WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Faison v0.6.1

Project Force Field

Save your WordPress sites and servers from certain death during brute force attacks with Project Force Field by Orion Group!

Project Force Field

The facts

Rating
4.6★ from 16
Active installs
20+
Price
Free
Last updated
13 May 2014
Added
Apr 2014
Requires WP
3.8
Tested up to
WP 3.9.40
Downloads
3,618

Our analysis

AI-assisted

Project Force Field is a WordPress plugin designed to protect your site from brute force attacks. It works by sending a 403 error code to anyone trying to access the login page after a set number of failed login attempts, thereby preventing attackers from accessing your WordPress files and database.

The plugin also allows you to change the default login URL and automatically alters it during an attack. It aims to stop user enumeration exploits, enhancing overall security for WordPress sites, particularly those vulnerable to brute force methods.

Best for: This plugin suits WordPress site owners looking for enhanced security against brute force attacks.

What it does well

  • Provides protection against brute force attacks
  • Sends 403 error codes to deter attackers
  • Automatically changes login URL during attacks
  • Allows custom login URL definition
  • Stops WordPress user enumeration exploits

Where it falls short

  • Multisite support is not currently available
  • Login failure threshold cannot be adjusted yet
  • Email notifications for brute force events are not implemented

Verdict

Project Force Field offers specific security features for WordPress, but some planned functionalities are still pending. It may be useful for sites needing basic brute force protection.

From the developer

Faison's own description of Project Force Field, lightly tidied.

Faison Zutavern, Jon Valcq, and Emma Edgar, from Orion Group LLC, bring superior Brute Force Attack protection to WordPress with their new plugin, Project Force Field. By tracking failed login attempts and taking advantage of Apache’s mod_rewrite module, Project Force Field stops Brute Force Attacks from bogging down your sites and servers.

Special thanks to Chris Aykroid for the plugin banner 😀

Contributing

If you would like to contribute or fork Project Force Field, we currently have a repo on Bitbucket. You can find it here

Features!

  • Sends a 403 error code to anyone visiting /wp-login.php – All brute force attacks we’ve seen target /wp-login.php. By responding with a 403 error, your WordPress files aren’t loaded, the Database isn’t queried, and the attacker doesn’t figure out your password.
  • Changes the default login url – While a so-called hacker is being deflected by your new Force Field, you will log in with ease at /wp-admin/. When you do that, WordPress will redirect you to the new, proper login url.
  • Automatically changes the login when a Brute Force Attack is detected – When too many login failures occur within a minute, Project Force Field shifts polarity! The new login you previously used now responds with a 403 error, and a large random number is now used as your login url! After some time, the login will return back to normal.
  • Unlimited polarity shifts – If a Brute Force Attacker gets smart and writes a script to check for the new login url, Project Force Field will continue to detect the attack and change the login.
  • Define the login yourself – By defining OGFF_LOGIN in your wp-config.php, you can set the login to be almost anything you want.
  • Stops WordPress User Enumeration Exploit – Many brute force attacks use the WordPress User Enumeration exploit to easily figure out valid usernames. We stop that to protect your site, and respond with a 403 to save your server.

Future Features!

  • Multisite Support – It’s not there yet, that’s pretty lame, so I’m going to fix that before anything else!
  • Adjust the login failure threshold – Currently, Project Force Field assumes a brute force is underway when there have been 30 login failures within a minute. This might not be ideal for large websites, so we want to let you increase that amount to 300 if needed.
  • Add optional email notification for brute force events – If you want to know when your website is under attack, we want to let you know. In a near future version, we will let you add email addresses to be notified of brute force attacks, and any other important related events that we add in the future.
  • Add last resort .htaccess password lockdown – If a so-called hacker writes a script that continues to learn the new login url, Project Force Field won’t help much. In an upcoming version, we will check to see how many times the login url was changed, determine if the Brute Force Attack is smart, and lockdown the login with an .htaccess password.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)