Browse documentation
WordPress

WordPress Sign-in Protection: Lock-outs, Two-Factor and a Secret Login Address

Stop password guessing and stolen logins with lock-outs, Cloudflare Turnstile, authenticator-app codes and a hidden login page.

3 min readUpdated Oct 10, 2026

The Sign-in section of the Security tab protects the WordPress login page. Remember to press Apply to site after changing anything.

Lock out addresses that keep guessing passwords

After too many wrong passwords, that address is refused for a while, even if the next password is right. The defaults are 5 failed tries counted over 15 minutes, then a 30-minute lock. You can change them: tries from 3 to 20, the counting window from 5 to 120 minutes and the lock from 5 to 1440 minutes. An address on your allow list (see Firewall, Blocking and Under Attack Mode) is never locked out.

Cloudflare Turnstile

Turnstile is a free, privacy-friendly check that stops bots at the login form. Create a widget in your Cloudflare dashboard (Turnstile), add your site's domain to it, switch Turnstile on here and paste the site key and the secret key. The check is shown on your site's own domains only, so your staging copy stays easy to log in to. If Cloudflare cannot be reached, logins still work.

Two-factor sign-in

A user with two-factor on must give a 6-digit code from an authenticator app (Google Authenticator, Authy, 1Password and similar) as well as their password. Users who have not set it up sign in as before.

Set it up for a user

  1. In Sign-in, open Two-factor sign-in and press Manage users.
  2. Press Set up next to the person. A QR code and a setup key appear.
  3. They scan the QR code with their authenticator app (or type the key in by hand) and enter the 6-digit code the app shows.
  4. FlyNode shows eight recovery codes, once. Save them somewhere safe. Each works one time if the phone is lost.

Treat the setup key like a password: anyone who has it can make the codes. To switch someone off, press Turn off next to their name.

How signing in works

The login form asks for the password. If the account uses two-factor, WordPress then asks for the authentication code (or a recovery code) and the person enters their password again with it. A wrong code counts as a failed attempt for the lock-out; being asked for the code does not. A code can only be used once.

Good to know

  • The switch Ask for the code at sign-in turns the question on or off for everyone without losing anyone's setup.
  • 1-Click WP-Admin from your FlyNode dashboard signs you in without a code: it already needs your FlyNode account.
  • Application passwords (used by apps and integrations) are separate credentials and are not asked for a code. If you block XML-RPC (recommended) it cannot be used to get around two-factor either.
  • The Security overview warns while any administrator has not set two-factor up.

A secret login address

Bots look for /wp-login.php and /wp-admin. With a secret login address, the login form moves to an address only you know, for example /my-team-door. The old address, and /wp-admin for anyone who is not signed in, answer "not found".

  1. Switch on Use a secret login address and type the address: 4 to 40 letters, numbers or dashes. Names WordPress already uses (such as login, admin or wp-admin) are not allowed.
  2. Press Apply to site. FlyNode checks that the new address really shows the login form and the old one answers "not found". If it cannot, it leaves the secret address off, applies everything else, and tells you why.
  3. Save the address in your password manager. The tab shows it, with a copy button, once it is on.

It needs pretty permalinks (Settings, Permalinks in WP Admin). Password-reset and lost-password links use the new address too. If you forget it, use 1-Click WP-Admin from the dashboard to get in, then switch the option off here.

Still stuck?

Open a support ticket from your dashboard and include the container name.

Contact support