Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Login Delay Shield slows down brute-force attacks by adding a configurable delay to failed login attempts while keeping successful logins instant.
Login Delay Shield is a WordPress plugin designed to enhance security against brute-force attacks by introducing delays after failed login attempts. It allows you to configure fixed or progressive delays, IP lockouts, and other protective measures to deter bots and hackers while ensuring legitimate users are not affected. The plugin also includes features like login feedback, email notifications, and logging of failed attempts, making it suitable for site administrators looking to bolster their login security.
This plugin is particularly useful for those managing WordPress sites that may be targeted by automated attacks. It is free to use and does not include upsells or ads, making it accessible for all users. Its compliance with accessibility standards further ensures that it can be effectively used by a wider range of site administrators.
Best for: Site administrators looking to improve login security on WordPress sites.
What it does well
Where it falls short
Login Delay Shield offers a straightforward approach to securing WordPress logins against brute-force attacks. It is a useful tool for those prioritising site security without the need for paid features.
michael.damoiseau's own description of Login Delay Shield, lightly tidied.
WordPress is one of the most widely used content management systems on the internet, making it a frequent target for bots and hackers attempting brute-force attacks.
A brute-force attack works by systematically trying passwords until finding the correct one. Login Delay Shield defends against this by adding a configurable delay after each failed login attempt. Since successful logins are never delayed, legitimate users experience no slowdown. This approach is particularly effective against bots that send thousands of login requests, as each failed attempt forces the attacker to wait before trying the next password.
Features:
IP only or IP + username to reduce false positives on shared networks/wp-login.phpwldelay_resolve_country_code filter to supply the visitor countryFree means free
Login Delay Shield has no ads, no upsells, no premium tier, and no account or API key requirement. Every admin notice is dismissible, and the plugin never nags you to upgrade — there is nothing to upgrade to.
You can always get back in
A security plugin that locks out its own administrator is worse than no security at all. Login Delay Shield is built so an admin can always recover access:
wp wp-login-delay unlock-ip <ip> and wp wp-login-delay flush-lockoutsThis plugin is not a complete security solution — dedicated security plugins offer more comprehensive protection. However, Login Delay Shield adds an effective layer of defense that works alongside your existing security measures without conflict.
Note: This plugin was formerly known as “WP Login Delay”.
Found a bug or want to suggest an improvement? Open a thread in the support forum on WordPress.org.
Want to help translate the plugin into your language? Visit translate.wordpress.org.
Other plugins for securing a site.
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...