WordPress
WordPress Basic Security & Login Protection
Lock down the WordPress login and admin area against the most common attacks.
The Problem
The /wp-login.php page is one of the most brute-forced URLs on the internet, and a default WordPress install does almost nothing to slow an attacker down.
About this problem
WordPress login at /wp-login.php and the admin area at /wp-admin are at known addresses on every install, so automated bots try common usernames and password lists against them around the clock. The default setup places no limit on attempts, so each request simply consumes server resources and gives an attacker unlimited guesses.
People usually come looking for this after seeing a flood of failed-login notifications, a slowdown that traces back to login requests, or after a security scan flags the site. Others simply want the obvious doors closed before a problem happens.
What's Included
- Login attempt limiting/lockout after repeated failures
- Hiding or renaming the default login URL
- Basic firewall rules for the wp-admin area
- Reviewing and removing any unnecessary admin accounts
What's NOT Included
- Full malware scan/removal (separate service if there's an active infection)
- Two-factor authentication setup (separate service, often bundled)
- Server-level security outside of WordPress itself
How It Works
- I review the current users and roles and identify unused or unnecessary administrator accounts, including any with predictable usernames such as admin.
- I set up login attempt limiting so repeated failures from one address lead to a temporary lockout.
- I move or hide the default login URL using a reputable plugin, then confirm the new address works and that password reset links still function.
- I add basic firewall rules for wp-admin and wp-login.php, for example blocking known bad request patterns, while keeping admin-ajax.php available for the front end.
- I test logins from a normal session and from a deliberately failing one to confirm the lockout triggers and a legitimate user is not locked out.
- I record the new login address and settings in a short note so you can recover access if needed.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- How do I stop brute force attacks on WordPress login?
- Limiting login attempts, hiding the default login URL and adding firewall rules for the admin area together remove most of the automated attempts. That is what this service sets up.
- Will changing the login URL lock me out?
- I test the new address before finishing and give you a note with the details. Password reset links are also checked so that normal recovery still works.
- Does this include two-factor authentication?
- No, two-factor authentication is a separate service, and the two work well together.
- Will this remove malware if my site is already hacked?
- No. This service is for hardening a clean site. If there is an active infection, the malware scan and removal service is the right one.
- Do you change server-level security as well?
- Not here. Work is limited to WordPress itself, so server firewalls and operating system settings are outside this service.
- Which security plugin do you use?
- I choose a well-maintained plugin that fits your site and hosting, and I keep the configuration small to avoid unnecessary overhead.
- What happens to the old admin accounts?
- I review them with you and remove only those that are clearly unnecessary, so content ownership and your own access are not affected.