Not complicated - folks click on the 'www' button below your post to see what you're about. I always get an uptick in visitors when I post, but my site's not protected. Alternately, a robot (connected to a user with an account here) scans the 'www' button URLs and tries to get in.
The app I use is "Limit Login Attempts", I've been using it for about a year now. I was shocked at first to see the amount of attempts. And then, to see an uptick trend when I'm posting here.
If it's exposed on the Internet, the code monkeys will try to gain access.
There are some good articles on the Wordpress site about how to secure your installation. And to help recover if you do get hacked, make regular backups of the files and database.
It's called robots/spiders. This site gets a lot of traffic and therefore a lot of robots/spiders which then go to your site. Just uninstall the plugin, I don't see how it can do anything but annoy you.