I use http://wordpress.org/extend/plugins/limit-login-attempts/ which blocks IPs when login attempts exceed set limit you set.
Limit Login Attempts blocks an Internet address from making further
attempts after a specified limit on retries is reached, making a
brute-force attack difficult or impossible.
If you’re on a host where you can install and run root code, look at http://sourceforge.net/projects/fail2ban/
“Fail2Ban monitors log files like /var/log/pwdfail or
/var/log/apache/error_log and bans failure-prone addresses. It updates
firewall rules to reject the IP address or executes user defined
commands.”
Related Posts:
- Security issues with WP sites
- How To Clean The Malware Infected & Hacked WordPress Websites? [duplicate]
- Hack-Proof OR Security in WordPress — is it real?
- Website show Google Ads when we have no Google Ads linked to our website
- WordPress disable direct access of files in WordPress installation path
- My WP site and password was hacked, what to do? [closed]
- What Are Security Best Practices for WordPress Plugins and Themes? [closed]
- Are WordPress Plugins essential?
- I found this in a plugin. What does it do? is it dangerous?
- What are the common security flaws I need to look for? [closed]
- Disabled plugins are they security holes – rumor or reality?
- What could a hacker do with my wp-config.php
- How Can I Securely Implement a Password-less Login Feature?
- Security and .htaccess
- Are there procedures to prevent malicious plugin updates?
- Secure WordPress paid plugin
- How to make media upload private? [duplicate]
- Does WordPress contain “default” anti-SQL injection code that responds with a 404 error?
- What does a security risk in a plugin look like?
- WordPress Capabilities: edit_user vs edit_users
- Should we use plugins that aren’t available from the official WordPress site?
- How to check plugins for malicious code?
- How to properly secure my WordPress installation?
- Why allow overriding crucial pluggable functions wp_verify_nonce and wp_create_nonce?
- Where should my plugin POST to?
- Security error WP 4.0 + WP phpBB Bridge [closed]
- Should I install plugins to my WordPress installation from web sites having in URL “nulled” or, “null”?
- Disabled plugins are security holes – rumor or reality?
- Why am I sometimes getting a 404 error when I try to update a page with Elementor?
- Prevent Brute Force Attack
- Why users disable the WordPress update?
- Will WordPress username displayed somewhere in the site?
- Is revealing just the AUTH_KEY a security issue?
- Questions about brute force attacks on the admin username, coming from amazon IP addresses
- Why Better WP security plugin returns 418 I’m a Teapot “error”?
- How to expire all wordpress user passwords instantly?
- Weird problems after recovery from security breach
- Security checking in meta_box save is reluctant?
- Escape when echoed
- Should you escape hardcoded URLs?
- Preventing BFA in WordPress without using a plugin
- How can I make uploaded images in the editor load with HTTPS?
- How to stop xmlrpc attacks without disabling component to allow JetPack to work in WordPress?
- WordPress filter that hook after each action/filter hook
- How to delete Passwrd Protected posts cookies when a user logged out from the site
- Upgraded to latest version – 3.0.3 and Now I get a “sufficient permissions to access this page” error
- Headers Content-Security-Policy CSP Major Issue
- How to block plugin activations with no known user or coming from unknown IP address range?
- Check for security updates
- Standard Fail2Ban vs. WP Fail2ban vs. WP Fail2Ban Redux
- Why can’t I access my Intranet LDAPS with NADI?
- Malicious File Upload [closed]
- Stop Plugin Enumeration [closed]
- Malware installation during plugin update?
- Some one is trying to hack my website, Need guidance [closed]
- I should enable automatic updates?
- Can some vulnerabilities in plugins be exploited even when the plugin is inactive?
- Is wp-app.php or wp-apps.php needed for WordPress?
- Security and Must Use Plugins
- Is Timthumb still broken? What security measures should be taken?
- Is it safe to use admin-ajax.php in the frontend?
- How to protect WordPress from security scanner [closed]
- Specific way to allow WordPress users to view their current password? And edit it?
- Too many login attempts
- How to prevent plugins from sniffing/stealing other plugins’ options?
- Vulnerability Concern From the Plugin or From Not Updating the Plugin?
- How to deal with Slow HTTP POST (slowloris) vulnerability
- Running multiple security plugins
- Chrome Dev Tools console says every page in my blog has link to http://maps.google.com [closed]
- Regarding plugin security
- How do I determine if the user who registered is not spam?
- If I use an alternative login (e.g. CAS or other SSO) plugin, is my site protected from the recent brute force login attempts?
- WP Insert Post If user refreshes override new post
- 404 errors when updating options in admin dashboard
- Website Captcha Error: The reCAPTCHA wasn’t entered correctly
- WordPress search shows protected content
- Can I disable xml-rpc by setting it to false?
- How can I disable new plugin and theme install, but allow updates?
- Help to Create a Simple Plugin to make a post
- Validating ajax search
- Content-Security-Policy implementation with WordPress W3Total Cache plugin installed
- Asking help regarding potential malware
- “Fire Secure” menu item
- https rewrite not working for All in one security Brute force > rename login url
- Redux framework somehow added to my site, can’t locate in plugins
- Being hacked. Is there a list of WordPress security holes I can check against?
- wp_verify_nonce fails always
- Validating values using Settings API?
- using .htaccess only for wordpress security no plugins
- Unwanted Links and Spam WordPress Pages and Posts
- Problem with permissions in wp-content/plugins
- File permissions for wp-minify plugin
- What is the recommended way to be notified of security updates to my plugins? [closed]
- How to resolve these findings from security audit
- How I can hide my wp folders from Inspect Element (Developer Tools)
- How to Find WordPress site has backdoor login Codes
- How to rename files during upload to a random string?
- WordPress website is redirecting on some different shopping page
- WordPress User Registration/ Sign Up -> Able to take Paid Certification Courses & keep track of Completed Certificates
- Block Root REST API Route using custom &/or iThemes