I do get why you don’t want to add Google Recaptcha, but when i login to this forum it is always the same code i need to enter ‘Xcode777’, so that is not safe at all, bots will find this out.
The custom login page will not provide security for real hackers. But i don’t know how to do it, so i can access every login page if it’s the default ‘wp-admin’ and try some passwords. So it will give some security.
The 2fac authentication will provide a lot of security. All the big security plugins has this feature.
Also: is there a function when someone tries to many times to login, it will be banned untill the admin gives access back, like AIO security has?
I want to come over from AIO.