How to Secure Your WordPress Login: 2FA, Strong Passwords and More
Practical ways to protect the WordPress login from brute-force attacks and account takeover: strong unique passwords, two-factor authentication, login limits, user roles, XML-RPC and firewalls.

On this page
- Use unique, manager-generated passwords and mandatory 2FA for admins.
- Limit login attempts, avoid "admin" usernames and use least-privilege roles.
- Disable unused XML-RPC, add a firewall and bot protection, and monitor activity.
Bots constantly try to guess passwords on WordPress sites, and stolen or reused passwords are a common way sites get hacked. Securing the login is one of the simplest, most effective security steps you can take.
1. Strong, unique passwords
- Use long, random passwords generated by a password manager
- Never reuse a password from another service
- Don't share logins; give everyone their own account
2. Two-factor authentication (2FA)
2FA asks for a second code, usually from an authenticator app, after the password. Even if a password is stolen, the attacker can't log in without the code. Add it with a security or 2FA plugin, and make it mandatory for administrators at least.
3. Limit login attempts
Block or slow down IP addresses after repeated failed logins. Many security plugins and hosts include this.
4. Avoid predictable usernames
Don't use "admin" or your domain name as the administrator username. Create a new admin user with a unique name and remove the old one (reassigning its content).
5. Use the right roles
Give people only the access they need: Editors for content, Shop Managers for orders, and very few Administrators. Remove accounts for staff or developers who no longer need access. See user roles explained.
6. Disable XML-RPC if you don't need it
XML-RPC is an older remote access feature that attackers use for password-guessing. If you don't use apps or services that need it, disable it with a security plugin or server rule.
7. Add a firewall
A web application firewall (from your host, Cloudflare or a security plugin) blocks known malicious traffic before it reaches your login page.
8. Bot protection on the login form
An invisible challenge like Cloudflare Turnstile or reCAPTCHA stops automated login attempts without annoying real users much.
9. Changing the login URL
Moving wp-login.php to a custom address reduces bot noise, but it's not real security on its own. Use it alongside the steps above, not instead of them.
10. Watch for suspicious activity
- Activity logs showing logins and changes
- Alerts for new administrator accounts
- Log out all sessions if you suspect a compromise, then change passwords
Login security is one part of the full WordPress security checklist.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


