About this video
See why hiding the WordPress login page cannot stop automated attacks through XML-RPC, and learn where stronger authentication controls help.
Changing the login page URL can reduce casual visits, but it does not close other authentication paths. This video demonstrates an XML-RPC multicall attack and shows why an obscured wp-login.php address does not address that exposure.
What you’ll see
- How automated requests can target WordPress authentication through XML-RPC.
- Why hiding the login URL leaves that path available.
- Ways to reduce the exposed attack surface and apply stronger authentication controls.
For more background, read Strengthening WordPress login security with AAM.