What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
You can reduce WordPress bot abuse without CAPTCHA or a web application firewall (WAF) by matching each control to the traffic: protect logins, moderate comments, add limits to abused forms or routes, and leave required integrations working. Start by identifying which URLs and actions are receiving unwanted requests; a blanket block can disrupt legitimate visitors and plugins.
Identify what the bots are targeting
Before changing settings, review available server logs, hosting analytics, or bot reports. Look for the paths receiving repeated requests and what those requests are trying to do. A login flood, comment spam, repeated form submissions, and excessive crawling are different problems and need different controls. Cloudflare recommends reviewing bot traffic before changing settings in its bot-traffic guidance.
- Login attempts: repeated requests to
/wp-login.phpor other authentication routes. - XML-RPC: requests to
/xmlrpc.php, which may be needed by Jetpack or another integration. - Comments: unwanted submissions on posts or pages with comments enabled.
- Forms: repeated posts to a form endpoint, including direct requests that bypass a form’s visible interface.
- API or crawler traffic: requests to REST API routes or pages being fetched at a high rate.
Note which legitimate users, integrations, and verified search crawlers also use the affected paths. That baseline helps you test changes without blocking expected traffic.
Recommended Free Tools
Protect WordPress logins with layered controls
Use strong, unique administrator passwords, store them in a password manager, and enable two-factor authentication (2FA) for administrator accounts. Keep WordPress core, themes, and plugins updated, and monitor failed-login patterns so you can tell whether the changes are helping.
#1 Best Overall
If the host or an edge service supports rate limiting, apply it to /wp-login.php rather than imposing an arbitrary limit across the whole site. Rate limiting restricts repeated requests after a defined threshold; set the threshold and response to fit normal administrative use. Test with the people and integrations that legitimately sign in.
A security plugin can throttle logins when no host- or edge-level control is available, but it runs within PHP. The request still reaches the server and WordPress processing begins, so application-level throttling may not protect origin resources as early as server- or edge-level limits. WordPress’s brute-force protection guidance discusses these trade-offs.
Do not rely on hiding or changing the login URL as your only defense, and avoid broad country blocks: they can exclude legitimate visitors and require ongoing maintenance.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Decide whether XML-RPC should remain available
XML-RPC is a compatibility decision, not a route to block automatically. If your site does not use it, disabling access can remove an exposed endpoint. If Jetpack, a mobile app, or another required service depends on it, preserve the necessary requests and control abusive traffic instead.
Cloudflare distinguishes its Jetpack-specific managed rule, WP0007, which protects Jetpack traffic to xmlrpc.php?for=jetpack, from WP0002, which completely disables access to xmlrpc.php when enabled. Check your integrations before choosing a rule; see Cloudflare’s WordPress managed rules reference.
Reduce native comment spam with WordPress settings
Turn off comments where discussion is not needed
Disable comments on posts or pages that do not need discussion. WordPress’s comment-spam documentation advises: “If a page or post does not need comments, you may decide to turn comments off completely.” This prevents submissions on those pages without adding a CAPTCHA.
Rank #4
Moderate comments before publication
Require moderation before comments appear publicly. This does not stop bots from submitting comments, but it keeps unapproved submissions from being published automatically. If you add a comment-management plugin, check that it is maintained, compatible with your WordPress version, documented, and supported. WordPress recommends evaluating those factors when selecting plugins.
Limit abuse of forms and high-volume endpoints
For repeated form submissions, use a control tied to the form or endpoint rather than disabling unrelated site features. If available, rate-limit repeated requests to the form route. An endpoint limit can also address direct POST requests that bypass a client-side form widget; a control displayed in the browser alone does not necessarily limit requests sent directly to the server.
Best Value
Cloudflare describes rate limiting as defining thresholds for requests that match an expression and an action to take when those limits are reached. Its bot guidance explains how endpoint-specific rules can be used to target abusive traffic. Choose a threshold that accommodates legitimate bursts and verify that normal submissions still succeed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Keep the REST API and legitimate crawlers working
Do not block the WordPress REST API wholesale just because bots make API requests. WordPress and plugins use the API for site and application functionality. If evidence points to abuse of a particular route, restrict that route, method, or request rate narrowly, then test the plugins and integrations that depend on it. WordPress explains the API’s role in its REST API documentation.
Likewise, distinguish unwanted crawling from verified search crawlers and other useful automated traffic. Prefer a targeted rule for the abusive path or rate over a broad bot setting that may affect legitimate services. Recheck traffic after changing a rule; Cloudflare’s bot guidance covers the distinction between broad bot controls and more targeted handling.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsChoose the right place to apply a control
WordPress settings, plugins, server rules, and hosted edge services act at different points in the request path. Consider these factors before applying a change:
- Coverage: Does the control address the actual surface—login, XML-RPC, comments, a form, an API route, or crawling?
- Filtering point: Is traffic rejected before reaching the origin, at the web server, or only after WordPress and PHP begin processing it?
- Compatibility: Could the rule affect Jetpack, mobile apps, single sign-on, webhooks, plugins, administrators, or verified crawlers?
- Visitor impact: Could a legitimate person be blocked from signing in or submitting a form?
- Operations and recovery: Can you review the rule’s effect, maintain it, and quickly undo it if expected traffic fails?
WordPress cautions that server-level examples vary by environment and should be tested in staging. Start with a narrow change, verify the site’s important workflows, and keep a recovery path if the rule blocks legitimate requests.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

