Really? I believe that the developer of the theme doesn’t follow WordPress coding standards. Besides, legitimate users will not directly visit wp-admin or wp-login.php if you use custom login and provide them with right URLs. Visitors of those pages are bots or hackers.
Yes, I think so. I’ve created custom wp dashboard login page with this plugin and custom frontend login with membership plugin for members. If someone try to access wp-admin or wp-login they must be hackers, bots or haters.
B.T.W I believe in WP Cerber plugin will fix it someday.