Linux 软件免费装
Banner图

Limit Login Attempts Security - Login Security, 2FA, Firewall, Brute Force Prevention

开发者 wpchefgadget
nikitaglobal
更新时间 2026年5月19日 21:32
捐献地址: 去捐款
PHP版本: 5.0 及以上
WordPress版本: 7.0
版权: GPLv2 or later

标签

security 2FA login security firewall brute force

下载

2.11.0 2.12.3 2.23.0 2.5.0 2.6.2 2.6.3 2.7.0 2.7.1 2.7.2 2.7.4 2.8.0 2.8.1 2.9.0 2.25.8 2.26.1 2.26.14 2.26.18 2.25.0 3.2.2 2.26.27 2.16.0 2.22.0 2.23.1 2.25.2 2.12.2 2.26.7 2.25.4 2.25.5 2.25.13 2.25.14 2.25.7 2.25.9 2.25.26 2.15.2 2.17.2 2.26.21 2.17.1 2.18.0 2.20.0 2.20.5 2.23.2 2.25.11 2.25.21 2.25.23 2.25.24 2.25.22 2.25.25 2.13.0 2.17.0 2.21.0 2.25.1 2.25.18 2.25.3 2.25.12 2.25.16 2.25.20 2.26.26 2.19.0 2.19.1 2.19.2 2.26.2 2.26.4 2.26.5 2.26.8 2.26.12 2.26.13 2.26.6 2.1.0 2.12.1 2.2.0 2.20.1 2.22.1 2.25.27 2.26.16 2.26.17 2.26.9 2.20.6 2.25.6 2.26.23 2.26.24 2.20.2 2.10.0 2.12.0 2.14.0 2.17.3 2.20.3 2.17.4 2.21.1 2.24.0 2.24.1 2.25.10 2.25.17 2.25.19 2.25.29 2.26.10 2.26.15 2.26.19 2.26.22 2.26.28 2.3.0 2.15.0 2.20.4 2.25.15 2.4.0 3.1.0 2.26.20 2.26.25 2.7.3 3.0.0 2.15.1 3.0.1 2.6.1 3.0.2 2.25.28 2.26.0 2.26.11 2.26.3 3.2.0 3.2.1 3.2.3 2.0.0 2.10.1 3.2.4

详情介绍:

Protect your WordPress website against brute force attacks, bot attacks, and unauthorized login attempts with one of the most trusted login security plugins for WordPress. Limit Login Attempts Security strengthens your WordPress login security by limiting failed login attempts, blocking malicious IPs, securing wp-login.php, protecting XML-RPC, and adding powerful firewall and 2FA protection without slowing down your website. Trusted by 2 million WordPress websites, Limit Login Attempts Security is designed specifically to protect the most targeted part of your website: the login page. https://www.youtube.com/watch?v=dX7Qu5MN2ok Why Use Limit Login Attempts Security? By default, WordPress allows unlimited login attempts. This creates a major security vulnerability where bots and attackers can repeatedly guess usernames and passwords until they gain access. This is especially important in the age of AI, where attackers now have access to faster and more sophisticated tools than ever before. Limit Login Attempts Security helps stop: The plugin automatically blocks excessive login attempts and locks out suspicious IP addresses and usernames before attackers can gain access. Features Included in the Free Version Login Security & Brute Force Protection 2FA / Multi-Factor Authentication (MFA) Firewall & Bot Protection WooCommerce & Plugin Compatibility Protects: Compatible With: Login Monitoring & Notifications Access Controls Premium Features (Start Your Free 14 Day Trial) Upgrade to Limit Login Attempts Security Premium to extend protection with cloud-based login security and advanced attack prevention. Advanced Cloud Protection Enhanced Performance Protection Advanced Security Features Multi-Site & Team Features Premium Support Lightweight Security Built for WordPress Unlike many large security suites, Limit Login Attempts Security focuses specifically on login security and brute force protection. This means: Protect More Than Just wp-login.php Limit Login Attempts Security secures: Trusted by Millions of WordPress Websites Limit Login Attempts Security is one of the most widely used WordPress login security plugins and has helped protect millions of websites from brute force attacks and malicious login activity. Whether you run: Limit Login Attempts Security helps secure your login experience with modern WordPress login protection. Upgrading from the Original Limit Login Attempts Plugin? Switching is easy:
  1. Remove the old Limit Login Attempts plugin
  2. Install Limit Login Attempts Security
  3. Your settings will remain intact
Translation Support Currently translated into multiple languages including: Secure Your WordPress Login Today Install Limit Login Attempts Security and protect your WordPress website with: Without slowing down your website.

