Limit Login Attempts
Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.
The facts
- Rating
- 4.6★ from 202
- Active installs
- 300k+
- Price
- Free
- Last updated
- 4 Apr 2023
- Added
- Jan 2009
- Requires WP
- 2.8
- Tested up to
- WP 6.2.11
- Downloads
- 2,300,782
Our analysis
AI-assistedLimit Login Attempts is a WordPress plugin designed to enhance security by restricting the number of login attempts from a single IP address. It helps prevent brute-force attacks by blocking further login attempts after a specified limit is reached. The plugin is customizable, allowing you to set the number of retries and includes features like user notifications and optional logging.
This plugin is suitable for WordPress site owners looking to improve their login security. It is particularly useful for those concerned about unauthorized access and who want to protect their site from potential attacks.
Best for: WordPress site owners seeking to improve login security.
What it does well
- ✓Limits login attempts to enhance security
- ✓Customizable retry limits for each IP address
- ✓Informs users about remaining retries or lockout time
- ✓Optional logging and email notifications
- ✓Compatible with servers behind reverse proxies
Where it falls short
- •No advanced features beyond basic login attempt limitation
- •Whitelisting IPs is possible but not recommended
Verdict
Limit Login Attempts offers a straightforward solution for enhancing login security on WordPress sites. It is effective for users who want to mitigate the risk of brute-force attacks.
From the developer
Automattic's own description of Limit Login Attempts, lightly tidied.
Limit the number of login attempts possible both through normal login as well as using auth cookies.
By default WordPress allows unlimited login attempts either through the login page or by sending special cookies. This allows passwords (or hashes) to be brute-force cracked with relative ease.
Limit Login Attempts blocks an Internet address from making further attempts after a specified limit on retries is reached, making a brute-force attack difficult or impossible.
Features
- Limit the number of retry attempts when logging in (for each IP). Fully customizable
- Limit the number of attempts to log in using auth cookies in same way
- Informs user about remaining retries or lockout time on login page
- Optional logging, optional email notification
- Handles server behind reverse proxy
- It is possible to whitelist IPs using a filter. But you probably shouldn’t. 🙂
Translations: Bulgarian, Brazilian Portuguese, Catalan, Chinese (Traditional), Czech, Dutch, Finnish, French, German, Hungarian, Norwegian, Persian, Romanian, Russian, Spanish, Swedish, Turkish
Plugin uses standard actions and filters only.