DocsSecurity
Protect sign-in: lockouts, your own address and two-factor
Lock out addresses that guess passwords, give the sign-in page an address of your own, require two-factor codes, add a CAPTCHA, and require strong passwords that aren’t in data breaches.
Everything here is in Native AI → Security → Sign-in.

Failed sign-ins#
- 5 wrong passwords within 15 minutes lock the address out of signing in for 30 minutes; the 3rd lockout in a day locks it out for 24 hours (all adjustable). A lockout only stops signing in — the address can still read the site.
- Usernames bots try — admin, administrator, root, test, user — lock the address out at once, when no account has them.
- Error messages say “the username, email address or password is incorrect” either way, so bots can’t learn which usernames exist.
- Wrong passwords through XML-RPC and the REST API count too.
Your own sign-in address#
Switch on Your own sign-in address and choose one, like team-entry. Sign in at yoursite.com/team-entry/; wp-login.php and, for people not signed in, wp-admin answer “not found”. Every link WordPress makes — sign out, lost password, password-reset emails — uses the new address, and it’s emailed to the site admin when it changes. WooCommerce’s My Account sign-in is unchanged.
Two-factor sign-in#
- Choose who must use itRequired for: administrators by default. People with these roles set it up the next time they sign in.
- Set it upEach person scans a QR code with an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Authy…) and enters the six-digit code — at sign-in, or any time in Users → Profile → Two-factor sign-in. With Codes by email allowed, people without an app get codes by email instead.
- Keep the backup codesTen single-use codes are shown once; each signs them in if they lose their phone.
- Trust a device for 30 days skips the code on that browser (0 asks every time).
- It works wherever the password is entered, including WooCommerce’s My Account.
- Lost phone and backup codes? An administrator can Reset it on the person’s profile.
- XML-RPC can’t sign in an account with two-factor using only its password.
CAPTCHA, passwords and sessions#
| Setting | What it does |
|---|---|
| Security check (CAPTCHA) | A Cloudflare Turnstile or Google reCAPTCHA connection (add it in Forms → Integrations) on sign-in, registration, lost password and comments. |
| Strong passwords for | People with these roles need 12+ characters (or 10 with three kinds), not their username, email or the site’s name, and not a common password. |
| Refuse passwords from data breaches | Checked with Have I Been Pwned’s range API, which only receives the first 5 characters of the password’s SHA-1 hash — never the password. |
| Sign out after idle minutes | Editors and administrators are signed out after a while without activity. |
| New-device emails | People get an email when they sign in from a browser or network not seen before; administrators’ new devices can alert you too. |
| XML-RPC | Off, on without pingbacks and multicall (the default), or fully on. |
| Application passwords | Let apps sign in with their own passwords through the REST API, or not. |
Signed in now lists people with active sessions and their devices, with Sign out to end their sessions.
Related articles
On the features pages
Still have a question? Email us at support.