WordPress Brute Force Protection
Close wp-login.php and xmlrpc.php to bots with one click, and keep signing in from the panel.
Brute force attacks target the WordPress login page (wp-login.php) and xmlrpc.php, with bots trying hundreds of passwords a minute. Birtikta's Brute Force Protection closes both doors with one click, site by site. Bots never reach the login form, while you keep signing in to the site with one-click login from the Birtikta panel.
The login form closes to bots
With protection on, outside login requests to wp-login.php are refused with a 403 and xmlrpc.php is shut completely. On Apache servers the block is applied by an .htaccess rule before WordPress even loads; on other servers the plugin applies the same block in PHP.
See who tried, and when
The WP Login Entries screen lists successful and failed login attempts across all your sites with the username, IP address and country. Block a suspicious IP with one click and get notified straight away with the failed login alarm.
What completes WordPress brute force protection
One-click login
With the login page closed, you still sign in from the Birtikta panel with one click and no password.
One-click WP loginAsk Biri
Say "Disable WP admin login" and confirm; the AI assistant switches protection on for you.
WordPress AI assistantGood to know
Protection does not count or limit login attempts; it closes the login page to the outside entirely. That means the lost password and registration forms are closed too while it is on. Because xmlrpc.php is shut completely, apps that rely on it (such as some Jetpack features) will not work. Protection is switched on or off separately for each site.
Frequently Asked Questions
On the sites where it is on, outside login requests to wp-login.php are refused with a 403 and xmlrpc.php is closed completely. Bots cannot reach the login form, so they cannot try passwords.
With one-click login from the Birtikta panel. It does not use wp-login.php, so it keeps working while protection is on. Users who are already logged in are not affected either.
On Apache the block is applied by an .htaccess rule before WordPress loads. On other servers such as Nginx the Birtikta plugin applies the same block in PHP.
Yes. The WP Login Entries screen lists successful and failed attempts with the username, IP and country, and you can block an IP from there.
Protection has a separate switch for each site; all your sites appear in one list on the Brute Force Protection page.
While protection is on, the lost password and registration forms are closed too, and apps that use xmlrpc.php stop working. Log out, session refresh and the password-protected post form keep working.