πŸ›‘οΈ
Beveiliging

Stopping Brute Force Attacks on WordPress

πŸ“… 8 October 2026 ✏️ 8 October 2026 ⏱ 4 min leestijd

Learn how to recognize and stop brute force attacks on your WordPress login with concrete, actionable measures for better security.

Brute force attacks are attempts by bots to gain access to your site through the WordPress login screen using thousands of combinations of usernames and passwords. You stop them by making the login screen harder to reach, combining strong passwords with two-factor authentication, limiting the number of login attempts, and blocking suspicious IP addresses. In this article, you’ll learn step by step how to set this up.

What is a brute force attack

In a brute force attack, automated scripts continuously try to log into your WordPress admin environment, usually via /wp-login.php or /wp-admin. The bots test known usernames such as ‘admin’ combined with commonly used passwords. If an attempt succeeds, the attacker gains full control over your site. You can recognize these attacks by a notably high number of failed login attempts in your server logs or security plugin.

Risks to your website

Besides the risk that someone actually logs in, brute force attacks also put a strain on your server. Thousands of login attempts per hour can negatively affect your site’s loading time and even lead to temporary overload. If an attack succeeds, your site can be used to spread malware, send spam, or redirect visitors to malicious pages. This harms not only your site but also your reputation and search engine visibility.

Bot attackerWordPress LoginLimit login+ 2FA blocks

Step-by-step plan to stop attacks

1

Limit the number of login attempts

Install a plugin that limits the number of failed login attempts per IP address and then temporarily blocks that address. This makes it impossible for bots to try thousands of combinations in quick succession.

2

Enable two-factor authentication

Add an extra verification step on top of your password, for example via an authenticator app. Even if an attacker guesses the correct password, they won’t get further without the second code.

3

Hide or relocate the login screen

Change the default login URL to a unique name. Many bots automatically target the default paths, so a different URL immediately filters out a large portion of attacks.

4

Use strong, unique passwords

Replace default usernames such as ‘admin’ and use long, unique passwords for each user. A password manager makes this easy to manage without sacrificing convenience.

5

Check logs and block suspicious IPs

Regularly review your access logs for repeated failed attempts from the same IP ranges and block these structurally through your server settings or a firewall plugin.

Additional security measures

In addition to direct measures against brute force attacks, it helps to always keep WordPress, themes, and plugins up to date, since outdated software is often the actual entry point after a successful attack. Also ensure daily backups, so you can quickly restore to a clean version of your site if in doubt. A well-secured hosting platform with a modern server configuration and server-level firewall forms a solid foundation on top of your WordPress settings; you can easily set this up via Plesk, where you can also directly manage your SSL certificates and backups. For a suitable foundation, check out our overview of web hosting, and read more background articles about website security in our knowledge base.

πŸ’‘ Tip: Always combine a login attempt limit with two-factor authentication. A limit alone stops bots that try many attempts quickly, but it doesn’t protect against a single guessed combination.

Frequently Asked Questions

How do I know if my site is being attacked?

You’ll see an unusually high number of failed login attempts in your server logs or security plugin, often from varying or foreign IP addresses, concentrated around the login screen.

Is changing the login URL really effective?

Yes, it wards off a large portion of automated attacks that blindly try default paths, although it remains a supplement to, not a replacement for, strong passwords and 2FA.

Can a brute force attack affect my email too?

Yes, email accounts can also be targeted. Make sure your business email hosting uses strong passwords and spam filtering to limit this risk.

Should I contact my hosting provider in case of persistent attacks?

In the event of structural or large-scale attacks, you can contact your hosting provider so that additional blocks or firewall rules can be set up at the server level.

Does switching to a different hosting provider help against brute force attacks?

A hosting environment with up-to-date server software and built-in security layers significantly reduces the risk. Check out the options for switching to Tandata if you doubt your current security.

Conclusion

You stop brute force attacks by making the login screen less discoverable and less accessible: limit login attempts, use two-factor authentication and strong passwords, and keep your site and server up to date. Combine these measures with regular log checks for a sustainably secure WordPress site.

View web hosting β†’

Was dit artikel nuttig?