Your login is under attack. It comes protected.

Right now, bots are guessing passwords against your login form and through XML-RPC — thousands of tries, around the clock. MalCare ships five layers of login protection, on automatically from the moment you connect: a 400,000-site bot network, login limits, captcha, IP whitelisting, and built-in 2FA. Attackers run out of road. You and your team never notice any of it.

2B+attacks blocked / mo
350,000+bots blocked / mo
0 configon by default
UNDER SIEGE · LIVEFIG. 0 · THE GAUNTLETguesses stopped today · 12,847NETWORKLIMITSCAPTCHA2FA12 guessing5210WP-ADMINyou & your team · whitelisted2fa ✓guesses — stopped at a gateyou — straight throughreached the door uninvited · 0
the door · decisionslive

Trusted by 400,000+ websites across 120 countries

Intel
Toshiba
eBay
Manthan
SiteCare
NMU
01The siege

Every WordPress login is being guessed right now.

Brute force is bots trying username and password combinations until one works. The evidence is in your own logs — floods of failed logins. It isn't personal; it's every site, all the time. And every guess burns CPU and bandwidth, so the siege slows your real visitors even when it never gets in.

FIG. 1Two doors, one siege
wp-loginxmlrpc.phpthe door everyone guardsthe door attackers love — and most plugins ignoreboth doors,guardedmost limit-login plugins guard the top door — and leave the bottom one open.

Read: XML-RPC accepts logins remotely — attackers send relentless request floods against it with varying passwords. MalCare's login protection covers the form and XML-RPC, automatically.

FIG. 1Two doors, one siege
1

wp-login

The door everyone guards — floods of password guesses.

GUARDED
2

xmlrpc.php

The door attackers love — remote login floods most plugins ignore.

ALSO GUARDED
02The five layers

Five layers. Each one ends a different attack.

No single lock survives everything — a limiter can't stop a stolen password, and 2FA alone still lets bots burn your server. The combination does. And it's on by default.

LAYER 1

Bot protection

The 400,000-site network convicts crackers before their first guess here. Ends: the botnet. How bots are identified →

LAYER 2

Login limits

Repeated failures get locked out — on the form and XML-RPC alike. Ends: the patient guesser.

LAYER 3

Captcha

A challenge humans pass in seconds — and scripts don't. Ends: the automated retry.

LAYER 4

IP whitelist

Known users' IPs are never locked out at all. Ends: the false positive.

LAYER 5

2FA, built in

A correct stolen password still isn't enough. Ends: the leaked password. How 2FA works →

TOGETHER

The gauntlet

Each layer ends what the previous one can't. Attackers run out of road before the door.

03No lockout pain

Strict for bots. Painless for humans.

The real fear with login limits is locking yourself out — and with crude time-based plugins, it's justified. MalCare's answer is structural: locked-out humans unblock themselves immediately with reCAPTCHA. No waiting out a timer, no emailing your host. And normal logins look completely normal.

FIG. 2The recovery loop — same wall, opposite outcomes
THE LOCKOUT · CAPTCHAyou · mistyped ×5back in · secondsbot · guessingstill locked · foreversame wall. humans recover in secondsscripts never do.

Read: the lockout is the same for everyone — the recovery isn't. A human proves it in one captcha and walks back in; an automated script stays outside indefinitely.

FIG. 2The recovery loop

You, locked out

Mistyped ×5 → captcha → back in. Seconds, self-serve.

RECOVERED

The bot, locked out

Guessing → captcha it can't pass → still locked.

FOREVER
3.1

Time-based plugins

Lock everyone out for a fixed period — including you, on a bad-memory day.

20 MIN · EVERYONE
3.2

MalCare

Humans recover immediately via reCAPTCHA; scripts never do. Strictness without the collateral.

SECONDS · HUMANS
3.3

Your team

Whitelist their IPs — whitelisted users aren't subject to lockouts at all.

PRE-CLEARED
04Zero configuration

On from the moment you connect. Nothing to tune.

