Title: NibbleSecure &#8211; Hide Login, Limit Login Attempts &amp; Brute Force Shield
Author: MVP Plugins
Published: <strong>September 29, 2026</strong>
Last modified: September 29, 2026

---

Search plugins

![](https://ps.w.org/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/
assets/banner-772x250.png?rev=3718811)

![](https://ps.w.org/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/
assets/icon-256x256.png?rev=3718811)

# NibbleSecure – Hide Login, Limit Login Attempts & Brute Force Shield

 By [MVP Plugins](https://profiles.wordpress.org/mvpplugins/)

[Download](https://downloads.wordpress.org/plugin/nibblesecure-hide-login-limit-login-attempts-brute-force-shield.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/#description)
 * [Reviews](https://wordpress.org/plugins/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/#reviews)
 *  [Installation](https://wordpress.org/plugins/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/#installation)
 * [Development](https://wordpress.org/plugins/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/#developers)

 [Support](https://wordpress.org/support/plugin/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/)

## Description

NibbleSecure protects your WordPress login page from bots, scanners, and brute force
attacks. It hides your default wp-login.php page behind a secret URL, so automated
login attacks never even find your real login form.

On top of hiding your login page, NibbleSecure limits login attempts and locks out
an IP address once it crosses your configured threshold. The lockout period grows
for repeat offenders. It then sends you an instant email alert when that happens.
No external service, API key, or subscription is required.

NibbleSecure runs natively on WordPress’s own database. It’s lightweight, fast, 
and 100% free.

Looking for Two-Factor Authentication (2FA)? Two-Factor Authentication (2FA/TOTP)
compatible with Google Authenticator, Authy, Microsoft Authenticator, and 1Password
is available through the separate NibbleSecure PRO add-on, along with heuristic 
malware scanning, file integrity monitoring, self-healing plugin protection, session
hijacking control, Application-Layer (L7) DDoS protection, advanced .htaccess server
hardening, an automated 404 scanner with IP auto-ban, manual IP/country blocking,
scheduled automatic backups with one-click restore, and a math CAPTCHA on the login
and lost-password forms. These PRO features are not included in this free version–
see “Available in PRO Version” below for details.

#### Free Version Capabilities

 1. Hide Login (Secret Login URL)
 2. Limit Login Attempts & Brute Force Protection
 3. Configurable Lockout Thresholds with Escalating Repeat-Offense Penalties
 4. Email Alerts & Secret URL Backup

#### Available in PRO Version

The following features require the separate, self-hosted NibbleSecure PRO add-on(
https://mvpplugins.com/nibblesecure/) and are not part of this free plugin:

 1.  Two-Factor Authentication (2FA/TOTP) – Adds a second verification step at login
     using Google Authenticator, Authy, Microsoft Authenticator, 1Password, or other
     standard authenticator apps, with emergency backup codes and secure email-based
     recovery if you lose your device.
 2.  Heuristic Malware Detection & File Integrity Monitoring – Scans plugin and core
     files every hour against SHA-256 baselines to catch unauthorized changes, injected
     code, and malware.
 3.  Self-Healing Plugin Protection – Automatically restores NibbleSecure’s own core
     files if an attacker deletes or tampers with them.
 4.  Session Hijacking Control – Detects unauthorized concurrent device logins and 
     lets you instantly log out every other active session.
 5.  Application-Layer (L7) DDoS & Flood Protection – Rate-limits and blocks malicious
     traffic spikes and botnet floods before they reach your server.
 6.  Scheduled Automatic WordPress Backups & Restore – Creates scheduled restore points
     for your database, files, and configuration, with one-click recovery.
 7.  Advanced Server Hardening (.htaccess Tweaks) – XML-RPC and pingback toggles, hidden-
     file blocking (.git, .env), bad-bot and malicious query-string blocking, and other
     server-level hardening options.
 8.  Automated 404 Scanner & IP Auto-Ban – Detects IPs that repeatedly request non-
     existent pages within a short time window (a common sign of vulnerability scanning)
     and automatically bans them for a configurable duration, independent of the login-
     attempt counter.
 9.  Manual IP, IP Range & Country Blocking – Instantly allow or block specific IP 
     addresses, IP ranges, or entire countries from accessing your site, from a dedicated
     management panel.
 10. Math CAPTCHA on Login & Lost Password Forms – Adds a simple math challenge to 
     the login and password-reset forms to stop automated bot submissions before they
     reach the brute-force checks.

