Thank’s for your reply. I already found the solution.
Here some of my concern:
-Hacker know our main username is ‘admin’ (which can’t be deleted)
-Hacker know if we powered by wordpress, our main editing website address is “https://our_domain_name/wp-admin/”
*Now hacker just need to do is to crack password ??
If we able to change the folder name and admin username, it will reduce our risk.
I just hope that wordpress able to solve this issue on their next update.
Thank you for your support. ??