SECURITY FINDING
No brute-force or login protection on WordPress
What it is
No limit on login attempts and no two-factor authentication was detected, so automated bots can try unlimited passwords against the login page without being slowed down or locked out.
How to fix it
Install a login-attempt-limiting plugin and/or two-factor authentication, and make sure every admin account uses a strong, unique password.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.