{"id":367859,"date":"2026-09-16T03:07:49","date_gmt":"2026-09-16T03:07:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/dadsfam-login-security\/"},"modified":"2026-09-16T03:07:16","modified_gmt":"2026-09-16T03:07:16","slug":"dadsfam-login-security","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/dadsfam-login-security\/","author":23486748,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.7.1","stable_tag":"1.7.1","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"DadsFam Login Security","header_author":"DadsFam","header_description":"Hardens your WordPress login against brute-force attacks, bots and username scanning. Smart lockouts, IP allow\/deny lists, a full login activity log, email alerts and built-in hardening \u2014 all free, no forced upsells.","assets_banners_color":"bbcbdf","last_updated":"2026-09-16 03:07:16","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/plugins.dadsfam.co.za\/dadsfam-login-security-free-and-pro\/","header_author_uri":"https:\/\/plugins.dadsfam.co.za\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":36,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.7.1":{"tag":"1.7.1","author":"dadsfam","date":"2026-09-16 03:07:16","revision":3697870}},"upgrade_notice":{"1.7.1":"<p>Removes our own branding from the emails this plugin sends to your users, and fixes a broken link in the plugin header.<\/p>","1.7.0":"<p>A settings search and an unsaved-changes save bar. No change to how the protection works \u2014 safe drop-in update.<\/p>","1.6.0":"<p>Brand-new dashboard in the DadsFam house style, Cloudflare\/proxy support, instant lockout for bot usernames, protection-level presets and a one-click \u201cnever lock me out\u201d. Safe drop-in update \u2014 your settings are kept.<\/p>","1.5.4":"<p>Warns you when a conflicting login\/2FA plugin is active, and is now translation-ready. Safe drop-in update.<\/p>","1.5.3":"<p>Adds a database index so dashboard stats stay fast on large logs (applied automatically). Safe drop-in update.<\/p>","1.5.2":"<p>Activity Log now labels email-link sign-ins from the Pro add-on. Safe drop-in update.<\/p>","1.5.1":"<p>Activity Log now labels passkey events from the Pro add-on. Safe drop-in update.<\/p>","1.5.0":"<p>New-sign-in email alerts, CSV export of the activity log, and an audit-events filter. Safe drop-in update.<\/p>","1.4.1":"<p>Two-factor audit events now appear clearly in the Activity Log. Safe drop-in update.<\/p>","1.4.0":"<p>Live attack arcs on the threat sphere, gauge pulse rings, panel spotlight and an unblock animation. Safe drop-in update.<\/p>","1.3.0":"<p>Adds a rotating 3D threat sphere, decode number animations, a chart scan line and an aurora backdrop. Safe drop-in update.<\/p>","1.2.0":"<p>A live security-console dashboard with gauge, radar, activity ticker, dark mode and optional alert sound. Safe drop-in update.<\/p>","1.1.0":"<p>Live auto-refreshing dashboard and a full premium UI refresh. Safe drop-in update.<\/p>","1.0.0":"<p>First release of DadsFam Login Security.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3697870,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3697870,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3697870,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3697870,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.7.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3697870,"resolution":"1","location":"assets","locale":"","width":1280,"height":1600},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3697870,"resolution":"2","location":"assets","locale":"","width":1280,"height":1296},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3697870,"resolution":"3","location":"assets","locale":"","width":1280,"height":1600}},"screenshots":{"1":"The dashboard: protection status in one sentence, a finish-locking-down checklist, live stats, the 14-day chart and who is locked out right now.","2":"Activity: every sign-in attempt, filtered with one click, with \u201cBlock for good\u201d on any row.","3":"Settings: pick Relaxed, Balanced or Strict, flip plain-English switches, and put your own address on the allow list with one click."