Apertura de la tienda: código promocional LAUNCH20 — 20 % de descuento en todo hasta finales de septiembre
El catálogo/Blog/Your wp-login.php is being probed right now — here is what a

Your wp-login.php is being probed right now — here is what actually helps

2026-09-29 · Yodsira

Check any WordPress site's login logs and you will find the same picture: a steady stream of automated login attempts — "admin", "test", common passwords, sometimes hundreds a day. This is not someone targeting you specifically. Bots scan the entire IPv4 space for wp-login.php and try credential lists against every one they find. Your site has been on that list since the hour it launched.

The good news: the overwhelming majority of these attempts are noise, and they fail. The uncomfortable news: bulk attacks are cover for targeted ones, and a compromised administrator account on a shop is a direct line to your customers' data.

What actually helps, in order

  1. Strong, unique passwords and no "admin" username. Boring, and still the number one defense. The bulk bot noise dies right here.
  2. Limit login attempts. Rate limiting turns a credential-stuffing run into a months-long impossibility. One line of defense, huge effect.
  3. Two-factor for administrators. Even a stolen password stops at the second factor. If your shop has three admins, this is the single highest-value change you can make.
  4. Know when a new administrator appears. The classic escalation is not guessing your password — it is exploiting a plugin vulnerability to create a fresh admin account. An alert on "new admin created" catches the moment that matters.

What matters less than it feels

  • Hiding wp-login.php on a "secret" URL: bots find it again via references in minutes; it mostly breaks your own plugins.
  • Blocking whole countries: blunter than it sounds if you sell internationally, and attacks come through proxies anyway.
  • Panicking about hundreds of failed attempts: with the first two items above, this is background radiation.

The part nobody watches

Protection is set up once; attention is where sites fail. Who logged in this week? From where? Did the failure rate spike yesterday? A weekly look at three numbers — logins, failures, new admins — catches what configuration cannot, and it takes two minutes when the history is in front of you. Our Login Watch plugin exists for exactly this: it logs every event with geo and ISP from a local database, routes alerts (new admins get their own chat), and sends a weekly report. But a notebook and the weekly habit work too — the point is that somebody actually looks, before the attackers' persistence pays off.

← Todos los artículos