I’d stick to patterns rather than chasing lists, since shared creds on the web are usually scraped from leaks and can push you into sketchy territory. What helped me most on WP sites is just locking down default usernames, forcing long passphrases, and adding rate limits. Makes brute force stuff fall flat without needing to poke around for any magic list.