## Screenshots

[⌊NibbleSecure dashboard overview with secret login URL settings.⌉⌊NibbleSecure 
dashboard overview with secret login URL settings.⌉[

NibbleSecure dashboard overview with secret login URL settings.

[⌊Brute force & limit login attempts settings with attempt limits and lockout duration.⌉⌊
Brute force & limit login attempts settings with attempt limits and lockout duration
.⌉[

Brute force & limit login attempts settings with attempt limits and lockout duration.

[⌊PRO feature preview tabs inside the dashboard.⌉⌊PRO feature preview tabs inside
the dashboard.⌉[

PRO feature preview tabs inside the dashboard.

## Installation

 1. Upload the plugin folder to your server’s /wp-content/plugins/ folder, or install
    the plugin package directly via the WordPress Admin Plugins panel screen.
 2. Click “Activate” on NibbleSecure from your Plugins dashboard.
 3. Open the new “NibbleSecure” settings tab under your WordPress admin settings.
 4. Set and save your custom secret login URL slug.
 5. Set your preferred maximum failed login attempts and lockout duration.

## FAQ

### What does the Hide Login feature do?

NibbleSecure replaces public access to your default wp-login.php page with a unique
secret URL. Anyone or any bot trying to reach the standard login page is blocked
before it ever loads.

### What happens if I forget my secret login URL?

Your secret login URL is shown in an on-screen notice right after you activate the
plugin, and it’s always visible on the NibbleSecure settings page. If you’d also
like a copy emailed to you, use the “Email Me” button on the settings page: enter
your admin email and it will send your current secret login URL to your inbox. No
email is sent automatically; this only happens when you choose to click that button.

### How does Limit Login Attempts & Brute Force Protection work?

NibbleSecure tracks failed login attempts by IP address. Once an IP crosses your
configured maximum attempts, it’s locked out from logging in for your set lockout
period. If the same IP gets locked out again within 24 hours, each repeat offense
adds your configured “Compounding Progression Interval” on top of the base lockout,
so persistent attackers face progressively longer bans. If your site sits behind
a trusted proxy or CDN, see the `nibblesecure_trusted_proxy_headers` filter to configure
which proxy header, if any, should be trusted for identifying the real visitor IP.
This is a code-level setting for developers, added via a filter in your theme or
a small custom plugin; it is not a toggle found on the Brute Force settings tab,
since the correct header depends on your specific hosting/CDN setup.

### Does this free version require any outside subscription services?

No. NibbleSecure runs entirely on your own WordPress database. It doesn’t load external
tracking scripts or require any paid cloud API to hide your login page or limit 
login attempts.

### Will login security checks slow down my site?

No. NibbleSecure is built to be lightweight. Login attempt checks and lockout lookups
are optimized to have minimal impact on your site’s load time.

### What is the purpose of the premium tabs visible inside the dashboard?

The locked settings tabs preview PRO-only features: Two-Factor Authentication (2FA/
TOTP), malware & file integrity scanning, session hijacking control, Application-
Layer (L7) DDoS protection, advanced .htaccess server hardening, an automated 404
scanner with IP auto-ban, manual IP/country blocking, a login math CAPTCHA, and 
scheduled backups with one-click restore. These are unlocked by installing the separate,
self-hosted NibbleSecure PRO add-on from our website. The free version on WordPress.
org is fully functional without it.

### Does NibbleSecure support Two-Factor Authentication (2FA)?

Two-Factor Authentication (2FA/TOTP) is not included in this free version. It’s 
available exclusively through the separate NibbleSecure PRO add-on. Once installed,
NibbleSecure PRO adds TOTP-based two-factor authentication compatible with Google
Authenticator, Authy, Microsoft Authenticator, 1Password, and other standard authenticator
apps. It also adds emergency backup codes and secure email recovery if you ever 
lose your device.

