Because WordPress powers over 40% of all websites, and because its login endpoint sits at the same predictable URL on almost every install, wp-login.php receives automated login attempts on nearly every publicly reachable site — often within hours of the domain first resolving, long before a human ever visits.
Two distinct patterns show up in real logs. Brute force tries many passwords against one known username (often admin or the site owner’s name, guessed from the About page). Credential stuffing tries a huge list of real username/password pairs leaked from unrelated breaches, betting that some fraction of users reuse passwords across sites. Both are almost always automated and distributed across many IP addresses to avoid simple rate limits.
Most login-hardening plugins work by blocking an IP after N failed attempts from that IP. That stops naive brute force but does very little against credential stuffing spread across hundreds of IPs, or against an attacker patient enough to stay under the per-IP threshold.
Thousands of failed logins are just internet background noise and rarely worth losing sleep over on their own. What matters is catching the one attempt that succeeds — a new admin session from an unfamiliar IP, immediately following a failed-login burst, is the actual signal worth an alert.
Real-time login-volume monitoring, with the noise-filtering to distinguish background internet scanning from a genuine attack in progress, is covered on the Security page. Per-site pricing for this kind of monitoring starts at $0 for your first site — see Pricing.
Connect a site in a few minutes and get your first inventory scan back immediately.
Try free →