}},"plugin_section":[262246],"plugin_tags":[2439,9374,13868,602,600],"plugin_category":[38,54],"plugin_contributors":[274194],"plugin_business_model":[],"class_list":["post-367859","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-brute-force","plugin_tags-limit-login-attempts","plugin_tags-lockout","plugin_tags-login","plugin_tags-security","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-dadsfam","plugin_committers-dadsfam"],"banners":{"banner":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/banner-772x250.png?rev=3697870","banner_2x":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/banner-1544x500.png?rev=3697870","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/icon-128x128.png?rev=3697870","icon_2x":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/icon-256x256.png?rev=3697870","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-1.png?rev=3697870","caption":"The dashboard: protection status in one sentence, a finish-locking-down checklist, live stats, the 14-day chart and who is locked out right now."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-2.png?rev=3697870","caption":"Activity: every sign-in attempt, filtered with one click, with \u201cBlock for good\u201d on any row."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-3.png?rev=3697870","caption":"Settings: pick Relaxed, Balanced or Strict, flip plain-English switches, and put your own address on the allow list with one click."}],"raw_content":"<!--section=description-->\n<p><strong>DadsFam Login Security<\/strong> protects the most-attacked part of your WordPress site \u2014 the login form \u2014 without making you read a manual or fiddle with servers.<\/p>\n\n<p>Everything described below works on every site. Nothing is disabled, blurred out, time-limited or reduced.<\/p>\n\n<p>It watches failed logins, locks out attackers automatically, escalates repeat offenders to a longer ban, and keeps a clean log of everything so you can see exactly what's hitting your site.<\/p>\n\n<h4>What you get (free)<\/h4>\n\n<ul>\n<li><strong>Smart brute-force lockouts<\/strong> \u2014 set how many tries are allowed and how long the lockout lasts. Repeat offenders get an automatic extended ban.<\/li>\n<li><strong>IP allow &amp; deny lists<\/strong> \u2014 exact IPs, wildcards (<code>1.2.3.*<\/code>) and CIDR ranges (<code>1.2.3.0\/24<\/code>). IPv4 and IPv6.<\/li>\n<li><strong>Full login activity log<\/strong> \u2014 every failed login, success, lockout and block, with IP, username and device. Searchable, filterable, auto-pruned.<\/li>\n<li><strong>Live dashboard<\/strong> \u2014 failed-login stats, a 14-day chart, top attacking IPs, and who's locked out right now (with one-click unblock).<\/li>\n<li><strong>Email alerts<\/strong> \u2014 get a tidy, throttled email when a lockout triggers.<\/li>\n<li><strong>Generic login errors<\/strong> \u2014 stop attackers learning whether a username exists.<\/li>\n<li><strong>Honeypot bot trap<\/strong> \u2014 an invisible field that catches dumb bots.<\/li>\n<li><strong>Hardening<\/strong> \u2014 block user enumeration (<code>?author=N<\/code> and the REST API), kill XML-RPC pingback amplification, or disable XML-RPC entirely.<\/li>\n<\/ul>\n\n<h4>Pro Features (DadsFam Login Security Pro add-on)<\/h4>\n\n<p>The optional <strong>DadsFam Login Security Pro<\/strong> add-on plugs into the same screens and adds two-factor authentication (authenticator apps and email codes, with backup codes and trusted devices), CAPTCHA on the login form (Google reCAPTCHA, hCaptcha, Cloudflare Turnstile or a built-in maths question), a custom hidden login address, a branded login screen, strong-password and breached-password checks, idle auto-logout, scheduled security reports, and country blocking.<\/p>\n\n<h4>A word about PRO<\/h4>\n\n<p>Right, let me be straight with you, because I hate being sold to as much as you do.<\/p>\n\n<p>Everything above is free and it stays free. The lockouts, the allow and deny lists, the activity log, the live dashboard, the email alerts, the bot traps and the hardening \u2014 none of those are premium features. Those are the things a login-security plugin should just do, and if I put them behind a paywall I would be taking the mickey.<\/p>\n\n<p>There is a PRO add-on. It exists because I am a dad in Cape Town, and this is one of the things that puts food on the table at my house. That is the honest reason. Not \"unlock your potential\", not \"supercharge your workflow\". Just: if this plugin kept the bots off your login page and you can spare it, PRO helps me keep building.<\/p>\n\n<p>What PRO adds is the second layer you reach for once the door is already locked \u2014 two-factor codes, a CAPTCHA, a hidden login address, breached-password checks, country blocking. That is extra security and convenience. It is not the plugin working properly, because the plugin already works properly.<\/p>\n\n<p>So if the free one does everything you need, brilliant. Genuinely. Use it, and I hope your activity log stays boring. If you get to the point where a second factor or a hidden login would let you sleep better, PRO is at plugins.dadsfam.co.za.