Linux 软件免费装
Banner图

DadsFam Login Security

开发者 dadsfam
更新时间 2026年10月3日 22:46
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security login brute force limit login attempts lockout

下载

1.7.1 2.0.0 2.2.0 2.6.1 2.6.2 2.8.0 2.9.0 3.0.1

详情介绍:

DadsFam Login Security protects the most-attacked part of your WordPress site — the login form — without making you read a manual or fiddle with servers. Most login plugins count wrong passwords and lock out whoever hits the number. That works on bots, and it also locks out your customer who mistyped twice on the same office connection a bot happens to be using. Version 2.0 gives the plugin its own Brain, running entirely on your site, so it can tell the two apart. The Brain (free, and it never phones home) Everything else you get (free) Privacy Everything the Brain knows stays in your WordPress database. Nothing is sent to DadsFam, to an AI company or to any other service — the free plugin makes no outside requests at all. It stores, per person, the browsers they have signed in with (as a random token matched by a scrambled fingerprint) and the networks they use (as one-way fingerprints that cannot be turned back into addresses). A recognised browser gets one first-party cookie, dfls_tb, which only your site can read. The activity log keeps the address, username and browser name of each attempt for 30 days by default. Uninstalling the plugin removes all of it. Pro features (DadsFam Login Security Pro add-on) Two-factor codes, a smart sign-in check that asks for an email code when a sign-in looks unusual to the Brain, a CAPTCHA, a hidden login address, breached-password checks, country blocking, sessions control and a full audit trail. A word about PRO Right, let me be straight with you, because I hate being sold to as much as you do. Everything above is free and it stays free. The lockouts, the allow and deny lists, the activity log, the live dashboard, the email alerts, the bot traps and the hardening — none of those are premium features. Those are the things a login-security plugin should just do, and if I put them behind a paywall I would be taking the mickey. There is a PRO add-on. It exists because I am a dad in Cape Town, and this is one of the things that puts food on the table at my house. That is the honest reason. Not "unlock your potential", not "supercharge your workflow". Just: if this plugin kept the bots off your login page and you can spare it, PRO helps me keep building. What PRO adds is the second layer you reach for once the door is already locked — two-factor codes, a CAPTCHA, a hidden login address, breached-password checks, country blocking. That is extra security and convenience. It is not the plugin working properly, because the plugin already works properly. So if the free one does everything you need, brilliant. Genuinely. Use it, and I hope your activity log stays boring. If you get to the point where a second factor or a hidden login would let you sleep better, PRO is at plugins.dadsfam.co.za. Either way, thanks for using something I built. — Zak, DadsFam

安装:

  1. Upload the plugin through Plugins → Add New → Upload Plugin, or search for "DadsFam Login Security".
  2. Activate it. Protection starts straight away with safe defaults, and the Brain starts learning from your next sign-in (it also reads your existing activity log if you are updating).
  3. Open Login Security in the admin menu and click Never lock me out.

屏幕截图:

  • The Brain: what it decided and why, the clues it weighs, the Autopilot and self-repair.
  • The activity log with the Brain's verdict on every attempt.
  • Settings, with the Brain's switches and plain-English explanations.
  • Ask the Brain: plain-English questions, answered from your own site with numbers, a chart and the fix as one button.
  • The Brain on the WordPress dashboard: ask a question without leaving it.
  • Ask the Brain in Afrikaans — how many attacks this month, why an account is locked out, unlock it — and it answers in Afrikaans, with the numbers and the fix.

升级注意事项:

3.0.1 The Brain no longer mistakes an attacker for the account owner, and blocks slow unscored guessing by itself. 3.0.0 The self-learning Brain: it learns how you ask things, and blocks slow password guessing by itself (with Undo). 2.9.0 The Brain now tells you what it noticed by itself, and can show how it knows. 2.8.0 The Brain now tells you how it went after you helped someone, and a "Needs a hand" card shows who is stuck signing in. 2.7.0 Ask the Brain "Why can't Rene sign in?" - one person's sign-in trouble explained in a sentence, with the fix. 2.6.2 Closes a gap that let bots find the admin username through /?author=1 and author pages on sites with normal web addresses. 2.6.1 Wording fix: "1 address", not "1 addresses" - everywhere the Brain and the screens count things. 2.6.0 The Brain now understands questions by their meaning, and asks "Is it one of these?" when it is not sure. Still private: it all runs on your site. 2.5.0 The Brain understands far more everyday questions, including "did someone get into my account?", and its typo-fixer no longer misreads real words. 2.4.0 Security release: closes six ways attackers could get extra guesses, flood reset emails or find out which accounts exist. Update straight away. 2.3.0 The Brain answers in Afrikaans when you ask in Afrikaans, every chat action can be undone, and everything fits a phone screen. 2.2.0 Ask the Brain everywhere: on your dashboards, typo-proof, English and Afrikaans, with memory, numbers and charts. Plus a heat-map, a diary and an optional weekly letter. 2.1.0 Ask the Brain in plain English, a Brain that checks its own work and learns bot usernames by itself, and bots stopped by a CAPTCHA now shown. Everything stays on your site. 2.0.0 Important fix: simply opening the sign-in page no longer counts as a wrong password. Adds the self-learning Brain, Autopilot, unlock by email and self-repair. Everything stays on your site. 1.7.1 Review fixes: no DadsFam branding in the emails your users receive, and the plugin homepage link is fixed. 1.7.0 Find any setting with the new search box, and a save bar that shows when something has changed.

常见问题:

How does the Brain understand what I mean?

It listens for ideas, not just exact words. It has a small thesaurus ("burglars", "culprits" and "baddies" all mean attackers), example questions for every topic, and a table of word meanings worked out from GloVe word vectors (Stanford NLP, public domain). All three are plain text files in the plugin's data folder, and it all runs on your site - nothing is sent anywhere. Understanding by meaning only ever picks what to show you; anything that changes something still needs exact words and your click.

Does the Brain send my data to an AI company?

No. It is not a connection to ChatGPT, Claude or anything else. It is a small learning engine written into the plugin, and it runs on your own server. Ask the Brain works the same way: it understands your question with its own language engine and answers from your site's data. Nothing leaves your site.

Will this lock me out of my own site?

It is built not to. Add yourself to the allow list with the Never lock me out button, and once you have signed in once your browser is recognised and cannot be locked out by its address. If you are ever stuck, use the "Email me an unlock link" link on the lockout message, or add define( 'DFLS_DISABLE_LOCKOUTS', true ); to wp-config.php, sign in, and remove the line again.

Can the Brain lock out a real person by mistake?

It is designed so it cannot. It only acts alone when it is almost certain and at least two hard clues agree — things a real browser in a person's hands does not do, like having no browser name at all. Recognised browsers and the networks your people use are excluded from that entirely.

Does it work behind Cloudflare or a load balancer?

Yes. Choose Cloudflare or Another proxy or load balancer under Settings → Where visitors' addresses come from, and it reads the real visitor address — only when the request really came through your proxy, so the header cannot be faked. Self-repair switches Cloudflare on for you when it detects Cloudflare.

Is it compatible with WooCommerce login forms?

Yes. The shop's account page is protected the same way as wp-login.php.

Will disabling XML-RPC break anything?

Only apps that still use XML-RPC, such as the old WordPress mobile app or some remote publishing tools. It is off by default.

更新日志:

3.0.1 Found on a live site: the Brain must never mistake an attacker for the account's owner. 3.0.0 The self-learning Brain. 2.9.0 The Brain notices things. 2.8.0 The Brain closes the loop. 2.7.0 The Brain helps one person sign in. 2.6.2 Usernames stay hidden. 2.6.1 2.6.0 The Brain understands what you mean, not just the words it was taught. 2.5.0 The Brain, attacked on purpose: every change below came from throwing everyday, odd and hostile questions at it until it answered them all. 2.4.0 Security release — every fix below was proven with a real attack against a test site. 2.3.0 2.2.0 2.1.0 2.0.0 1.7.1 1.7.0 1.6.1