WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Daniel Convissor v0.56.0

Login Security Solution

Security against brute force attacks by tracking IP, name, password; requiring very strong passwords. Idle timeout. Maintenance mode lockdown.

Login Security Solution

The facts

Rating
4.4★ from 54
Active installs
4k+
Price
Free
Last updated
28 Nov 2017
Added
Mar 2012
Requires WP
3.3
Tested up to
WP 4.4.34
Downloads
291,845

Our analysis

AI-assisted

Login Security Solution is a WordPress plugin designed to enhance login security for both multisite and regular WordPress installations. It blocks brute force and dictionary attacks while ensuring that legitimate users can access their accounts without unnecessary hurdles. The plugin monitors login attempts, tracks IP addresses, and implements various measures to slow down attackers, such as increasing response times after multiple failed attempts.

The plugin also features password strength enforcement, customizable password aging, and options for maintenance mode. It notifies administrators of potential breaches and can log out users if suspicious activity is detected. This tool is suitable for website administrators looking to bolster their site's login security without complicating the user experience.

Best for: Website administrators seeking to improve login security for their WordPress sites.

What it does well

  • Blocks brute force and dictionary attacks
  • Tracks IP addresses and login attempts
  • Customizable password strength and aging policies
  • Notifies administrators of attacks
  • Supports multisite installations

Where it falls short

  • Last updated in November 2017
  • Tested up to WordPress 4.4.34
  • Limited information on user experience and support

Verdict

Login Security Solution provides a range of features aimed at enhancing login security, but its age and limited updates may be a concern for some users.

From the developer

Daniel Convissor's own description of Login Security Solution, lightly tidied.

A simple way to lock down login security for multisite and regular
WordPress installations.

  • Blocks brute force and dictionary attacks without inconveniencing
    legitimate users or administrators

    • Tracks IP addresses, usernames, and passwords
    • Monitors logins made by form submissions, XML-RPC requests and
      auth cookies
    • If a login failure uses data matching a past failure, the plugin
      slows down response times. The more failures, the longer the delay.
      This limits attackers ability to effectively probe your site,
      so they’ll give up and go find an easier target.
    • If an account seems breached, the “user” is immediately logged out
      and forced to use WordPress’ password reset utility. This prevents
      any damage from being done and verifies the user’s identity. But
      if the user is coming in from an IP address they have used in the
      past, an email is sent to the user making sure it was them logging in.
      All without intervention by an administrator.
    • Can notify the administrator of attacks and breaches
    • Supports IPv6

    Thoroughly examines and enforces password strength. Includes full
    UTF-8 character set support if PHP’s mbstring extension is enabled.
    The tests have caught every password dictionary entry I’ve tried.

    • Minimum length (customizable)
    • Doesn’t match blog info
    • Doesn’t match user data
    • Must either have numbers, punctuation, upper and lower case characters
      or be very long. Note: alphabets with only one case (e.g. Arabic,
      Hebrew, etc.) are automatically exempted from the upper/lower case
      requirement.
    • Non-sequential codepoints
    • Non-sequential keystrokes (custom sequence files can be added)
    • Not in the password dictionary files you’ve provided (if any)
    • Decodes “leet” speak
    • The password/phrase is not found by the dict dictionary
      program (if available)

    Blocks discovering user names via the “?author=” query string

    Password aging (optional) (not recommended)

    • Users need to change password every x days (customizable)
    • Grace period for picking a new password (customizable)
    • Remembers old passwords (quantity is customizable)

    Administrators can require all users to change their passwords

    • Done via a flag in each user’s database entry
    • No mail is sent, keeping your server off of spam lists

    Logs out idle sessions (optional) (idle time is customizable)

    Maintenance mode (optional)

    • Publicly viewable content remains visible
    • Disables logins by all users, except administrators
    • Logs out existing sessions, except administrators
    • Disables posting of comments
    • Useful for maintenance or emergency reasons
    • This is separate from WordPress’ maintenance mode

    Prevents information disclosures from failed logins

    Improvements Over Similar WordPress Plugins

    • Multisite network support
    • Monitors authentication cookies for bad user names and hashes
    • Tracks logins from XML-RPC requests
    • Adjusts WordPress’ password policy user interfaces
    • Takes security seriously so the plugin itself does not open your site
      to SQL, HTML, or header injection vulnerabilities
    • Notice-free code means no information disclosures if display_errors
      is on and error_reporting includes E_NOTICE
    • Only loads files, actions, and filters needed for enabled options
      and the page’s context
    • Provides an option to have deactivation remove all of this plugin’s
      data from the database
    • Uses WordPress’ features rather than fighting or overriding them
    • No advertising, promotions, or beacons
    • Proper internationalization support
    • Clean, documented code
    • Unit tests covering 100% of the main class
    • Internationalized unit tests

    For reference, the similar plugins include:

    Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)