On WordPress, there are two main potential vectors of bruteforce intrusion * http my-site com wp-login php.
This plugin adds one in front of your login page, and by the way you can also XML-RPC with simple checkbox if you don't need it ..
The idea is simple you choose pair of words, and when you want to access your login page, you just have to provide them in URL like this http my-site com wp-login php word1=word2.
If you try to access your login page without this pair of words, you get message, where you can insult the attacker as much as you want
Read more