Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Phantom User Lockout

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Phantom User Lockout

By efraing
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Bots guess usernames like “admin” and “administrator”. On most sites those names don’t exist, so any attempt with them is a bot. Phantom User Lockout records each one and blocks the IP address that made it.

For every attempt with a username that doesn’t exist on your site, you get:

  • The time, in site time with UTC on hover
  • The username and the password that was tried
  • The IP address, shown as IP Blocked, Not blocked or Safe
  • Where the IP is: city, region and country
  • Who owns it: the hosting company or network (for example “AS53667 FranTech Solutions”) and the reverse hostname
  • How the attempt came in: the login form, XML-RPC (every guess inside a system.multicall batch gets its own row), REST API application passwords, or another login form
  • The user agent and the requested URL

Blocking

  • An IP is blocked after its first attempt with a username that doesn’t exist. You can raise that threshold.
  • Blocks are permanent. They only lift when you press Unblock.
  • A blocked visitor gets a 403 page that reads “IP Blocked”.
  • By default a block covers the login page, XML-RPC, REST logins and any other form that logs in through WordPress. You can widen it to the whole site.
  • Optionally, the plugin can also block IPs that enter the wrong password for a real username. This is off by default, and the default threshold is 3 wrong passwords.

Built not to lock you out

  • Real accounts are never recorded unless you turn on the real-account option, and even then their passwords are never stored.
  • If a username is within two letters of a real login or email, it’s treated as a typo by one of your own people. It’s logged with the password hidden and never causes a block.
  • Safe IPs are never recorded or blocked. Add yours with one click: “Add my current IP address to the list”.
  • A signed-in administrator is never blocked. Neither are the server’s own address and loopback.
  • Emergency switch: add define( 'BOTLO_DISABLE', true ); to wp-config.php.

The plugin never edits .htaccess or any other server file.

External services

To show where an IP address is and who owns its network, the plugin looks the address up with ipinfo.io.

  • What is sent: only the IP address that made the login attempt, plus your ipinfo.io token if you entered one in Settings. No information about your site, your users or your visitors is sent.
  • When: once per new IP address, in the background shortly after its first attempt, or when an administrator opens the Phantom User Lockout screen while a lookup is still pending.
  • Turning it off: Settings → Location lookups.
  • ipinfo.io terms of service: https://ipinfo.io/terms-of-service
  • ipinfo.io privacy policy: https://ipinfo.io/privacy-policy

Privacy

The plugin stores IP addresses, user agents, usernames and passwords from failed login attempts that used usernames which don’t exist. It adds suggested wording to Settings → Privacy → Policy Guide.

Installation

  1. Upload the plugin through Plugins → Add New → Upload Plugin, or install it from the directory.
  2. Activate it.
  3. Open Phantom User Lockout in the admin menu, go to Blocked & Safe IPs and click Add my current IP address to the list. Do the same from every place you or your staff log in.
  4. If your site is behind a proxy or CDN and every visitor shows the same IP, change Visitor IP comes from in Settings.

FAQ

I locked myself out.

Add define( 'BOTLO_DISABLE', true ); to wp-config.php, or rename the plugin’s folder over FTP. Then log in, unblock your IP, add it to Safe IPs, and remove the line.

Why record the password?

It shows you which password lists are being used against your site. It’s only recorded for usernames that don’t exist, so it never belongs to a real account. You can turn it off under Settings → Passwords.

Does it replace a lockout plugin like Limit Login Attempts?

It can run next to one. Those plugins lock an IP out for a while after failed logins. Phantom User Lockout records what was tried and blocks the IP permanently.

Can it block the whole site, not just the login page?

Yes: Settings → “A blocked IP cannot reach”. Pages served from a caching plugin’s disk cache never reach WordPress, so those can’t be covered.

Where is the data kept?

In two database tables of the plugin’s own. Attempt rows are removed after 180 days or 100,000 rows, whichever comes first, and you can change both limits. Blocked IPs are kept until you unblock them. Deactivating the plugin keeps everything. Deleting the plugin removes the tables and the settings.

Where do I get help?

Post in the plugin’s support forum at https://wordpress.org/support/plugin/phantom-user-lockout/. Include your WordPress and PHP versions, and what you see in the Attempts log. Don’t post passwords or your own IP address there, because the forum is public.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Phantom User Lockout” is open source software. The following people have contributed to this plugin.

Contributors
  • efraing

Translate “Phantom User Lockout” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.2.0

  • Renamed from Login Lockout to Phantom User Lockout.

1.1.0

  • First public release.
  • Records login attempts with usernames that don’t exist, including the password tried, the IP’s location and its hosting company.
  • Permanent IP blocks, lifted only by Unblock.
  • Safe IPs, with a one-click “Add my current IP address to the list”.
  • Optional blocking after wrong passwords for real accounts (default 3).
  • Option to stop recording passwords.
  • CSV export.

Meta

  • Version 1.2.0
  • Last updated 22 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.2 or higher
  • Tested up to 7.1.2
  • PHP version 7.2 or higher
  • Tags
    block ipBrute Forcehoneypotloginsecurity
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • efraing

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org
  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry
The WordPress® trademark is the intellectual property of the WordPress Foundation.