Brute force defence should reduce automated login attempts without locking out legitimate administrators. A layered setup combines rate limits, strong authentication, safe recovery, monitoring, updates and protection before requests consume WordPress resources.
How this guide was produced
Documented features reviewed on 10 September 2026. Firewall modes, feed timing and plan scope change, so confirm before you rely on them.
Eight options at a glance
| Option | Best fit | First thing to verify |
|---|---|---|
| Wordfence Security | WordPress firewall and login controls | Firewall mode, feed timing, resource use |
| Solid Security | Guided WordPress hardening | Included features and lockout policy |
| Sucuri | Cloud firewall and incident response | DNS routing and service plan |
| Jetpack Protect | Simple vulnerability checks | WAF features and account connection |
| Limit Login Attempts Reloaded | Focused login rate limiting | Trusted IP and lockout configuration |
| Cloudflare Turnstile | Privacy-minded bot challenges | Plugin integration and widget behaviour |
| WP 2FA | Two-factor authentication policies | Supported methods and recovery |
| MalCare | Managed scanning and firewall | Site connection, cleanup and plan scope |
How we assessed them
We compared protection location, rate limiting, two-factor authentication, bot challenges, XML-RPC handling, trusted networks, lockout safety, logs, alerts, firewall rules, vulnerability signals, multisite support, recovery, performance and ongoing cost.
Roll it out safely
- Create separate named administrator accounts and remove unused users
- Require long unique passwords, two-factor authentication and a protected recovery email
- Set rate limits from your normal traffic data, not guesswork
- Test login, password reset, application passwords, XML-RPC, mobile apps and trusted proxies
- Rehearse lockout recovery and emergency access before you need them
Read next
- Two-factor authentication plugins - the strongest single login control
- Hosts with free SSL - encrypt the login you are protecting
- Code snippet plugins - control who can run code
- Run a live speed test - security scanning has a performance cost
Where to get these
Direct links to the official plugin, theme and store pages for everything named above. Prices and plans are set by the vendor, and some links may earn us a commission.
- Get it
- Get it
Solid Security
Plugin · SolidWP · Freemium
- Get it
Sucuri
Plugin · Sucuri · Freemium
- Get it
Jetpack Protect
Plugin · Automattic · Freemium
- Get it
Limit Login Attempts Reloaded
Plugin · WPChef · Freemium
- Get it
Cloudflare Turnstile
Service · Cloudflare · Freemium
- Get it
WP 2FA
Plugin · Melapress · Freemium
- Get it
MalCare
Plugin · MalCare · Freemium
Common questions
Does changing the login URL stop brute force attacks?
It may reduce noise, but it is not a primary control. Attackers can discover endpoints and target other authentication routes.
Is rate limiting enough?
No. Combine it with unique passwords, two-factor authentication, updates, least privilege, monitoring and protected recovery.
Should failed logins block an IP forever?
Usually not. Shared networks and changing addresses affect real users. Use measured limits, increasing delays and a safe recovery path.
Fast WordPress editorial
Independent research edition · Published 10 September 2026. We update field guides when a plugin's documented capabilities change.









































































