even after your password has leaked. If you must pick one, 2FA offers stronger protection — but in practice, enable both.

Can hosting help protect against brute force too?

Yes. Good hosting includes server-level protection such as Imunify360, which automatically detects and blocks IPs that repeatedly fail login, plus a WAF (Web Application Firewall) that filters malicious requests before they reach WordPress — giving you an extra layer even without configuring plugins yourself.

Priority Summary: (1) Change Login URL → (2) Limit attempts → (3) Enable 2FA → (4) Strong password → (5) Security Plugin. Doing all 5 reduces risk by over 95%.

Hosting with Built-In WordPress Security

AsiaGB Hosting includes cPGuard Security, SpamAssassin, and Imunify360 for automatic malware protection.

View Hosting Plans