All posts
April 2012·6 min read

Brute force attacks on WordPress: what's happening and how to stop them

Automated brute force attacks on WordPress login pages are becoming more frequent and more sophisticated. Here's what's actually happening and the most effective ways to stop it.

What a brute force attack is

A brute force attack against WordPress is straightforward: automated software submits login attempts to wp-login.php, cycling through username and password combinations until it finds one that works. The software isn't guessing randomly — it uses lists of common usernames (admin, administrator, the site's domain name) combined with lists of common passwords, leaked credentials from other sites, and dictionary words.

Modern attack tools can attempt hundreds or thousands of login combinations per hour. Against a WordPress site with default settings and no login protection, there's nothing to slow them down.

Why WordPress is targeted specifically

WordPress powers an enormous share of the web. Attackers invest in building tools for WordPress because the return — the number of sites they can potentially compromise — is larger than any other platform. The login form is at the same URL on every WordPress install:/wp-login.php. Scanners can identify WordPress sites and target them automatically.

The default "admin" username that WordPress historically created during installation meant that attackers only needed to guess one thing — the password. Even after WordPress began encouraging users to choose their own username, a large installed base of sites retained the default.

The server load problem

Even failed login attempts have a cost. Each request to wp-login.php triggers PHP execution — WordPress loads, checks the credentials, returns a failure response. Under sustained attack, a site on shared or budget hosting can exhaust its PHP worker limit, causing legitimate visitors to receive errors or experience severe slowdowns.

This means brute force attacks are a performance problem as well as a security problem. Even if your password is never guessed, a sustained attack can effectively take your site down.

Effective countermeasures

Limit login attempts

The Limit Login Attempts plugin (and its successor, Login LockDown) adds a lockout after a configurable number of failed attempts. Set to five attempts with a 20-minute lockout, it makes automated brute force attacks effectively impossible — a tool that can only make five attempts every 20 minutes will never get through.

The weakness is that sophisticated attacks use large pools of IP addresses to distribute their attempts, partially bypassing per-IP lockouts. It still stops the vast majority of unsophisticated automated attacks.

Change or eliminate the admin username

If your site still has a user named "admin", create a new administrator account with a different username and delete the admin account. An attacker who has to guess your username as well as your password faces a combinatorially harder problem.

Block wp-login.php at the server level

If you have access to your server's Apache or Nginx configuration, you can add IP-based restrictions to wp-login.php directly. Allowing access only from your own IP address is the most thorough option — no bot from anywhere else in the world can reach the login form. The tradeoff is needing to update the restriction when your IP changes.

Alternatively, HTTP basic authentication (a browser username/password dialog before WordPress loads at all) adds a second layer that most automated tools don't handle, at essentially no performance cost.

Move or rename wp-login.php

Some security plugins offer the option to move the login page to a different URL. This is security through obscurity — it doesn't make the login form more secure, but automated scanners looking for the standard URL won't find it. It's a minor layer of protection rather than a primary defence.

What to look for in your access logs

Check your server's access logs for repeated POST requests to /wp-login.php from the same or similar IP addresses. A legitimate site might see a handful of login attempts per day. A targeted site under attack might see hundreds or thousands per hour. If you see this pattern and your host's control panel shows elevated CPU or PHP worker usage, you're almost certainly under active attack.


DownUnder WP applies Nginx-level rate limiting on wp-login.php across all hosted sites as standard — limiting requests to 10 per minute per IP with a burst allowance. This eliminates automated brute force traffic before it ever reaches WordPress or PHP.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.