Honeypot sensors
Reconnaissance starts before exploitation. Automated scanners map plugin paths, admin panels and XML-RPC long before anyone tries to break in.
What it does
Places convincing decoys around the site: a login path that is not real, readme files for plugins you do not run and a watched XML-RPC endpoint. Real visitors never encounter them; anything that does has gone looking.
Why WordPress specifically
WordPress paths are identical across sites, so fingerprinting is cheap and automatic. Decoys work because the attacker’s script requests a standard list without knowing which paths are genuine.
What it does not do
It detects and records; it does not block. Use it alongside a firewall, not instead of one.
Who needs it most
Anyone who wants warning while an attacker is still mapping the site, before something breaks.