With Admins Still Choosing ‘Admin’, WordPress Password Troubles Continue
thecyberexpress.com
thecyberexpress.com
+ Change login URL from /wp-admin/ to something unique such as /custom-login. This stops the majority of bots as they usually only target /wp-admin
+ disable “admin” username
+ automatically block the IP address of any attempt to log in using “admin” username.
+ block IP address of x failed login attempts for y minutes.
This can be achieved by many free and commercial WordPress security plugins.
Is something like this possible in PHP?