{"id":28050,"date":"2016-09-22T23:01:11","date_gmt":"2016-09-22T15:01:11","guid":{"rendered":"https:\/\/www.hongkiat.com\/blog\/?p=28050"},"modified":"2022-10-18T20:12:17","modified_gmt":"2022-10-18T12:12:17","slug":"strengthen-wordpress-security","status":"publish","type":"post","link":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/","title":{"rendered":"5 Tips to Toughen Up Your WordPress Login Security"},"content":{"rendered":"<p>No matter the size of your website, losing your site data or not being able to access your own website can be a nerve-wracking experience. WordPress, which powers more than 25% of the Web, is one of the most targeted websites for hackers.<\/p>\n<p>In our previous posts, we have shown you <strong>a number of tips and tricks which already covered almost everything to <a href=\"https:\/\/www.hongkiat.com\/blog\/secure-wordpress-blog-tips\/\">secure your WordPress website<\/a><\/strong>. Still, there is always room for improvement. In this post we will be looking at a few more tips to help you make your WordPress site harder to breach.<\/p>\n<p class=\"recommended_top\">\n\t\t\t\t\t<strong>Read Also:<\/strong>\u00a0\n\t\t\t\t\t<a target=\"_blank\" href=\"https:\/\/www.hongkiat.com\/blog\/hardening-wordpress-security\/\">10 Plugins to Harden WordPress Security<\/a>\n\t\t\t\t<\/p>\n<h2>1. Bcrypt Password Hashing<\/h2>\n<p>WordPress was started in 2003 when PHP and the  Web in general were still in their early days. Facebook was not around yet,  PHP did not even have OOP (Object-oriented Programming) architecture built-in; hence, WordPress inherited legacies that are no longer ideal today \u2013 including how it <em>encrypts<\/em> the password.<\/p>\n<p class=\"recommended_top\">\n\t\t\t\t\t<strong>Read Also:<\/strong>\u00a0\n\t\t\t\t\t<a target=\"_blank\" href=\"https:\/\/www.hongkiat.com\/blog\/dropbox-hack-and-its-impact\/\">Lessons from Dropbox Hack: State of Web Security<\/a>\n\t\t\t\t<\/p>\n<p>WordPress to this day still uses MD5 <em>hashing<\/em>. Basically, what it does is to turn your <code>123456<\/code> password into something like <code>e10adc3949ba59abbe56e057f20f883e<\/code>.<\/p>\n<p>However, since computers are now more sophisticated than 10 years ago this <em>hashed<\/em> password can now be easily reversed into its bare form <a href=\"https:\/\/www.php.net\/manual\/en\/faq.passwords.php#faq.passwords.fasthash\">almost instantly<\/a>.<\/p>\n<p>PHP has <strong>native encrypting<\/strong> since 5.5 and If your WordPress is running in PHP5.5 or above, there is handy plugin called <a href=\"https:\/\/github.com\/roots\/wp-password-bcrypt\">wp-password-bcrypt<\/a> that allows you to embrace this native utility in PHP.<\/p>\n<p>Install and activate the plugin through <a href=\"https:\/\/getcomposer.org\/\">Composer<\/a> or through <a href=\"https:\/\/codex.wordpress.org\/Must_Use_Plugins\">MU-Plugins<\/a>. Re-save your password and you are all set.<\/p>\n<h2>2. Enable WordPress.com Protect<\/h2>\n<p>Brute-force is a common hacking attempt where  attackers try logging in to your website by guessing numerous possible passwords, typically words found in the dictionary. This is the  reason why you should set a hard-to-guess password.<\/p>\n<p>Automattic, the people behind WordPress.com, has acquired one of the most popular WordPress plugins that can counter brute-force attacks. It is called <a href=\"https:\/\/wordpress.org\/plugins\/bruteprotect\/\">BruteProtect<\/a>, and it is integrated with Jetpack.<\/p>\n<p>Based on  our experience, it has <strong>tremendously helped us<\/strong> combat brute-force attacks more than <strong>close to  a million<\/strong> times.<\/p>\n<figure><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/assets.hongkiat.com\/uploads\/strengthen-wordpress-security\/jetpack-report.jpg\" height=\"100\" width=\"750\" alt=\"Jetpack Report\"><figcaption>Jetpack Dashboard Widget reporting the number of attack and spam encountered.<\/figcaption><\/figure>\n<p>To get it, you need to install Jetpack\u2019s latest version and connect your website to WordPress.com. Then enable the \u201cProtect\u201d module, and white-listing your own IP address as well.<\/p>\n<figure><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/assets.hongkiat.com\/uploads\/strengthen-wordpress-security\/jetpack-protect-module-activated.jpg\" height=\"234\" width=\"750\" alt=\"Jetpack Protect module menu in the Settings\"><\/figure>\n<p>Now you should feel a bit more safer.<\/p>\n<h2>3. Hide Your Login URL<\/h2>\n<p>WordPress is very well-known for the login page, <code>wp-login.php<\/code>. Hence hackers know which exact page  to direct their brute-force attacks. You can make it harder for them by <strong>disguising your WordPress login URL<\/strong>.<\/p>\n<p>Fortunately, there are a few plugins that provide this utility:<\/p>\n<ul>\n<li><a href=\"https:\/\/wordpress.org\/plugins\/better-wp-security\/\">iThemes Security<\/a><\/li>\n<li><a href=\"https:\/\/wordpress.org\/plugins\/wps-hide-login\/\">WPS Hide Login<\/a><\/li>\n<\/ul>\n<figure><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/assets.hongkiat.com\/uploads\/strengthen-wordpress-security\/custom-wordpress-login-url.jpg\" height=\"420\" width=\"750\" alt=\"WordPress login form with the custom URL\"><\/figure>\n<h2>4. Disable \u201cForget Password\u201d<\/h2>\n<p>The \u201cForget Password\u201d utility in the login form is a way in for attackers, who usually go through an <a href=\"https:\/\/en.wikipedia.org\/wiki\/SQL_injection\">SQL injection<\/a> to get your login credentials. If there are only a few people who have access to the admin area, it might be better to switch it off.<\/p>\n<p>To do so, create a new file upload \u2013 name it <code>forget-password.php<\/code>.<\/p>\n<p>First we change the lost password URL:<\/p>\n<pre>\r\nfunction lostpassword_url() {\r\n\treturn site_url( 'wp-login.php' );\r\n}\r\nadd_filter( 'lostpassword_url','lostpassword_url' );\r\n<\/pre>\n<p>Remove the link. Unfortunately, WordPress does not provide a proper hook to do this neatly through an <code>add_filter<\/code> function. So, we do it with JavaScript instead.<\/p>\n<pre>\r\nfunction lostpassword_elem( $page ) { ?>\r\n\r\n&lt;script type=\"text\/javascript\"&gt;\r\n(function(){\r\n\tvar links = document.querySelectorAll( 'a' );\r\n\r\n\tfor (var i = links.length - 1; i &gt;= 0; i--) {\r\n\t\tif ( links[i].innerText === \"Lost your password?\" ) {\r\n\t\t\tlinks[i].parentNode.removeChild( links[i] );\r\n\t\t}\r\n\t};\r\n}());\r\n&lt;\/script&gt;\r\n\r\n&lt;?php }\r\nadd_action( 'login_footer', 'lostpassword_elem' );\r\n<\/pre>\n<p>Lastly, we redirect the \u201cLost Password\u201d URL to the login screen.<\/p>\n<pre>\r\nfunction lostpassword_redirect() {\r\n\tif ( isset( $_GET[ 'action' ] ) ){\r\n   \t\tif ( in_array( $_GET[ 'action' ], array( 'lostpassword', 'retrievepassword' ) ) ) {\r\n\t\t\twp_redirect( '\/wp-login.php', 301 );\r\n\t\t\texit;\r\n\t\t}\r\n\t}\r\n}\r\nadd_action( 'init','lostpassword_redirect' );\r\n<\/pre>\n<h2>5. Enable HTTPS<\/h2>\n<p>HTTPS gives your site an extra layer of security with data transmission. It may also give you a boost  in Google search rankings. And now you can get valid HTTPS cert <strong>for free<\/strong> through the communal initiative <a href=\"https:\/\/letsencrypt.org\/\">Let\u2019s Encrypt<\/a>.<\/p>\n<p>For WordPress websites you can easily obtain a <em>Let\u2019s Encrypt<\/em> certificate with <a href=\"https:\/\/wordpress.org\/plugins\/wp-encrypt\/\">WP Encrypt<\/a>. So there is no reason why you should not deploy HTTPS in your website today.<\/p>\n<figure><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/assets.hongkiat.com\/uploads\/strengthen-wordpress-security\/lets-encrypt.jpg\" height=\"254\" width=\"750\" alt=\"Let's encrypt homepage\"><\/figure>\n<h2>Wrapping Up<\/h2>\n<p>I just like to leave you with the reminder that in spite of all these attempts, our websites <strong>could still be subject to attacks, hacks and to being compromised by hackers<\/strong> through means beyond our comprehension. Even large companies like Dropbox and LinkedIn have fallen prey to security threats.<\/p>\n<p>As a last resort, <strong>remember to regularly back up your website\u2019s files and database<\/strong> whenever you can.<\/p>","protected":false},"excerpt":{"rendered":"<p>No matter the size of your website, losing your site data or not being able to access your own website can be a nerve-wracking experience. WordPress, which powers more than 25% of the Web, is one of the most targeted websites for hackers. In our previous posts, we have shown you a number of tips&hellip;<\/p>\n","protected":false},"author":113,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[49],"tags":[4663,4601,3325,252],"topic":[4520],"class_list":["entry-content","is-maxi"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v22.8 (Yoast SEO v27.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>5 Tips to Toughen Up Your WordPress Login Security - Hongkiat<\/title>\n<meta name=\"description\" content=\"No matter the size of your website, losing your site data or not being able to access your own website can be a nerve-wracking experience. WordPress,\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"5 Tips to Toughen Up Your WordPress Login Security\" \/>\n<meta property=\"og:description\" content=\"No matter the size of your website, losing your site data or not being able to access your own website can be a nerve-wracking experience. WordPress,\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Hongkiat\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/hongkiatcom\" \/>\n<meta property=\"article:published_time\" content=\"2016-09-22T15:01:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-10-18T12:12:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/assets.hongkiat.com\/uploads\/strengthen-wordpress-security\/jetpack-report.jpg\" \/>\n<meta name=\"author\" content=\"Thoriq Firdaus\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@tfirdaus\" \/>\n<meta name=\"twitter:site\" content=\"@hongkiat\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Thoriq Firdaus\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/\"},\"author\":{\"name\":\"Thoriq Firdaus\",\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/#\\\/schema\\\/person\\\/e7948c7a175d211496331e4b6ce55807\"},\"headline\":\"5 Tips to Toughen Up Your WordPress Login Security\",\"datePublished\":\"2016-09-22T15:01:11+00:00\",\"dateModified\":\"2022-10-18T12:12:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/\"},\"wordCount\":690,\"commentCount\":6,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/assets.hongkiat.com\\\/uploads\\\/strengthen-wordpress-security\\\/jetpack-report.jpg\",\"keywords\":[\"ad-divi\",\"Security and Privacy\",\"WordPress Security\",\"WordPress Tips\"],\"articleSection\":[\"WordPress\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/\",\"url\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/\",\"name\":\"5 Tips to Toughen Up Your WordPress Login Security - Hongkiat\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/assets.hongkiat.com\\\/uploads\\\/strengthen-wordpress-security\\\/jetpack-report.jpg\",\"datePublished\":\"2016-09-22T15:01:11+00:00\",\"dateModified\":\"2022-10-18T12:12:17+00:00\",\"description\":\"No matter the size of your website, losing your site data or not being able to access your own website can be a nerve-wracking experience. WordPress,\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/#primaryimage\",\"url\":\"https:\\\/\\\/assets.hongkiat.com\\\/uploads\\\/strengthen-wordpress-security\\\/jetpack-report.jpg\",\"contentUrl\":\"https:\\\/\\\/assets.hongkiat.com\\\/uploads\\\/strengthen-wordpress-security\\\/jetpack-report.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/strengthen-wordpress-security\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"5 Tips to Toughen Up Your WordPress Login Security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/\",\"name\":\"Hongkiat\",\"description\":\"Tech and Design Tips\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/#organization\",\"name\":\"Hongkiat.com\",\"url\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/wp-content\\\/uploads\\\/hkdc-logo-rect-yoast.jpg\",\"contentUrl\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/wp-content\\\/uploads\\\/hkdc-logo-rect-yoast.jpg\",\"width\":1200,\"height\":799,\"caption\":\"Hongkiat.com\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/hongkiatcom\",\"https:\\\/\\\/x.com\\\/hongkiat\",\"https:\\\/\\\/www.pinterest.com\\\/hongkiat\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/#\\\/schema\\\/person\\\/e7948c7a175d211496331e4b6ce55807\",\"name\":\"Thoriq Firdaus\",\"description\":\"Thoriq is a writer for Hongkiat.com with a passion for web design and development. He is the author of Responsive Web Design by Examples, where he covered his best approaches in developing responsive websites quickly with a framework.\",\"sameAs\":[\"https:\\\/\\\/thoriq.com\",\"https:\\\/\\\/x.com\\\/tfirdaus\"],\"jobTitle\":\"Web Developer\",\"url\":\"https:\\\/\\\/www.hongkiat.com\\\/blog\\\/author\\\/thoriq\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"5 Tips to Toughen Up Your WordPress Login Security - Hongkiat","description":"No matter the size of your website, losing your site data or not being able to access your own website can be a nerve-wracking experience. WordPress,","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/","og_locale":"en_US","og_type":"article","og_title":"5 Tips to Toughen Up Your WordPress Login Security","og_description":"No matter the size of your website, losing your site data or not being able to access your own website can be a nerve-wracking experience. WordPress,","og_url":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/","og_site_name":"Hongkiat","article_publisher":"https:\/\/www.facebook.com\/hongkiatcom","article_published_time":"2016-09-22T15:01:11+00:00","article_modified_time":"2022-10-18T12:12:17+00:00","og_image":[{"url":"https:\/\/assets.hongkiat.com\/uploads\/strengthen-wordpress-security\/jetpack-report.jpg","type":"","width":"","height":""}],"author":"Thoriq