WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by michael.damoiseau v2.6.0

Login Delay Shield

Login Delay Shield slows down brute-force attacks by adding a configurable delay to failed login attempts while keeping successful logins instant.

Login Delay Shield

The facts

Rating
4.4★ from 5
Active installs
60+
Price
Free
Last updated
15 Jul 2026
Added
Aug 2013
Requires WP
3.5.1
Tested up to
WP 7.0.4
Requires PHP
7.4
Downloads
5,499

Our analysis

AI-assisted

Login Delay Shield is a WordPress plugin designed to enhance security against brute-force attacks by introducing delays after failed login attempts. It allows you to configure fixed or progressive delays, IP lockouts, and other protective measures to deter bots and hackers while ensuring legitimate users are not affected. The plugin also includes features like login feedback, email notifications, and logging of failed attempts, making it suitable for site administrators looking to bolster their login security.

This plugin is particularly useful for those managing WordPress sites that may be targeted by automated attacks. It is free to use and does not include upsells or ads, making it accessible for all users. Its compliance with accessibility standards further ensures that it can be effectively used by a wider range of site administrators.

Best for: Site administrators looking to improve login security on WordPress sites.

What it does well

  • Configurable delays after failed login attempts
  • IP lockout feature to block repeated offenders
  • Email notifications for failed login thresholds
  • Accessible admin interface compliant with WCAG 2.1
  • No ads or upsells; completely free

Where it falls short

  • Limited information on user experience or support
  • No details on performance impact or resource usage

Verdict

Login Delay Shield offers a straightforward approach to securing WordPress logins against brute-force attacks. It is a useful tool for those prioritising site security without the need for paid features.

From the developer

michael.damoiseau's own description of Login Delay Shield, lightly tidied.

WordPress is one of the most widely used content management systems on the internet, making it a frequent target for bots and hackers attempting brute-force attacks.

A brute-force attack works by systematically trying passwords until finding the correct one. Login Delay Shield defends against this by adding a configurable delay after each failed login attempt. Since successful logins are never delayed, legitimate users experience no slowdown. This approach is particularly effective against bots that send thousands of login requests, as each failed attempt forces the attacker to wait before trying the next password.

Features:

  • Distributed attack detection — spot credential-stuffing that rotates IPs, which per-IP lockouts miss.
  • Security Setup Wizard — Choose Conservative, Balanced, or Aggressive protection profiles from the settings page
  • Login delay — Fixed or random delay on failed login attempts (1-10 seconds)
  • Progressive delay — Delay increases with each consecutive failed attempt from the same IP
  • IP lockout — Temporarily block IP addresses after too many failed attempts
  • Username-aware lockout strategy — Choose IP only or IP + username to reduce false positives on shared networks
  • Login feedback — Shows remaining attempts before lockout and a lockout countdown when blocked
  • IP whitelist — Bypass all security measures for trusted IPs (supports CIDR notation)
  • Email notifications — Receive alerts when failed login thresholds are reached
  • Failed login log — Track all failed attempts with a dashboard widget showing recent activity, 7-day trends, and top targeted usernames
  • fail2ban logging (optional) — Write fail2ban-compatible failed-login and lockout lines to a safe log file
  • XML-RPC protection — Apply delays to XML-RPC authentication or block it entirely
  • Password reset protection — Apply delays, lockouts, and logging to password reset submissions without revealing account existence
  • Custom login URL — Move the login page to a custom URL to reduce automated bot traffic targeting /wp-login.php
  • Country blocking (optional, developer integration) — Block login authentication from selected country codes. Ships no GeoIP database; requires a resolver hooked to the wldelay_resolve_country_code filter to supply the visitor country
  • Emergency recovery URL (optional) — Generate a secret link that clears the lockout for your own IP, so you can get back in even with no admin, shell, or file access
  • Log retention — Automatic cleanup of old log entries (configurable retention period)
  • Accessible admin interface — WCAG 2.1 compliant with keyboard navigation and screen reader support
  • Multilingual — Translated into 18 languages including French, German, Spanish, Japanese, Chinese, Arabic, and more
  • Lightweight and compatible with other security plugins

Free means free

Login Delay Shield has no ads, no upsells, no premium tier, and no account or API key requirement. Every admin notice is dismissible, and the plugin never nags you to upgrade — there is nothing to upgrade to.

You can always get back in

A security plugin that locks out its own administrator is worse than no security at all. Login Delay Shield is built so an admin can always recover access:

  • Whitelisted IPs (including CIDR ranges) bypass every delay and lockout
  • The Active Lockouts manager on the settings page lists current lockouts with a one-click Unlock for each, plus an “Unlock Current IP” action
  • The optional Emergency Recovery URL — a secret link you save in advance — clears your own IP lockout even when you have no admin, shell, or file access
  • WP-CLI recovery commands: wp wp-login-delay unlock-ip <ip> and wp wp-login-delay flush-lockouts
  • Lockouts are always temporary (24 hours maximum) — there are no permanent bans

This plugin is not a complete security solution — dedicated security plugins offer more comprehensive protection. However, Login Delay Shield adds an effective layer of defense that works alongside your existing security measures without conflict.

Note: This plugin was formerly known as “WP Login Delay”.

Contribute

Found a bug or want to suggest an improvement? Open a thread in the support forum on WordPress.org.

Want to help translate the plugin into your language? Visit translate.wordpress.org.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)