Plugin Directory

Limit Login Attempts

Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.

Download Version 1.6.2

Limit the number of login attempts possible both through normal login as well as using auth cookies.

By default WordPress allows unlimited login attempts either through the login page or by sending special cookies. This allows passwords (or hashes) to be brute-force cracked with relative ease.

Limit Login Attempts blocks an Internet address from making further attempts after a specified limit on retries is reached, making a brute-force attack difficult or impossible.

Features

  • Limit the number of retry attempts when logging in (for each IP). Fully customizable
  • Limit the number of attempts to log in using auth cookies in same way
  • Informs user about remaining retries or lockout time on login page
  • Optional logging, optional email notification
  • Handles server behind reverse proxy

Translations: Bulgarian, Brazilian Portuguese, Catalan, Chinese (Traditional), Czech, Dutch, Finnish, French, German, Hungarian, Norwegian, Persian, Romanian, Russian, Spanish, Swedish, Turkish

Plugin uses standard actions and filters only.

Author: johanee

Requires: 2.8 or higher
Compatible up to: 3.2.1
Last Updated: 2011-8-25 Downloads: 110,028

Average Rating

5 stars
4 stars
3 stars
2 stars
1 star
(85 ratings)

Compatibility

+
=
Works!

12 people say it works.
0 people say it's broken.

Log in to vote.

100,1,1 100,1,1
100,4,4 100,2,2
100,1,1
100,1,1 100,1,1
100,1,1
100,9,9
83,6,5 80,5,4 100,2,2 100,1,1
100,2,2 100,8,8 100,3,3 100,1,1
100,1,1
100,2,2
100,6,6 100,1,1
100,1,1 50,2,1
100,6,6 73,11,8
80,5,4
80,5,4
88,8,7
100,3,3
100,5,5 95,20,19
100,7,7
100,12,12