SECURITY FINDING

No brute-force or login protection on WordPress

What it is

No limit on login attempts and no two-factor authentication was detected, so automated bots can try unlimited passwords against the login page without being slowed down or locked out.

How to fix it

Install a login-attempt-limiting plugin and/or two-factor authentication, and make sure every admin account uses a strong, unique password.

In depth

We detected that your site allows unlimited attempts to guess your admin password without blocking whoever is trying, which makes it easy for someone to get unauthorized access to your control panel. To protect yourself, install a security plugin like Wordfence or Brute Force Protections that automatically locks out users after several failed login attempts. Also turn on two-factor authentication, which will ask you for a code from your phone in addition to your password each time you log in, making it much harder for someone to get in even if they guess your password. These two measures together dramatically reduce the risk of your site being compromised by automated attacks.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.