WordPress installations face several attack vectors that are unique to the platform. The XML-RPC endpoint (xmlrpc.php) is frequently exploited for DDoS amplification, where attackers use the pingback feature to generate floods of requests from WordPress sites to a target. If your site is both the source and the target, the impact is doubled.
The wp-login.php page is targeted by brute-force attacks that serve a dual purpose: attempting to guess admin credentials while simultaneously consuming server resources. Thousands of login attempts per second can bring a WordPress site to its knees, especially if security plugins add database queries to each authentication attempt.
WordPress's dynamic nature makes it particularly vulnerable to application-layer DDoS. Every page request typically triggers multiple PHP processes and database queries. An HTTP flood that would barely impact a static site can overwhelm a WordPress installation by exhausting PHP workers and database connections. Our protection addresses all of these WordPress-specific vectors.