How to
How to

How to catch bots and robots with a list of prohibited logins

Cerber uses the list of prohibited usernames to reinforce protection by catching bots and hackers


As you already know, there is small, but very useful feature that called a list of prohibited logins/usernames. It’s a comma-separated list of usernames you do not want to be used on your website in any circumstances. That’s it? No, there is no “just in case” feature in the WP Cerber plugin. But how does Cerber use logins from the list to reinforce protection? First of all, the Cerber plugin does the following.

  • Login or registration with a prohibited username is not allowed.
  • Attempt to log in with prohibited username will be denied and an IP address will be blocked.

Most importantly, combining the list of prohibited logins and the Custom login URL together you help your Cerber is being smart and to detect and catch bots/robots/hackers easily.

If your list is still empty, you definitely have to put on that list the following (commonly used by bots and hackers) usernames: admin, administrator, manager, editor, user, demo, test.

Read more how to create another trap with the Custom login URL.

Last posts from WordPress security blog


I'm a team lead in Cerber Tech. I'm a software & database architect, WordPress - PHP - SQL - JavaScript developer. I started coding in 1993 on IBM System/370 (yeah, that was amazing days) and today software engineering at Cerber Tech is how I make my living. I've taught to have high standards for myself as well as using them in developing software solutions.

View Comments
There are currently no comments.