site get login attempts after htaccess ip restriction

@birgire has a right answer

And they can use WPScan for example, with a brute force attack on wp-login.php

I recommand to rename your login page, you can do it manually or with a plugin.