How to Protect Your Site from Brute-Force Attacks

Defend your login pages against brute-force attacks with rate limiting, strong passwords, and cPanel security tools.

· Updated · 2,633 views

A brute-force attack tries thousands of username and password combinations until one works. Login pages, especially WordPress wp-login.php, are common targets. A few layers of defense make these attacks impractical.

Strengthen Your Logins

  • Use long, unique passwords for every admin account.
  • Avoid obvious usernames like admin.
  • Enable two-factor authentication where possible.
  • Remove unused accounts that could be targeted.

Use cPanel Protection Tools

Many cPanel servers run security tools that detect repeated failed logins:

  1. Failed login attempts trigger temporary IP bans automatically.
  2. Check the IP Blocker to add persistent blocks for repeat offenders.
  3. Review Raw Access logs to spot attack patterns.

Protect wp-login.php with .htaccess

You can limit who reaches the WordPress login page. To allow only your own IP, add this to .htaccess:

<Files wp-login.php>
    Require all denied
    Require ip 203.0.113.10
</Files>

Replace the example IP with your own. This blocks every other address from the login form.

Add Rate Limiting

| Measure | Effect | | --- | --- | | Login attempt limits | Locks out after repeated failures | | CAPTCHA on forms | Stops automated bots | | Web application firewall | Filters known attack patterns |

Monitor and Respond

  • Watch for spikes in failed logins.
  • Keep WordPress, plugins, and themes updated.
  • Install a security plugin that logs and limits attempts.

If your IP changes often, the .htaccess allow-list approach may lock you out. In that case rely on a login-limiting plugin and a web application firewall instead.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.