常见问题:

What do I do if all users get blocked?

If you are using contemporary hosting, it's likely your site uses a proxy domain service like CloudFlare, Sucuri, Nginx, etc. They replace your user's IP address with their own. If the server where your site runs is not configured properly (this happens a lot) all users will get the same IP address. This also applies to bots and hackers. Therefore, locking one user will lead to locking everybody else out. If the plugin is not using our Cloud App, this can be adjusted using the Trusted IP Origin setting. The cloud service intelligently recognizes the non-standard IP origins and handles them correctly, even if your hosting provider does not.

How do I know if I'm under attack?

An easy way to check if the attack is legitimate is to copy the IP address from the lockout notification and check its location using a IP locator tool. If the location is not somewhere you recognize and you have received several failed login attempts, then you are likely being attacked. You might notice dozens or hundreds of IPs each day. Visit our website to learn how can you prevent brute force attacks on your website.

How can I tell that the premium plugin is working?

After you upgrade to our premium version, you will see a new dashboard in your WordPress admin that shows all attacks that will now relay through our cloud service. On the graph, you'll see requests and failed login attempts. Each request will represent the cloud app validating an IP, which also includes denied logins. In some cases, you may notice an increase in speed and efficiency with your website. Also, a reduction in lockout notifications via email.

Could these failed login attempts be fake?

Some users find it hard to believe that they could experience numerous unsuccessful login attempts, particularly when their site has just been established or has minimal human traffic. The plugin is not responsible for generating these failed login attempts. Newly created websites are frequently hosted on shared IP addresses, making it easy for hackers to discover them. Additionally, newly registered domain names are often crawled soon after creation, rendering a WordPress website susceptible to attacks. Such websites are attractive targets as security is not a primary concern for their owners. We've created an article that delves deeper into the issue of fake login attempts in WordPress.

What happens if my site exceeds the request limits in the plan?

The premium plan’s resource limits start from 100,000 requests per month, which should accept almost any heavy brute-force attack. We monitor all of our sites and will alert the user if it appears they are going over their limits. If limits are reached, we will suggest to the user upgrading to the next plan. If you are using the free version, the load caused by brute force attacks will be absorbed by your current hosting bandwidth, which could cause your hosting costs to increase.

What URLs are being attacked and protected?

The URLs being protected are your login page (wp-login.php, wp-admin), xmlrpc.php, WooCommerce login page, and any custom login page you have that uses regular WordPress login hooks.

Why is Limit Login Attempts Security more popular than other brute-force protection plugins?

Our main focus is protecting your site from brute force attacks. This allows our plugin to be very lean and effective. It doesn’t require a lot of your web hosting resources and keeps your site well-protected. More importantly, it does all of this automatically as our service learns on its own about each IP it encounters. In contrast, a firewall would require manual blocking of IPs.

What to do when an admin gets blocked?

Open the site from another IP. You can do this from your cell phone, or using Opera browser and enabling free VPN there. You can also try turning off your router for a few minutes and then see if you get a different IP address. These will work if your hosting server is configured correctly. If that doesn’t work, connect to the site using FTP or your hosting control panel file manager. Navigate to wp-content/plugins/ and rename the limit-login-attempts-reloaded folder. Log in to the site then rename that folder back and whitelist your IP. By upgrading to our premium app, you will have the unlocking functionality right from the cloud so you’ll never have to deal with this issue.

What settings should I use In the plugin?

The settings are explained within the plugin in great detail. If you are unsure, use the default settings as they are the recommended ones.

Can I share the safelist/denylist throughout all of my sites?

By default, you will need to copy and paste the lists to each site manually. For the premium service, sites are grouped within the same private cloud account. Each site within that group can be configured if it shares its lockouts and access lists with other group members. The setting is located in the plugin's interface. The default options are recommended.

更新日志:

3.2.4 3.2.3 3.2.2 3.2.1 3.2.0 3.1.0 3.0.2 3.0.1 Earlier versions For the changelog of earlier versions, please refer to the changelog.txt file.