NewThe agent now reads your files and links, and can search the web.Files, links and web search in the agent.See how

DocsSecurity

Protect sign-in: lockouts, your own address and two-factor

Lock out addresses that guess passwords, give the sign-in page an address of your own, require two-factor codes, add a CAPTCHA, and require strong passwords that aren’t in data breaches.

Everything here is in Native AI → Security → Sign-in.

Sign-in protection: lockouts after failed sign-ins, usernames bots try, a sign-in address of your own, two-factor for chosen roles and a CAPTCHA
Sign-in protection: lockouts, usernames bots try, your own sign-in address and two-factor.

Failed sign-ins#

  • 5 wrong passwords within 15 minutes lock the address out of signing in for 30 minutes; the 3rd lockout in a day locks it out for 24 hours (all adjustable). A lockout only stops signing in — the address can still read the site.
  • Usernames bots try — admin, administrator, root, test, user — lock the address out at once, when no account has them.
  • Error messages say “the username, email address or password is incorrect” either way, so bots can’t learn which usernames exist.
  • Wrong passwords through XML-RPC and the REST API count too.

Your own sign-in address#

Switch on Your own sign-in address and choose one, like team-entry. Sign in at yoursite.com/team-entry/; wp-login.php and, for people not signed in, wp-admin answer “not found”. Every link WordPress makes — sign out, lost password, password-reset emails — uses the new address, and it’s emailed to the site admin when it changes. WooCommerce’s My Account sign-in is unchanged.

Two-factor sign-in#

  1. Choose who must use itRequired for: administrators by default. People with these roles set it up the next time they sign in.
  2. Set it upEach person scans a QR code with an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Authy…) and enters the six-digit code — at sign-in, or any time in Users → Profile → Two-factor sign-in. With Codes by email allowed, people without an app get codes by email instead.
  3. Keep the backup codesTen single-use codes are shown once; each signs them in if they lose their phone.
  • Trust a device for 30 days skips the code on that browser (0 asks every time).
  • It works wherever the password is entered, including WooCommerce’s My Account.
  • Lost phone and backup codes? An administrator can Reset it on the person’s profile.
  • XML-RPC can’t sign in an account with two-factor using only its password.

CAPTCHA, passwords and sessions#

SettingWhat it does
Security check (CAPTCHA)A Cloudflare Turnstile or Google reCAPTCHA connection (add it in Forms → Integrations) on sign-in, registration, lost password and comments.
Strong passwords forPeople with these roles need 12+ characters (or 10 with three kinds), not their username, email or the site’s name, and not a common password.
Refuse passwords from data breachesChecked with Have I Been Pwned’s range API, which only receives the first 5 characters of the password’s SHA-1 hash — never the password.
Sign out after idle minutesEditors and administrators are signed out after a while without activity.
New-device emailsPeople get an email when they sign in from a browser or network not seen before; administrators’ new devices can alert you too.
XML-RPCOff, on without pingbacks and multicall (the default), or fully on.
Application passwordsLet apps sign in with their own passwords through the REST API, or not.

Signed in now lists people with active sessions and their devices, with Sign out to end their sessions.