WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Automattic v1.7.2

Limit Login Attempts

Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.

Limit Login Attempts

The facts

Rating
4.6★ from 202
Active installs
300k+
Price
Free
Last updated
4 Apr 2023
Added
Jan 2009
Requires WP
2.8
Tested up to
WP 6.2.11
Downloads
2,300,782

Our analysis

AI-assisted

Limit Login Attempts is a WordPress plugin designed to enhance security by restricting the number of login attempts from a single IP address. It helps prevent brute-force attacks by blocking further login attempts after a specified limit is reached. The plugin is customizable, allowing you to set the number of retries and includes features like user notifications and optional logging.

This plugin is suitable for WordPress site owners looking to improve their login security. It is particularly useful for those concerned about unauthorized access and who want to protect their site from potential attacks.

Best for: WordPress site owners seeking to improve login security.

What it does well

  • Limits login attempts to enhance security
  • Customizable retry limits for each IP address
  • Informs users about remaining retries or lockout time
  • Optional logging and email notifications
  • Compatible with servers behind reverse proxies

Where it falls short

  • No advanced features beyond basic login attempt limitation
  • Whitelisting IPs is possible but not recommended

Verdict

Limit Login Attempts offers a straightforward solution for enhancing login security on WordPress sites. It is effective for users who want to mitigate the risk of brute-force attacks.

From the developer

Automattic's own description of Limit Login Attempts, lightly tidied.

Limit the number of login attempts possible both through normal login as well as using auth cookies.

By default WordPress allows unlimited login attempts either through the login page or by sending special cookies. This allows passwords (or hashes) to be brute-force cracked with relative ease.

Limit Login Attempts blocks an Internet address from making further attempts after a specified limit on retries is reached, making a brute-force attack difficult or impossible.

Features

  • Limit the number of retry attempts when logging in (for each IP). Fully customizable
  • Limit the number of attempts to log in using auth cookies in same way
  • Informs user about remaining retries or lockout time on login page
  • Optional logging, optional email notification
  • Handles server behind reverse proxy
  • It is possible to whitelist IPs using a filter. But you probably shouldn’t. 🙂

Translations: Bulgarian, Brazilian Portuguese, Catalan, Chinese (Traditional), Czech, Dutch, Finnish, French, German, Hungarian, Norwegian, Persian, Romanian, Russian, Spanish, Swedish, Turkish

Plugin uses standard actions and filters only.

Read the full description on the official page →

Tagged as