Hacker News new | ask | show | jobs
by snowwrestler 3997 days ago
IMO there is no excuse for the lack of login rate limiting in Wordpress core. Drupal has had this for years and it causes no usability problems at all, while making it almost impossible to brute-force an admin session. It just boggles my mind that it takes a plugin to provide this basic protection on WP.