1 Comment
  1. Here are some recommendations:

    If possible enable MFA in wordpress. This will block password based login attempts all together. You can find the option in WordFence here:

    /wp-admin/admin.php?page=WFLS#top#manage

    Then I recommend disabling XML RPC Auth. visit

    /wp-admin/admin.php?page=WFLS#top#settings

    and check “**Disable XML-RPC authentication”**

    If you setup MFA, then also make sure “**Require 2FA for XML-RPC call authentication”** is set to “**required**”

    Another thing you can do is mess with the brute force settings in wordfence here:

    /wp-admin/admin.php?page=WordfenceOptions

    On this page, there is a section “**Brute Force Protection**”

    Here you can configure how soon a person is blocked by wordfence. I recommend lowering the thresholds and increasing the timeout period.

    Something like

    “Count Failures over” 6h

    “Lockout for” 6h

    “Lock out after how many login failures” and “Lock out after how many forgot password attempts” to 10 or so (too low and you may block yourself)

    These above measures will ensure you are safe.

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer