What are these attacks?
A brute force attack is a bot that guesses your password again and again. It is like trying every key on a ring until one fits.

A DoS attack (denial of service) sends so many requests that your site becomes slow or stops. Think of a shop door blocked by a huge crowd. Real customers cannot get in.
Steps
- Log in to your WordPress dashboard.
- Go to Users and check that no one uses the username
admin. Create a new admin with a different name, then delete the old one. Back up your site first. - Set a long, strong password for every user. Use letters, numbers and symbols.
- Go to Plugins and click Add New. Search for a login limiting plugin, such as one named "Limit Login Attempts". Install and activate it.
- Open the plugin settings. Set it to lock out an address after a few failed logins.
- Install a two-factor plugin too. Two-factor means you need your password and a code from your phone to log in.
- Go to Dashboard and then Updates. Update WordPress, themes and plugins. Old code is a common way in.
- Delete themes and plugins you do not use.
Block the XML-RPC door
xmlrpc.php is an old file that lets other apps talk to WordPress. Bots abuse it to try many passwords in one request. If you do not need it, block it. Open your .htaccess file in the File Manager and add these lines at the bottom. Copy the file first as a backup.
<Files xmlrpc.php>
Order allow,deny
Deny from all
</Files>
This tells the server to refuse every visit to that file.
Slow down DoS traffic
A CDN or firewall service sits in front of your site and filters bad visitors. Cloudflare is a well-known one. Many are free to start. Ask Hostvento support if a firewall is available on your plan.
Also use a caching plugin. Caching saves ready-made pages, so your site works less for each visit and handles more traffic.
Quick recap
- Brute force guesses passwords. DoS floods your site with requests.
- Do not use the username admin. Use strong passwords.
- Limit login tries and turn on two-factor login.
- Keep WordPress, themes and plugins updated.
- Block xmlrpc.php if you do not need it, and consider a firewall service.