security / cms & plugins / login page
CMS & plugins

Login page

WordPress's login page sits at a well-known address, making it a constant target for automated password-guessing attacks.

Severity if missing
Low
Category
CMS & plugins
Standard
OWASP

What it is

Every WordPress site has its login page at the same predictable location — /wp-login.php. Attackers know this, so it's one of the most probed URLs on the internet, hit continuously by bots trying common username and password combinations.

The page being reachable isn't a flaw in itself, but without protection it's an open invitation for brute-force attempts.

Why it matters

A predictable login page with no defences lets attackers try password after password unchallenged. Combined with exposed usernames or reused passwords, that's a realistic path to a break-in. Adding rate limiting, a login limit, or two-factor authentication turns an open door into a locked one.

The risk
An unprotected, publicly reachable login page invites continuous automated password-guessing attacks against your accounts.

How Pentrawl checks it

Pentrawl checks whether the WordPress login page is publicly reachable. It reports the finding so you can ensure the page is protected against automated attacks.

How to fix it

Protect the login page rather than just hiding it. Add rate limiting or a failed-login limit, enable two-factor authentication, and consider restricting access to trusted IP addresses.

Recommended
Add a login-attempt limit and two-factor authentication (via a security plugin).
Check your domain's Login page in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →