Security

How to Secure Your WordPress Login: 2FA, Strong Passwords and More

Practical ways to protect the WordPress login from brute-force attacks and account takeover: strong unique passwords, two-factor authentication, login limits, user roles, XML-RPC and firewalls.

How to Secure Your WordPress Login: 2FA, Strong Passwords and More
On this page
  1. 1. Strong, unique passwords
  2. 2. Two-factor authentication (2FA)
  3. 3. Limit login attempts
  4. 4. Avoid predictable usernames
  5. 5. Use the right roles
  6. 6. Disable XML-RPC if you don't need it
  7. 7. Add a firewall
  8. 8. Bot protection on the login form
  9. 9. Changing the login URL
  10. 10. Watch for suspicious activity
Key takeaways
  • Use unique, manager-generated passwords and mandatory 2FA for admins.
  • Limit login attempts, avoid "admin" usernames and use least-privilege roles.
  • Disable unused XML-RPC, add a firewall and bot protection, and monitor activity.

Bots constantly try to guess passwords on WordPress sites, and stolen or reused passwords are a common way sites get hacked. Securing the login is one of the simplest, most effective security steps you can take.

1. Strong, unique passwords

  • Use long, random passwords generated by a password manager
  • Never reuse a password from another service
  • Don't share logins; give everyone their own account

2. Two-factor authentication (2FA)

2FA asks for a second code, usually from an authenticator app, after the password. Even if a password is stolen, the attacker can't log in without the code. Add it with a security or 2FA plugin, and make it mandatory for administrators at least.

3. Limit login attempts

Block or slow down IP addresses after repeated failed logins. Many security plugins and hosts include this.

4. Avoid predictable usernames

Don't use "admin" or your domain name as the administrator username. Create a new admin user with a unique name and remove the old one (reassigning its content).

5. Use the right roles

Give people only the access they need: Editors for content, Shop Managers for orders, and very few Administrators. Remove accounts for staff or developers who no longer need access. See user roles explained.

6. Disable XML-RPC if you don't need it

XML-RPC is an older remote access feature that attackers use for password-guessing. If you don't use apps or services that need it, disable it with a security plugin or server rule.

7. Add a firewall

A web application firewall (from your host, Cloudflare or a security plugin) blocks known malicious traffic before it reaches your login page.

8. Bot protection on the login form

An invisible challenge like Cloudflare Turnstile or reCAPTCHA stops automated login attempts without annoying real users much.

9. Changing the login URL

Moving wp-login.php to a custom address reduces bot noise, but it's not real security on its own. Use it alongside the steps above, not instead of them.

10. Watch for suspicious activity

  • Activity logs showing logins and changes
  • Alerts for new administrator accounts
  • Log out all sessions if you suspect a compromise, then change passwords

Login security is one part of the full WordPress security checklist.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now