Login page
WordPress's login page sits at a well-known address, making it a constant target for automated password-guessing attacks.
What it is
Every WordPress site has its login page at the same predictable location — /wp-login.php. Attackers know this, so it's one of the most probed URLs on the internet, hit continuously by bots trying common username and password combinations.
The page being reachable isn't a flaw in itself, but without protection it's an open invitation for brute-force attempts.
Why it matters
A predictable login page with no defences lets attackers try password after password unchallenged. Combined with exposed usernames or reused passwords, that's a realistic path to a break-in. Adding rate limiting, a login limit, or two-factor authentication turns an open door into a locked one.
How Pentrawl checks it
Pentrawl checks whether the WordPress login page is publicly reachable. It reports the finding so you can ensure the page is protected against automated attacks.
How to fix it
Protect the login page rather than just hiding it. Add rate limiting or a failed-login limit, enable two-factor authentication, and consider restricting access to trusted IP addresses.
Add a login-attempt limit and two-factor authentication (via a security plugin).