Securing wp-login.php in WordPress
wp-login.php is a very attractive target for hackers trying to gain access to your site. They do this by automatically sending large numbers of POST requests to wp-login.php until they find the right one.
It is therefore advisable to secure it so that only your IP address can log in to WordPress.
Create a file named .htaccess in the public_html folder with the following content:
<Files wp-login.php>
Order Deny,Allow
deny from all
allow from 11.22.33.44
</Files>
Replace 11.22.33.44 with your own IP address. You can look up your IP address at www.toonipnummer.nl
Also create a file named 403.shtml in the public_html folder. This is where users are sent if they do not have access.
No hosting for your WordPress site yet? Take a look at our Dutch web hosting, with LiteSpeed, free SSL and daily backups.
