HustleHardNow
Regular Member
- Jun 30, 2017
- 290
- 60
One of my WordPress sites has been getting flooded by bots trying to brute force into my /wp-login.php page for over 2 days now. They haven't been able to do so yet because I have the WordFence plug-in installed that has a firewall which has been blocking failed login attempts right as they happen but this is not stopping them from trying.
I also used the Hide my WP plug-in to change the /wp-login.php page to a different URL so every time someone visits the /wp-login.php page it leads to a 404 page, but the bot requests to that page have continued.
Is there anything I can do to curtail this bot flood? I was thinking of either purchasing the premium version of WordFence because it has a built-in IP blacklist, or even changing my DNS to Cloudflare and letting Cloudflare do it's job.
Would either one of those ideas actually clamp down on these bot hits or is there something else that could be done to stop this?
Any help is appreciated!
I also used the Hide my WP plug-in to change the /wp-login.php page to a different URL so every time someone visits the /wp-login.php page it leads to a 404 page, but the bot requests to that page have continued.
Is there anything I can do to curtail this bot flood? I was thinking of either purchasing the premium version of WordFence because it has a built-in IP blacklist, or even changing my DNS to Cloudflare and letting Cloudflare do it's job.
Would either one of those ideas actually clamp down on these bot hits or is there something else that could be done to stop this?
Any help is appreciated!