A brute-force attack tries thousands of username and password combinations until one works. Login pages, especially WordPress wp-login.php, are common targets. A few layers of defense make these attacks impractical.
Strengthen Your Logins
- Use long, unique passwords for every admin account.
- Avoid obvious usernames like
admin. - Enable two-factor authentication where possible.
- Remove unused accounts that could be targeted.
Use cPanel Protection Tools
Many cPanel servers run security tools that detect repeated failed logins:
- Failed login attempts trigger temporary IP bans automatically.
- Check the IP Blocker to add persistent blocks for repeat offenders.
- Review Raw Access logs to spot attack patterns.
Protect wp-login.php with .htaccess
You can limit who reaches the WordPress login page. To allow only your own IP, add this to .htaccess:
<Files wp-login.php>
Require all denied
Require ip 203.0.113.10
</Files>
Replace the example IP with your own. This blocks every other address from the login form.
Add Rate Limiting
| Measure | Effect | | --- | --- | | Login attempt limits | Locks out after repeated failures | | CAPTCHA on forms | Stops automated bots | | Web application firewall | Filters known attack patterns |
Monitor and Respond
- Watch for spikes in failed logins.
- Keep WordPress, plugins, and themes updated.
- Install a security plugin that logs and limits attempts.
If your IP changes often, the .htaccess allow-list approach may lock you out. In that case rely on a login-limiting plugin and a web application firewall instead.