WordPress Admin Passwords: Stop Using Weak Ones
Why weak WordPress admin passwords still get sites owned, bad-password patterns since 2012, passkeys, application passwords, breach response, and 2FA.
Topics Login & access
Why weak WordPress admin passwords still get sites owned, bad-password patterns since 2012, passkeys, application passwords, breach response, and 2FA.
Topics Login & access
Weak admin passwords are still one of the cheapest ways to lose a WordPress site. Bots do not need a genius plan. They try common passwords and credentials spilled from other breaches.
Attackers automate guesses against wp-login.php and reuse passwords from leaks (credential stuffing). If your admin password is short, common, or reused from email, you are in the easy pile.
Check whether your email appears in known breaches at Have I Been Pwned. That does not prove your WordPress password is safe. It does prove reuse is dangerous.
Security Ninja’s free security tests include password-quality checks for users on the site. Run them from the plugin after install.
The lists below summarize commonly reported weak passwords over the years from public breach research and cleanup work. They are historical patterns, not a new 2024-2026 lab study. The lesson is stable: 123456, password, and keyboard walks never go out of style for bots.
password, 123456, 12345678, abc123, qwerty, monkey, letmein, dragon, 111111, baseball
123456, password, 12345678, qwerty, abc123, 123456789, 111111, 1234567, iloveyou, adobe123
123456, password, 12345, 12345678, qwerty, 1234567890, 1234, baseball, dragon, football
123456 and password stayed on top. Frequent companions: qwerty, 12345678, 123456789, football, letmein, iloveyou.
Still dominated by short numerics. Odd one-offs like test1 or zinch show up in some yearly dumps, but the boring defaults remain the volume winners.
123456, 123456789, password, qwerty, 111111, 123123, plus language-specific favorites (for example senha in some datasets).
password, 123456, guest, qwerty, letmein, Password1, abc123. Slightly “clever” variants (a1b2c3, Password1) still fail against stuffing lists.
You do not need a longer hall of shame. If a human can remember it without a manager, a bot can often try it.
Stuffing is why reusing your email password on WordPress is especially bad. One unrelated breach becomes an admin login elsewhere. Dictionary: brute force.
passwords.xlsxComplexity theater (one symbol, one uppercase) matters less than length + uniqueness. A 20-character random secret beats Summer2026!.
WordPress Application Passwords let REST clients authenticate without typing your main admin password into a script. Use them for:
Rules:
Human admins should still use 2FA on their own accounts. More: REST and API security.
Full walkthrough: WordPress login security guide. Day-to-day habits: password management tips.
If Have I Been Pwned, your host, or a client reports a leaked password:
Do not “just change the password” on a compromised site and stop there. Attackers often leave backdoors when they had admin access.
Security Ninja includes security tests that flag weak password habits and related login risks. Pro adds stronger login limits, 2FA, firewall, and scanning so a guessed password is not the whole story.
admin if you can avoid itIf you already suspect a compromise, rotate passwords from a clean device and follow malware removal or hire cleanup.
Found this useful? Share it.
Bots still hammer 123456, password, qwerty, and keyboard walks. Slightly clever variants like Password1 fail too. Length and uniqueness beat memorable patterns.
Yes for automation and integrations that need REST access. Create a dedicated user with minimum role, issue an application password per tool, and revoke when the tool is removed. Do not share the main admin password.
Change the WordPress password from a clean device, enable 2FA, review admin users, scan for malware if login was reused elsewhere, and check failed-login logs for stuffing attempts.