  1. These attacks are definitely still hammering a lot of WordPress installations.

    As well as “admin”, I’ve also seen them trying usernames based on the domain name, e.g. trying to log in as “example” if the site’s called “”, so you may want to avoid those names, too.

