Bots constantly try common usernames and passwords on login pages. With strong unique passwords they rarely succeed — but the attempts can still use your account’s resources.
Recognising an attack
In the domain’s access log (Viewing website statistics and logs in DirectAdmin):
198.51.100.23 - - [15/Sep/2026:02:14:01 +0000] "POST /wp-login.php HTTP/1.1" 200 ...
198.51.100.23 - - [15/Sep/2026:02:14:02 +0000] "POST /wp-login.php HTTP/1.1" 200 ...
Many POST requests to a login URL, often from rotating IP addresses, sometimes to xmlrpc.php.
Stopping them
1. Strong, unique passwords — so the attacks fail. Strong passwords and password managers
2. Limit login attempts. A reputable WordPress plugin locks out IPs after repeated failures.
3. Two-factor authentication for administrators.
4. Block XML-RPC if you don’t use it. Most sites don’t (the WordPress mobile app and some integrations do). In .htaccess:
<Files xmlrpc.php>
Require all denied
</Files>
5. Restrict the login page for sites with a small number of admins, using password protection on wp-admin or limiting access to known IPs:
<Files wp-login.php>
Require ip 203.0.113.50
</Files>
Only do this if your IP address is fixed, or you’ll lock yourself out.
Don’t rename “admin” and stop there
Hiding the login URL reduces noise but isn’t protection on its own. Strong passwords and login limits are.