All Systems Operational|support@delhihosting.com
WordPress

How to Limit Login Attempts in WordPress

25 Jan 2026 Β· 4 min read Β· DelhiHosting Team

By default WordPress lets anyone try to log in endlessly, which invites brute-force bots. Capping failed attempts shuts that attack down almost entirely.

Why it matters

Bots try thousands of username and password combinations against wp-login. Without a limit, they can keep guessing forever. Limiting attempts locks them out after a few failures, making the attack pointless.

Set it up

Install a login-limit plugin (some security plugins include it) and set a small number of allowed attempts and a lockout period. Legitimate users rarely fail more than a couple of times, so the impact on real people is minimal.

Combine with other defences

Pair attempt limits with strong passwords, two-factor authentication and a changed login URL. Together these make brute-force attacks effectively impossible.

Quick tips
  • βœ“Cap attempts at a few tries
  • βœ“Set a sensible lockout duration
  • βœ“Pair with two-factor authentication
  • βœ“Change the default login URL too
Key takeaway

Limiting login attempts locks out brute-force bots after a few tries β€” a simple, high-impact security control.

Related WordPress guides

Need a hand with this?

Our Delhi-based engineers set up, secure and speed up WordPress for you β€” free migration included.