Your wp-login.php is being probed right now — here is what actually helps
2026-09-29 · Yodsira
Check any WordPress site's login logs and you will find the same picture: a steady stream of automated login attempts — "admin", "test", common passwords, sometimes hundreds a day. This is not someone targeting you specifically. Bots scan the entire IPv4 space for wp-login.php and try credential lists against every one they find. Your site has been on that list since the hour it launched.
The good news: the overwhelming majority of these attempts are noise, and they fail. The uncomfortable news: bulk attacks are cover for targeted ones, and a compromised administrator account on a shop is a direct line to your customers' data.
What actually helps, in order
- Strong, unique passwords and no "admin" username. Boring, and still the number one defense. The bulk bot noise dies right here.
- Limit login attempts. Rate limiting turns a credential-stuffing run into a months-long impossibility. One line of defense, huge effect.
- Two-factor for administrators. Even a stolen password stops at the second factor. If your shop has three admins, this is the single highest-value change you can make.
- Know when a new administrator appears. The classic escalation is not guessing your password — it is exploiting a plugin vulnerability to create a fresh admin account. An alert on "new admin created" catches the moment that matters.
What matters less than it feels
- Hiding wp-login.php on a "secret" URL: bots find it again via references in minutes; it mostly breaks your own plugins.
- Blocking whole countries: blunter than it sounds if you sell internationally, and attacks come through proxies anyway.
- Panicking about hundreds of failed attempts: with the first two items above, this is background radiation.
The part nobody watches
Protection is set up once; attention is where sites fail. Who logged in this week? From where? Did the failure rate spike yesterday? A weekly look at three numbers — logins, failures, new admins — catches what configuration cannot, and it takes two minutes when the history is in front of you. Our Login Watch plugin exists for exactly this: it logs every event with geo and ISP from a local database, routes alerts (new admins get their own chat), and sends a weekly report. But a notebook and the weekly habit work too — the point is that somebody actually looks, before the attackers' persistence pays off.