No thresholds to pick, no lockout durations to weigh, no settings page to revisit. Login protection operates automatically once your site is connected to MalCare. Want proof? Try to log in wrong, quickly, and watch yourself get locked out — then pass the captcha and walk back in.

4.1

A dedicated limiter plugin

Pick retry counts, tune lockout durations, maintain one more plugin forever.

YOUR HOMEWORK
4.2

A functions.php snippet

Edit a critical theme file, risk a fatal error, lose it on the next theme update — and block themes don't even have the file.

YOUR RISK
4.3

MalCare

Connected = protected. All five layers, already running.

ALREADY DONE
05The dividend

Blocked guesses give you your server back.

Login floods strain server resources — real visitors feel a slow, unresponsive site. Ending the siege isn't just security; it's performance you can measure.

5.1

Load, returned

Every blocked guess is CPU and bandwidth your real visitors get back.

LIGHTER
5.2

Evidence, kept

Every attempt — blocked, failed, or successful — lands in the activity log. The siege becomes visible, and so does anything unusual.

ON RECORD
06Where it fits

The door, inside 7-layer security.

Login protection guards the most-attacked door; the rest of the suite covers everything around it.

6.1

Bot protection

Manages the non-human crowd — most crackers never arrive.

THE BOUNCER
6.2

Login protection

Guards the door — limits, captcha, whitelist, 2FA, combined.

THE GAUNTLET
6.3

Firewall

Blocks attack payloads — exploits inside individual requests.

THE PERIMETER
6.4

Malware scanner

Finds whatever slips through, wherever it hides.

THE SEARCHLIGHT
6.5

Activity log

Records every hand that touches the site — including every login.

THE RECORD

One dashboard — every layer already on.

07Voices

What customers say.

Real customers — quotes from our reviews and case studies.

"

Best login protection ever! We handle hundreds of sites, and I'd heard bad stories about brute force attacks & password hacking… but thankfully we never had to worry about this because of MalCare. I'm sure this saved us from many sleepless nights!

Robert AbelaWP Activity Log
"

I was on the beach with my family when MalCare notified me of a plugin vulnerability across 50 of my sites. With one click on my smartphone, all sites were fixed within minutes.

Paul LaceyPaul LaceyWordPress Expert
Watch case study →
"

I had been running iThemes, WordFence & Sucuri, but they kept getting hacked. Then I installed MalCare, which quickly found the malware and cleaned up the entire site.

Adam SilverAdam SilverConciergeWP · Founder
Watch case study →
08Questions

Answered straight.

How many failed attempts before a lockout?+

Repeated rapid failures trigger it — industry guidance puts the right threshold at 3–5 attempts, and MalCare handles this automatically. There's nothing for you to configure or tune.

What if I lock myself out?+

Pass the reCAPTCHA and you're back in immediately. No waiting out a timer, no support ticket to your host — the recovery is self-serve and takes seconds.

Can I make sure my team is never locked out?+

Yes. Whitelist their IPs — whitelisted users aren't subject to lockouts, even after failed attempts. Useful for offices, agencies, and anyone who logs in daily.

Does it protect XML-RPC too?+

Yes. XML-RPC accepts logins remotely and attackers flood it with password attempts exactly like the login form — so MalCare guards both doors, not just the one with a visible login box.

Will normal visitors or users see captchas?+

No. Normal logins look completely normal. The captcha appears as the recovery path after a lockout — a quick check that you're human, not a routine hoop.

Do I still need 2FA?+

They stop different things. Login limits stop guessing; 2FA stops a correct stolen password. Both are included in the plugin — use both.

Is this the same as bot protection?+

They're layers, not duplicates. Bot protection convicts bad actors across the 400,000-site network before they guess here; login limits catch whoever still gets through. Together they end the siege from both ends.

Does it slow down my site?+

The opposite. Login floods burn CPU and bandwidth; blocking them removes that load, and your real visitors get a faster site.

09Start

Protect the most-attacked door on your site.

Five layers of login protection, on automatically. Bots run out of road; your team never notices.

No configuration · no lengthy lockouts · 2FA included