There’s an app plugin for that, Limit Login Attempts.
Some more info available in this wp beginner post: http://www.wpbeginner.com/plugins/how-and-why-you-should-limit-login-attempts-in-your-wordpress/
Related Posts:
- WordPress login urls
- Is there any way to rename or hide wp-login.php?
- Increase of failed login attempts, brute force attacks? [closed]
- How to fake a WordPress login?
- Receiving “This content cannot be displayed in a frame” error on login page
- Websites defaced by uploading script using theme editor
- Make wordpress admin failed login attempt return 401
- Can’t stop hacker trying to get admin access in WordPress blog after trying many ways [closed]
- Store brute-force IP addresses
- How to create a private login page for admin.?
- WordPress Security – How to block alternative WordPress access
- Protecting WordPress login page
- wp-admin folder, brute force, and password protection
- Sniffing wordpress user’s credentials
- disable site_url redirect in wp-login.php
- Does WordPress (or a plugin) reveal login credentials to admin?
- Is wp_login_form secure on a non secure page?
- WordPress login security
- Why isn’t the login page rate limited by default?
- How can I password protect a WordPress site without requiring users to log in?
- Input sanitation
- How to Prevent Brute Force Attack on WordPress
- Advice on redirect to lock site from unauthorized users
- Where is the php file, that does the checks for login information?
- Error on WordPress Login
- Access log “POST /wp-login.php HTTP/1.0” 400
- force login loophole
- I need to find which is the file that checks the DB for correct login (username, password)
- How to create separate login for authors/moderators/subscribers?
- How to invalidate `password reset key` after being used
- Site is not loading after relogin attempts on SSL
- Some crawlers/bots attempting to login with very good guesses. How?
- Hide wp-login.php but not the widget
- How login is possible, if I deny login page via nginx?
- Custom login form
- Make my wordpress blog remember my login “forever”
- How to check in timber if user is loggedin?
- Stop WordPress from logging me out (need to keep me logged in)
- Does wp_logout_url() destroy a session? (Logging out question)
- custom login page redirect to logged in user profile page
- What is the purpose of logging out after WordPress upgrade?
- How to translate “wrong password” message
- Login cookie across multiple domains on network w/ mapping
- Can’t login after URL change
- Adding HTML to login page under the body tag
- force user to re-login after 4 hours – how?
- How does WordPress handle sessions?
- Preexisting login to change to logout link in sub menu
- Customizing login error messages
- screwed-up my blog..what should I do
- Changes only show when logged in?
- How can I find the login page? It was lost after moving the site
- How to integrate external user tables with WP?
- WordPress as webapp login session
- How to modify the action attribute of the wp-login.php?action=register form?
- How can I add a login/logout link in the sub-nav of my website?
- Correct passwords keep appearing as incorrect
- Odd login issue that needs manual page refresh on some devices
- WordPress asking for login on public pages on localhost
- Good way to block users within a multisite setup without deleting them?
- 404 redirect wp-login and wp-admin after changing login url [closed]
- Show directory listing/browsing if user is logged in
- Disabling standard registration login with username/email and password?
- Login form doesn’t log in
- Possible to display a button only if user are login?
- Disable all other page except index,register,login till user login
- Auto login after reset password
- Is there anyway to get the inputted password string from the login form?
- Invalidate username if it contains @ symbol
- WordPress Login and Register Link
- Login and Forgot password in Lightbox
- WordPress Login redirection according to user role
- Getting a person’s username from a wordpress cookie
- Prevent display password on wp-login.php
- WordPress ‘limit_login_lockouts’ using internal ip adress
- wp_get_current_user does not work properly on log in page
- “if is logged in” doesn’t work for me [closed]
- Timezone Change Locked Me Out? [closed]
- How are all users now set to inactive?
- Membership Plugin with Facebook integration [closed]
- Unable to login into WordPress 401
- Google reCaptcha on WP login page
- Recovering log in information
- Extend Cookie with auth_cookie_expiration not working
- WordPress login page not display
- WordPress Login & Register works in localhost but don’t work on server
- Opening WordPress on wordpress.example.com, while the webpage is at example.com
- prevent login after incorrect password 5 times
- Why does /wp-admin login send me to this landing page?
- Locked out of WordPress admin area [closed]
- WordPress login page blank after customizations – works on other sites
- WordPress does not send email confirmation to newly registered users
- How do I resolve my inability to login to WordPress dashboard? [duplicate]
- Chrome incorrectly displaying WP login as ‘not fully secure’
- Changed from HTTP to HTTP, can login no longer login
- Without user loging inner page is disable wordpress [duplicate]
- Registration and Login form
- Share login status across subdomains without network
- How to change the login URL
- Login and register by API