The WordPress login page is a favorite target for automated attacks. By default, it’s accessible via /wp-admin or /wp-login.php, making it easy for malicious actors to attempt logins. By hiding the login page, limiting login attempts, setting up two-factor authentication, and enforcing strong passwords, you significantly reduce the chance of a successful attack. In this article, you’ll find concrete steps to make your WordPress login more secure right away.
Why the login page is a risk
A brute force attack is a method where a script automatically tries thousands of username and password combinations until one works. Because the default WordPress login location is the same and predictable everywhere, botnets can attack your site without any prior knowledge. This consumes server resources, can slow down your site, and in the worst case provides direct access to your entire website, including customer data.
Many attacks aren’t specifically targeted at your site but scan the internet en masse looking for weaknesses. That’s exactly why it’s important to have the basics in order, even if you think your site isn’t an interesting target.
Hiding or relocating the login page
One of the most effective measures is changing the default login URL. By replacing /wp-admin or /wp-login.php with your own unique URL, automated scanners simply can’t find a login form to attack anymore. This can be done with a plugin that changes the login slug, without having to work in the WordPress core.
Make sure you remember the new URL well or save it in your password manager. If you lose the custom link, you’ll need to recover it via the database or by temporarily disabling the plugin through FTP.
Limiting login attempts
In addition to hiding the login page, it’s wise to limit the number of login attempts. With a plugin that tracks failed attempts, an IP address gets temporarily blocked after a set number of incorrect attempts. This makes brute force attacks practically unworkable, as it takes too long to try enough combinations.
Install a limiting plugin
Choose a plugin that logs login attempts per IP address and blocks after a set number of failed attempts.
Change the login URL
Change the default login slug to a unique, non-obvious value.
Activate two-factor authentication
Link an authenticator app to your user account for an extra login step.
Check user roles
Remove or downgrade accounts that no longer need administrator rights.
Adding extra security layers
Two-factor authentication (2FA) is one of the most powerful measures against unauthorized access. Even if a password gets leaked, an attacker still needs the code from your authenticator app. Combine this with strong, unique passwords and remove the default ‘admin’ user account, as it’s often the first one guessed.
Also make sure WordPress, themes, and plugins are always up to date, as outdated software is a common entry point for attackers. Are you using SSL on your website? That’s standard nowadays and prevents login credentials from being sent unencrypted. Through Plesk in your hosting environment, you can also easily set IP restrictions at the directory level, adding an extra server-wide security layer on top of the WordPress settings themselves.
A well-performing and secure hosting environment with NVMe storage and daily backups forms the foundation under all these measures. Unsure about your current hosting provider? Check out the options to switch to Tandata, or read more about our web hosting with LiteSpeed servers and free SSL. Questions about a specific setting? Check our knowledge base for more background information.
Frequently Asked Questions
Is changing the login URL really necessary if I already use 2FA?
2FA protects against unauthorized access, but a hidden login URL already prevents automated scanners from putting a strain on your site. Together they form a stronger combination than either measure alone.
Can I lock myself out if I change the login page?
Yes, if you forget the new URL. Store it somewhere safe and test the change immediately after saving, before logging out.
Does limiting login attempts also work against attacks from different IP addresses?
Large-scale attacks sometimes use rotating IPs. Therefore, combine limiting with 2FA and strong passwords for the best protection.
Does server security also affect my WordPress login?
Absolutely, a well-secured server platform with up-to-date software and firewall settings forms an extra protective layer alongside your WordPress measures.
Conclusion
A secure WordPress login page consists of multiple layers: a unique login URL, a limit on login attempts, two-factor authentication, and up-to-date software. Combine these measures with a reliable hosting environment for optimal protection of your website.