### What is Two-Factor Authentication and why should I use it?

Two-Factor Authentication (2FA) adds a second verification step after your username
and password: a time-based 6-digit code from an authenticator app. This keeps your
account protected even if your password is stolen, guessed, or leaked elsewhere.
This free version protects your login with a secret login URL, limit login attempts,
and brute force protection; full 2FA/TOTP support is available in the NibbleSecure
PRO add-on.

### Does NibbleSecure block bots that scan my site for vulnerabilities?

The free version’s Limit Login Attempts & Brute Force Protection only tracks failed
login attempts. Detecting and auto-banning IPs that repeatedly probe non-existent
pages is a separate PRO-only feature, Automated 404 Scanner & IP Auto-Ban. Repeatedly
probing non-existent pages is a common sign of vulnerability scanning. This feature
is available through the NibbleSecure PRO add-on.

### Can I manually block specific IPs or countries?

Not in this free version. Manual IP, IP range, and country blocking is available
through the NibbleSecure PRO add-on, which includes a dedicated management panel
for adding and removing blocks.

### Does NibbleSecure include a CAPTCHA on the login form?

Not in this free version. A math CAPTCHA on the login and lost-password forms, which
helps stop automated bot submissions before they reach the brute-force checks, is
available through the NibbleSecure PRO add-on.

### Does NibbleSecure protect against DDoS attacks?

Not in this free version. Application-Layer (L7) DDoS & Flood Protection, which 
rate-limits and blocks malicious traffic spikes and botnet floods before they reach
your server, is available through the NibbleSecure PRO add-on.

### Can NibbleSecure back up my site automatically?

Not in this free version. Scheduled automatic backups with one-click restore, covering
your database, files, and configuration, are available through the NibbleSecure 
PRO add-on.

### Does NibbleSecure stop attackers from discovering my usernames?

Not in this free version. Blocking author/user enumeration attacks, a common technique
bots use to discover valid usernames before attempting a brute-force login, is available
through the NibbleSecure PRO add-on.

### Can NibbleSecure block content scrapers that use my site’s RSS feed?

Not in this free version. Blocking RSS/Atom feeds from content scrapers is available
through the NibbleSecure PRO add-on.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“NibbleSecure – Hide Login, Limit Login Attempts & Brute Force Shield” is open source
software. The following people have contributed to this plugin.

Contributors

 *   [ MVP Plugins ](https://profiles.wordpress.org/mvpplugins/)

[Translate “NibbleSecure – Hide Login, Limit Login Attempts & Brute Force Shield” into your language.](https://translate.wordpress.org/projects/wp-plugins/nibblesecure-hide-login-limit-login-attempts-brute-force-shield)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/),
check out the [SVN repository](https://plugins.svn.wordpress.org/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/)
by [RSS](https://plugins.trac.wordpress.org/log/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial release.
 * Hide Login (secret login URL) protection.
 * Limit Login Attempts & Brute Force Protection with configurable, escalating IP
   lockout thresholds.
 * Email alerts for brute-force lockouts, plus a “Email Me” option to receive your
   secret login URL by email at any time.

## Meta

 *  Version **1.0.0**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [brute force protection](https://wordpress.org/plugins/tags/brute-force-protection/)
   [firewall](https://wordpress.org/plugins/tags/firewall/)[hide login page](https://wordpress.org/plugins/tags/hide-login-page/)
   [limit login attempts](https://wordpress.org/plugins/tags/limit-login-attempts/)
   [login security](https://wordpress.org/plugins/tags/login-security/)
 *  [Advanced View](https://wordpress.org/plugins/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/reviews/)

## Contributors

 *   [ MVP Plugins ](https://profiles.wordpress.org/mvpplugins/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/nibblesecure-hide-login-limit-login-attempts-brute-force-shield/)