Limit the number of login attempts possible both through normal login as well as using auth cookies.
By default WordPress allows unlimited login attempts either through the login page or by sending special cookies. This allows passwords (or hashes) to be brute-force cracked with relative ease.
Limit Login Attempts blocks an Internet address from making further attempts after a specified limit on retries is reached, making a brute-force attack difficult or impossible.
The plugin is simple to install:
- Download the file
wp-limit-failed-login-attempts.zip.
- Unzip it.
- Upload
wp-limit-failed-login-attempts directory to your /wp-content/plugins directory.
- Go to the plugin management page and enable the plugin.
- Configure the options from the
Limit Failed Login page
5.6
Security Bug fixing - part 2
5.5
Security Bug fixing
5.4
Security Bug fixing
5.3
Bug fixing in log report
5.2
Checking with wordpress version 6.2
5.1
- Bug fixing in lockout (locked accounts) report (security issiu reported by WPScan)
4.9.1
- Bug fixing in log report (security issiu reported by WPScan) - part 3
4.9
- Bug fixing in log report (security issiu reported by WPScan) - part 2
4.8
- Bug fixing in log report (security issiu reported by WPScan)
4.7
- Bug fixing in dashboard & email reports
4.6
- Bug fixing - Use local flags instead of using third party website
4.5
- Bug fixing - Remote get issue
4.4
- Bug fixing - PHP notice message
4.3
- Bug fixing in login attempts counter
4.2
- Bug fixing in email alerts
4.1
- Bug fixing in email alerts
4.1
- Adding statistics page & new statistics widgets
- Adding a new feature: Block by IP and Range IP
- Bug fixing and enhancements
2.8
2.7
- Compatibility with SMPT plugins
2.6
- bug fixing in attempts count
- bug fixing in email alerts
2.5
- Bug fixing in a timezone
- Bug fixing in the lockout timer
2.4
- Bug fixing in recording attempts
2.3
- Bug fixing in the email alerts
2.2
- improvements in reports
- improvements in dashboard widgets
2.1
- hot fixes in the wp-buy cp page
1.9
1.8
- Add one starting page for all of our plugins
- Add links to dismiss the new start page links
1.7
- Adding new feature (IP blocking)
- Adding new feature (search by IP, country, username)
- Adding new feature (show username and password in the log reports)
1.6
- Bug fixing - PHP Notice -> Undefined index
1.5
- Adding username and user role to the log
- Adding search by username, IP, role, country
1.4
- Email template improvements
1.3
- Display GEO location in detail for any blocked IP address
1.2
- Bug fixing in the user permissions
- adding "Vote" message
1.1
1.0