Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect a WordPress site with layers: unique administrator passwords, administrator 2FA, rate limits enforced before requests reach PHP when possible, a deliberate XML-RPC policy, current software, monitoring, least-privilege accounts, and tested backups. Changing the login URL alone cannot secure every authentication surface.

What a brute-force attack looks like

A brute-force attack repeatedly submits guessed usernames and passwords, usually through automated scripts. Attackers may spread requests across many addresses, so failed guesses can still consume server, PHP, database, and logging resources. The relevant surfaces include /wp-login.php, XML-RPC requests to /xmlrpc.php, and any alternative authentication endpoint exposed by a plugin or integration.

The official WordPress brute-force guidance (reported as updated February 25, 2026) recommends treating obscured login URLs as a noise-reduction measure rather than a primary defense.

Build protection in the right order

  1. Secure privileged accounts. Use long, unique passwords, 2FA, and only the permissions each person needs.
  2. Throttle abusive requests upstream. Prefer CDN, WAF, hosting, or web-server controls that can reject traffic before WordPress runs.
  3. Make an XML-RPC decision. Disable it when unused; otherwise protect it without breaking required services.
  4. Keep the site recoverable. Update software, watch authentication activity, and maintain tested backups.

Secure administrator and privileged accounts

Use unique passwords and a password manager

Every administrator should have a difficult-to-guess password that is not reused on another site. A password manager makes unique credentials practical and reduces the temptation to share or recycle them. Remove dormant administrator accounts, and demote active users who do not need administrator privileges.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Require two-factor authentication

WordPress core does not ship with 2FA. Add it through a maintained, compatible security plugin or an identity provider, and enforce it for administrators and other privileged roles. Depending on the chosen provider, passkeys or FIDO2 hardware security keys may be available; confirm compatibility before buying or enrolling a device. Register a backup authenticator and store recovery codes securely so a lost phone or key does not lock out every administrator.

Use least privilege

Give authors, editors, contractors, and integrations the lowest role that completes their work. Review accounts periodically, especially after staff or agency changes. Fewer privileged credentials mean fewer accounts an attacker can use for a high-impact takeover.

Rate-limit login traffic before WordPress processes it

Ask your host and CDN/WAF whether they provide rules for login throttling or managed WordPress protection. Scope rules to /wp-login.php and, where relevant, /xmlrpc.php; then test administrator sign-in, password resets, publishing workflows, mobile apps, and other legitimate integrations.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

An edge or web-server rule can reject abusive requests before PHP and WordPress load, which is generally more resource-efficient during a flood. If upstream controls are unavailable, a login-protection plugin can still slow repeated guesses, but it runs inside WordPress/PHP and therefore cannot protect server resources as efficiently under a heavy request flood. Do not copy a universal attempt threshold: choose limits that fit your users, publishers, integrations, and recovery process, and monitor false positives.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Control location Strength Watch for
CDN or WAF Can reject traffic at the edge before it reaches the origin Rules may block legitimate offices, mobile networks, or password-reset traffic
Host or web server Protects the origin before WordPress/PHP handles the request Availability and syntax depend on the hosting stack
WordPress plugin Works when upstream throttling is unavailable and can add application-level logs Still consumes PHP resources; verify compatibility and maintenance

Limit Login Attempts Reloaded is one available WordPress.org directory option. Its listing describes its own features; it is not independent evidence of performance, so verify its current compatibility, settings, and support before deployment.

Handle XML-RPC deliberately

Disable it when nothing needs it

Inventory connected services first. WordPress identifies Jetpack and mobile apps as examples that may rely on XML-RPC. If no required service uses it, disable XML-RPC and confirm that publishing, app access, and monitoring still work.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Restrict it when an integration is required

If XML-RPC must remain enabled, apply access controls and rate limits to /xmlrpc.php at the CDN, WAF, host, or web server where possible. Test the exact services that need it, and log rejected requests. Changing the visible login URL does not remove XML-RPC from the threat model.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep the rest of the site hardened

Update every code layer

Apply current WordPress core, theme, and plugin updates from trusted sources. Remove abandoned plugins and themes rather than leaving unused code enabled. The official WordPress hardening guidance covers broader account and configuration practices.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use HTTPS

HTTPS encrypts credentials and session data while they travel between a browser and the site. It does not stop guessing, so keep the authentication controls above in place.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Be careful with extra admin gates

HTTP Basic Authentication in front of /wp-admin can add a barrier, but WordPress notes that it may interfere with admin-ajax.php. Test editor screens, asynchronous saves, media workflows, and any plugin that uses admin AJAX before adopting it.

Do not rely on permanent country blocks

Broad geographic deny-lists can block legitimate travelers, staff, customers, and distributed services and are difficult to maintain. Use them only when you have a documented, monitored business case and a way to recover access.

Monitor attempts and preserve a way back

Review authentication anomalies

Look for bursts of failed logins, attempts against nonexistent usernames, unusual administrator locations, repeated XML-RPC calls, and sudden new users or privilege changes. Coordinate logs from the WordPress security layer, web server, CDN/WAF, and hosting provider so a block at one layer is visible at the others. Temporarily block clearly abusive sources when appropriate, while avoiding rules that strand legitimate administrators.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Maintain tested backups

Keep backups of the database and files, retain copies separate from the live server, and rehearse a restore on a safe environment. A backup is protection only if it is complete, recent enough for your recovery target, and known to restore successfully. Keep emergency administrator recovery procedures and authenticator backups documented.

A practical rollout checklist

  1. List all administrators, privileged users, service accounts, mobile apps, and publishing integrations.
  2. Remove unused accounts, assign least-privilege roles, and replace reused passwords with unique manager-generated credentials.
  3. Enroll 2FA for every administrator and privileged user; add a tested backup authenticator.
  4. Check the host and CDN/WAF for rules covering /wp-login.php and /xmlrpc.php.
  5. Apply conservative rate limits, then test normal sign-in, resets, publishing, APIs, Jetpack, mobile apps, and monitoring.
  6. Disable XML-RPC if no dependency remains; otherwise restrict and rate-limit it.
  7. Update core, themes, and plugins; remove unused code and confirm HTTPS.
  8. Enable useful authentication logging, define an escalation contact, and review anomalies on a schedule.
  9. Make a backup and perform a restore rehearsal before declaring the setup complete.

When legitimate users are being blocked

  • Administrators cannot sign in: use the documented recovery authenticator or backup code, inspect the WAF/host block log, and add a narrow temporary exception rather than disabling all protection.
  • Password resets fail: check that the rate rule does not cover reset endpoints or outbound mail dependencies, then test delivery and logs.
  • Jetpack or a mobile app stops working: confirm whether it uses XML-RPC and allow only the required path or service while retaining throttling.
  • The site slows during an attack: move throttling upstream if possible; an in-WordPress limiter cannot prevent PHP from receiving every request.

The Bottom Line

The durable defense is layered: protect privileged credentials with 2FA, throttle both login surfaces as early as your infrastructure allows, keep XML-RPC intentional, maintain current software, monitor changes, and verify that backups restore.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.