To stop providing valuable information to hackers, disable WordPress login hints in login error messages.
Sample WordPress Login Hints
ERROR: Invalid username. Lost your password?
ERROR: Incorrect username or password.
ERROR: The password you entered for kunaldesai is incorrect. Lost your password?
This is what WordPress displays if someone enters wrong username or password.
Hackers use these error messages as hints to guess your WordPress blog’s username, email address or password.
If you want to stop others from guessing and improve privacy, read further.
Disable WordPress Login Hints
It’s not a good habit of putting custom code snippets in functions.php file.
Follow Good Habits and place the below code in WordPress Blog Specific Plugin.
//Disable WordPress Login Hints
function no_login_hints(){
return 'Made in India!';
}
add_filter('login_errors','no_login_hints');
The above code displays “Made in India” whenever someone enters wrong username or password.
You have now secured username, password, email address and ultimately improved privacy.