Hackers tried user name with wrong case [closed]

WordPress do not consider user names to be private information. It is trivial to get a user name of any one which has authored a post, and it is not very complex to get a list of active user names based on the errors displayed at the login form when using a wrong password.

Regardless of my personal dislike to this policy, in the end most user names can be easily guessed and more targeted attacks can use email adrress, which for many is a public information, to attempt login.

Best advice is probably to put less emphasize on “security” plugins which report many things you either can do nothing about, or are just part of the “the internet is full of evil people” fact, and focus on keeping good user passwords and limit user capabilities as much as possible.

error code: 523