i think what david said about hiding the login screen is essentially putting the login page to a different URL. most hackers targets specific default URis not unless their script is pretty advance that can sniff for redirects but in most cases they dont do that. if you are using live traffic or atleast you can see in your logs the ip of the login attempt, copy the IP and you can go to Wordfence - > Blocked Ips, somewhere at the the top of the screen there is a input box right beside the button labeled a Manually Block IP. you can paste the IP there
↧