WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by joho68 v1.3.0

Fail2WP

Security plugin for WordPress with support for fail2ban. Tested with WordPress 5.5+ and PHP 7.4-8.4

Fail2WP

The facts

Rating
5★ from 2
Active installs
100+
Price
Free
Last updated
24 Jun 2026
Added
Feb 2021
Requires WP
5.4.0
Tested up to
WP 7.0.4
Requires PHP
7.4
Downloads
4,255

Our analysis

AI-assisted

Fail2WP is a WordPress plugin designed to enhance security by integrating with fail2ban, although it can function independently. It offers various features to strengthen login security, such as requiring email addresses for login, blocking specific usernames, and limiting login attempts based on IP addresses. The plugin also provides options to disable certain functionalities within WordPress, such as REST API access and RSS feeds.

This plugin is suitable for WordPress site owners looking to improve their site's security measures without needing extensive technical knowledge. It is particularly beneficial for those who want to manage user registrations and logins more securely while monitoring account changes.

Best for: WordPress site owners looking for enhanced security features.

What it does well

  • Integrates with fail2ban for dynamic IP blocking
  • Disables login with usernames, requiring email addresses
  • Allows/denies login from specific IP addresses or hostnames
  • Prevents user enumeration and provides less detailed error messages
  • No tracking code or user data storage

Where it falls short

  • Limited feature details provided
  • Commercial support available but not included in the plugin

Verdict

Fail2WP offers a range of security functionalities suitable for improving login and registration processes. It is a practical choice for those focused on safeguarding their WordPress sites.

From the developer

joho68's own description of Fail2WP, lightly tidied.

This WordPress plugin provides security functionality and integration with fail2ban.

It does not require fail2ban to function.

Basic security functionality includes:

  • Disabling login with username (require e-mail address)
  • Allow/Deny login from IP address, hostname (including wildcard support)
  • Preventing user enumeration (?author=nnn)
  • Less detailed error messages on login failures
  • Minimum username length
  • Blocking specific usernames from being used to register new users
  • Requiring e-mail address matching for new user registrations
  • Warning about new user role setting
  • Blocking of portions or all of WordPress REST API
  • Disabling of RSS and Atom feeds
  • Removal of “Generator” information from HTML and feeds
  • Detection of Cloudflare IP addresses for logging of actual IP addresses
  • Blocking/Allowing logins from IP addresses, IP ranges, and/or hostnames
  • Partially or fully disable XMLRPC access
  • Monitoring administrator accounts for unexpected role/account changes

The plugin also plays nicely with Fail2ban, which is an advanced way of blocking IP addresses dynamically upon suspicious behavior.

Other notes:

  • This plugin may work with earlier versions of WordPress
  • This plugin has been tested with WordPress 5.5-7.0.x at the time of this writing
  • This plugin has been tested with PHP 7.4, 8.1, 8.2, and 8.3 at the time of this writing
  • Local syntax/runtime compatibility checks have also been run on PHP 8.4
  • This plugin optionally makes use of mb_ PHP functions
  • This plugin may create entries in your PHP error log (if active)
  • This plugin contains no Javascript
  • This plugin contains no tracking code and does not store any information about users

Credits

The Fail2WP Plugin was written by Joaquim Homrighausen while converting caffeine into code.

Fail2WP is sponsored by WebbPlatsen i Sverige AB, Sweden.

Copyright 2020-2026 Joaquim Homrighausen; all rights reserved.

Commercial support and customizations for this plugin is available from WebbPlatsen i Sverige AB in Sweden.

If you find this plugin useful, the author is happy to receive a donation, good review, or just a kind word.

If there is something you feel to be missing from this plugin, or if you have found a problem with the code or a feature, please do not hesitate to reach out to support@webbplatsen.se.

This plugin can also be downloaded from code.webbplatsen.net and GitHub

More detailed documentation is available at code.webbplatsen.net/documentation/fail2wp/

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)