On Smarthost servers, security measures have been enabled to prevent brute-force attacks targeting WordPress. The security protects the wp-login.php address (login screen) and the xmrpc.php file (WordPress remote management). By enabling such security, a WordPress hack attempt will be interrupted by the need to enter reCaptcha.
In practice, it looks like a user who wants to log in to the panel and knows the login and password will do it without any problems, when entering the administration panel page, he will see a standard login field:
data:image/s3,"s3://crabby-images/99771/9977171284024fb34ad3fed1b9ca3b58d41ef578" alt=""
A person / robot who is entering random passwords after 10 unsuccessful attempts within 5 minutes will see a field with a request for verification:
data:image/s3,"s3://crabby-images/9f554/9f55428c597086a1710c78726356d45592a51c30" alt=""
Latest posts by Tomasz (see all)
- Clearing redis cache memory - December 22, 2022
- Does “Time to first byte” (TTFB) means server speed? - October 31, 2022
- Automatic WordPress login security by reCaptcha - August 24, 2021