Firdaus","twitter_card":"summary_large_image","twitter_creator":"@tfirdaus","twitter_site":"@hongkiat","twitter_misc":{"Written by":"Thoriq Firdaus","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/#article","isPartOf":{"@id":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/"},"author":{"name":"Thoriq Firdaus","@id":"https:\/\/www.hongkiat.com\/blog\/#\/schema\/person\/e7948c7a175d211496331e4b6ce55807"},"headline":"5 Tips to Toughen Up Your WordPress Login Security","datePublished":"2016-09-22T15:01:11+00:00","dateModified":"2022-10-18T12:12:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/"},"wordCount":690,"commentCount":6,"publisher":{"@id":"https:\/\/www.hongkiat.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/#primaryimage"},"thumbnailUrl":"https:\/\/assets.hongkiat.com\/uploads\/strengthen-wordpress-security\/jetpack-report.jpg","keywords":["ad-divi","Security and Privacy","WordPress Security","WordPress Tips"],"articleSection":["WordPress"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/","url":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/","name":"5 Tips to Toughen Up Your WordPress Login Security - Hongkiat","isPartOf":{"@id":"https:\/\/www.hongkiat.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/#primaryimage"},"image":{"@id":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/#primaryimage"},"thumbnailUrl":"https:\/\/assets.hongkiat.com\/uploads\/strengthen-wordpress-security\/jetpack-report.jpg","datePublished":"2016-09-22T15:01:11+00:00","dateModified":"2022-10-18T12:12:17+00:00","description":"No matter the size of your website, losing your site data or not being able to access your own website can be a nerve-wracking experience. WordPress,","breadcrumb":{"@id":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/#primaryimage","url":"https:\/\/assets.hongkiat.com\/uploads\/strengthen-wordpress-security\/jetpack-report.jpg","contentUrl":"https:\/\/assets.hongkiat.com\/uploads\/strengthen-wordpress-security\/jetpack-report.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hongkiat.com\/blog\/strengthen-wordpress-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hongkiat.com\/blog\/"},{"@type":"ListItem","position":2,"name":"5 Tips to Toughen Up Your WordPress Login Security"}]},{"@type":"WebSite","@id":"https:\/\/www.hongkiat.com\/blog\/#website","url":"https:\/\/www.hongkiat.com\/blog\/","name":"Hongkiat","description":"Tech and Design Tips","publisher":{"@id":"https:\/\/www.hongkiat.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hongkiat.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hongkiat.com\/blog\/#organization","name":"Hongkiat.com","url":"https:\/\/www.hongkiat.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hongkiat.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.hongkiat.com\/blog\/wp-content\/uploads\/hkdc-logo-rect-yoast.jpg","contentUrl":"https:\/\/www.hongkiat.com\/blog\/wp-content\/uploads\/hkdc-logo-rect-yoast.jpg","width":1200,"height":799,"caption":"Hongkiat.com"},"image":{"@id":"https:\/\/www.hongkiat.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/hongkiatcom","https:\/\/x.com\/hongkiat","https:\/\/www.pinterest.com\/hongkiat\/"]},{"@type":"Person","@id":"https:\/\/www.hongkiat.com\/blog\/#\/schema\/person\/e7948c7a175d211496331e4b6ce55807","name":"Thoriq Firdaus","description":"Thoriq is a writer for Hongkiat.com with a passion for web design and development. He is the author of Responsive Web Design by Examples, where he covered his best approaches in developing responsive websites quickly with a framework.","sameAs":["https:\/\/thoriq.com","https:\/\/x.com\/tfirdaus"],"jobTitle":"Web Developer","url":"https:\/\/www.hongkiat.com\/blog\/author\/thoriq\/"}]}},"jetpack_featured_media_url":"https:\/\/","jetpack_shortlink":"https:\/\/wp.me\/p4uxU-7iq","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/posts\/28050","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/users\/113"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/comments?post=28050"}],"version-history":[{"count":3,"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/posts\/28050\/revisions"}],"predecessor-version":[{"id":41874,"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/posts\/28050\/revisions\/41874"}],"wp:attachment":[{"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/media?parent=28050"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/categories?post=28050"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/tags?post=28050"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.hongkiat.com\/blog\/wp-json\/wp\/v2\/topic?post=28050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}