WordPress and Joomla website administrators who want to prevent hackers from accessing the default login page can use a plugin called jSecure Authentication (Joomla version) or wSecure Authentication (WordPress version).
Plugins use a secret code embedded within the URL path to protect the login page. For example, in the case of Joomla websites, the default login URL is https://yourwebsite.com/administrator. When jSecure Authentication is installed, the URL should be followed by a secret code.
The same goes for WordPress websites. The default login URL is https://yourwebsite.com/wp-admin/, but after installing the plugin it can only be accessed with https://yourwebsite.com/wp-admin/?SECRETCODE.
If the secret code is incorrect, the user is redirected to the site's home page.
Both jSecure Authentication and wSecure Authentication are available for free. However, there are commercial versions that come with some additional features.
With commercial versions, administrators can block access to the plugin settings page for other administrators, can block specific IP addresses, log logins, see a graphical representation of login attempts, receive email notifications, and manage files and folders.
You can download jSecure Authentication for Joomla from here and wSecure Authentication, the version for WordPress, is also available for download here.

