WordPress Security Plugins

Wordfence Installation and Configuration

Settings
Learning Mode: Enabled and Protecting
Brute Force Protection:
Lock out after how many login failures: 3 – 5
Lock out after how many forget password attemps: 3-5
Count failures over what time period : 4 hours
Amount of time a user is locked out: 4 hours
Immediately lock out invalid usernames

How should we treat Google’s crawlers: Verified Google crawlers will not be blocked
If anyone’s requests exceed: 240 per minute
If a crawler’s page views exceed: 120 per minute
If a crawler’s pages not found (404s) exceed: 60 per minute
If a human’s page views exceed: 120 per minute
If a human’s pages not found (404s) exceed: 120 per minute
How long is an IP address blocked when it breaks a rule: 5 minutes