Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The most reliable way to stop WordPress brute-force attacks is a layered setup: protect administrator accounts with unique passwords and two-factor authentication (2FA), throttle requests before they reach WordPress when possible, handle XML-RPC deliberately, keep software updated, monitor authentication activity, and maintain tested backups. Changing the login URL can reduce background noise, but it cannot replace these controls.

What a brute-force attack is—and why failed guesses still matter

A brute-force attack repeatedly submits guessed usernames and passwords, usually through automated scripts. Attackers may distribute requests across many addresses, so a single-IP block is not always enough. Even unsuccessful guesses can consume web-server, PHP, database, and bandwidth resources.

WordPress has more than one authentication surface. In addition to /wp-login.php, XML-RPC at /xmlrpc.php may accept authentication-related requests. Protect both paths rather than assuming that securing the visible login page solves the problem.

Use the WordPress Developer Resources brute-force guidance as the reference for current WordPress-specific recommendations; its search listing reports an update on February 25, 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Secure privileged accounts first

Use unique, long passwords

Every administrator should have a different, difficult-to-guess password generated and stored by a reputable password manager. Never reuse a password from another service. Remove unused administrator accounts, and change active users to a less-privileged role when they do not need administrative capabilities.

Require 2FA for administrators

WordPress core does not ship with built-in 2FA. Add it through a maintained, compatible plugin or an identity provider, and enforce it for administrators and other privileged users. Depending on the selected solution, passkeys or FIDO2 hardware security keys may be available. Enroll a backup authenticator and store recovery codes securely so a lost phone or key does not lock out the only administrator.

Check compatibility with your WordPress version, hosting stack, login customizations, and any external identity service before enforcing a method across all users. No single plugin is universally compatible.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Rate-limit requests before WordPress processes them

Ask your host whether it provides login throttling, and check your CDN or web application firewall (WAF) for rules that can limit requests to /wp-login.php and /xmlrpc.php. Server- or edge-level controls can reject abusive traffic before PHP and WordPress consume resources.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test the rules with a normal administrator login, password reset, publishing workflow, mobile access, and any automation used by your site. A rule that is too strict can lock out legitimate users or break integrations.

When a plugin is the fallback

If your host and CDN/WAF do not offer suitable controls, a login-protection plugin can throttle attempts inside WordPress. The Limit Login Attempts Reloaded directory listing is one available option, but its listing is vendor-provided and does not establish independent performance or efficacy. Verify current compatibility and features before installing any plugin.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Because plugin controls run after a request reaches PHP, they are generally less resource-efficient during a large request flood than an upstream rule. Do not copy a universal attempt threshold from another site; choose limits based on your users, integrations, and lockout-recovery process.

Make an XML-RPC decision based on actual usage

Disable it when nothing needs it

Inventory your integrations before turning XML-RPC off. WordPress identifies Jetpack and its mobile apps as examples that may rely on it. If no required service uses XML-RPC, disabling /xmlrpc.php removes an authentication surface and simplifies monitoring.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restrict and throttle it when it is required

If Jetpack, a mobile app, or another approved integration needs XML-RPC, keep it available only as necessary and apply access restrictions and rate limits at the CDN, host, or web-server layer. Test publishing, media uploads, notifications, and other dependent features after every rule change. A hidden or changed login URL does not protect XML-RPC.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Keep the WordPress stack hardened

  • Update WordPress core, themes, and plugins promptly from trusted sources.
  • Use HTTPS so credentials are encrypted while being transmitted.
  • Give each person only the role required for their work; avoid shared administrator accounts.
  • Review installed plugins and remove abandoned or unnecessary code.
  • Follow the broader recommendations in WordPress’s hardening handbook. Protecting wp-admin with HTTP Basic Authentication can affect admin-ajax.php, so test administrative features before deploying that control.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Monitor authentication activity and prepare recovery

Review failed-login and other authentication logs for unusual bursts, unfamiliar locations, repeated usernames, and requests against XML-RPC. Use temporary blocks for clearly abusive sources when appropriate, while avoiding rules that could trap legitimate administrators or integrations. Confirm that alerts reach someone who can act; a log that nobody reviews is not an active defense.

Maintain backups that include the database and uploaded files, keep copies separate from the live server, and periodically perform a restore to verify that they are usable. A rehearsed restore procedure matters if an account is compromised, a security change causes an outage, or malicious code is introduced through a different vulnerability.

Should you hide or change the login URL?

Changing the login URL can reduce automated background scans and make logs quieter. It does not strengthen the password, add a second factor, rate-limit XML-RPC, or protect other authentication endpoints. WordPress states: “Obscuring the login URL can reduce noise but should not be your only defense.” Treat this as a minor noise-reduction measure after account security and request throttling are in place, and document the new path for administrators and recovery procedures.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose controls by where they run and what they cover

Control Where it runs Coverage and trade-offs
CDN/WAF or host rate limit Edge, host, or web server Can reject abusive requests before PHP; configure and test both /wp-login.php and /xmlrpc.php.
Login-security plugin WordPress/PHP Useful when upstream controls are unavailable, but still consumes server resources under a flood; compatibility and features vary.
Administrator 2FA Authentication layer Stops a password-only compromise when correctly enforced; requires recovery planning and compatible software.
Changed login URL WordPress routing May reduce scanning noise, but does not replace authentication controls or secure XML-RPC.

A practical rollout checklist

  1. List every administrator, remove unused accounts, and reduce unnecessary privileges.
  2. Replace reused administrator passwords with unique passwords stored in a password manager.
  3. Deploy and test 2FA for administrators and other privileged users; enroll a backup method.
  4. Check your host and CDN/WAF for rules covering /wp-login.php and /xmlrpc.php.
  5. Set site-appropriate limits and test legitimate logins, resets, publishing, mobile access, and integrations.
  6. Inventory XML-RPC dependencies; disable it if unused, or restrict and rate-limit it if required.
  7. Update core, themes, and plugins, remove unnecessary components, and verify HTTPS.
  8. Enable authentication monitoring, define an escalation contact, and review alerts.
  9. Back up the database and files, keep copies separate, and test a complete restore.
  10. Only then consider a changed login URL as an additional noise-reduction measure.

Common mistakes to avoid

  • Relying on a renamed login page: attackers can target other endpoints, including XML-RPC.
  • Using only a plugin during a flood: the request may already have reached PHP before the plugin blocks it.
  • Setting an arbitrary lockout threshold: overly aggressive limits can deny service to legitimate users and support staff.
  • Disabling XML-RPC without checking dependencies: Jetpack or mobile workflows may stop working.
  • Applying permanent, broad geographic blocks: WordPress warns that these can block legitimate users and are difficult to maintain.
  • Skipping restore tests: an untested backup may not be recoverable when you need it.

The Bottom Line

Protect WordPress brute-force surfaces in layers: unique administrator credentials and 2FA, upstream rate limits for both login and XML-RPC, deliberate integration decisions, current software, active monitoring, and verified backups. Treat login-URL changes as optional noise reduction—not as security.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.