<\/p>\n\n<p>Either way, thanks for using something I built. \u2014 Zak, DadsFam<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>, or install the ZIP via <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>.<\/li>\n<li>Activate it through the <strong>Plugins<\/strong> menu.<\/li>\n<li>Head to <strong>Login Security<\/strong> in the admin sidebar. Sensible defaults are already on \u2014 tweak the numbers under <strong>Settings<\/strong> if you like.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20lock%20me%20out%20of%20my%20own%20site%3F\"><h3>Will this lock me out of my own site?<\/h3><\/dt>\n<dd><p>It locks out by IP after repeated <em>failed<\/em> logins. Add your own IP to the <strong>Allow list<\/strong> under Settings to be safe. If you ever get stuck, lockouts expire on their own, or you can clear the <code>wp_dfls_lockouts<\/code> database table.<\/p><\/dd>\n<dt id=\"does%20it%20work%20behind%20cloudflare%20or%20a%20load%20balancer%3F\"><h3>Does it work behind Cloudflare or a load balancer?<\/h3><\/dt>\n<dd><p>By default it uses the real connection IP (<code>REMOTE_ADDR<\/code>), which can't be spoofed. If you're behind a trusted proxy, you can return the forwarded header using the <code>dfls_client_ip<\/code> filter.<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20woocommerce%20login%20forms%3F\"><h3>Is it compatible with WooCommerce login forms?<\/h3><\/dt>\n<dd><p>Yes \u2014 the honeypot and protection also apply to the WooCommerce login form.<\/p><\/dd>\n<dt id=\"will%20disabling%20xml-rpc%20break%20anything%3F\"><h3>Will disabling XML-RPC break anything?<\/h3><\/dt>\n<dd><p>Disabling just <strong>pingbacks<\/strong> is safe for nearly everyone. Disabling XML-RPC <strong>completely<\/strong> can affect the WordPress\/Jetpack mobile app and some remote-publishing tools, so that option is off by default.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.7.1<\/h4>\n\n<ul>\n<li>Removed the small \"Powered by DadsFam\" line from the bottom of the lockout and new-login emails. Those emails go to your users, and nothing of ours belongs in them unless you have asked for it.<\/li>\n<li>Corrected the plugin's homepage link in its header, which pointed at a page that no longer exists.<\/li>\n<\/ul>\n\n<h4>1.7.0<\/h4>\n\n<ul>\n<li>New: find any setting. A search box above the Settings cards filters every switch and field by a word in its label or description, opens the \"actual numbers\" section when a match is inside it, and says plainly when nothing matches.<\/li>\n<li>New: the save bar tells you. It lights up the moment something on the page changes and the browser warns before you leave with unsaved changes.<\/li>\n<li>Readme: added the standing \"A word about PRO\" note \u2014 what stays free, why the optional add-on exists, and what it actually adds \u2014 and the line that nothing in the free plugin is disabled, blurred out, time-limited or reduced. Tested up to WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.6.1<\/h4>\n\n<ul>\n<li>Fixed: cleared every WordPress.org Plugin Check violation \u2014 six request values read without sanitising, a discouraged text-domain call, and a set of table-name and nonce false positives now carry the justification the checker needs. Zero violations.<\/li>\n<li>Fixed: a CAPTCHA refusal raised by another plugin was counted as a failed password. A visitor turned away by a bot check a few times was then locked out here as well \u2014 two plugins compounding one problem. Any error whose code mentions a CAPTCHA is now ignored when counting failed attempts, whichever plugin raised it. Wrong passwords still count exactly as before.<\/li>\n<\/ul>\n\n<h4>1.6.0<\/h4>\n\n<ul>\n<li>New: the whole admin screen has been rebuilt in the DadsFam house style \u2014 one calm, tabbed screen (Dashboard \u00b7 Activity \u00b7 Settings) that leads with what is true right now and what to do about it, in plain English. Protection status at a glance, a \u201cfinish locking things down\u201d checklist that disappears once you're done, big tap-tiles, and an \u201cif something goes wrong\u201d panel with the fix written right there.<\/li>\n<li>New: \u201cNever lock me out\u201d \u2014 one click puts your own address on the allow list, from the dashboard or the checklist.<\/li>\n<li>New: instant lockout for bot usernames. Anyone trying \u201cadmin\u201d, \u201croot\u201d, \u201ctest\u201d and friends when no such account exists is a bot; they're locked out on the first try instead of the fifth. Real accounts with those names are never affected. The list is editable.<\/li>\n<li>New: protection levels. Pick Relaxed, Balanced (recommended) or Strict instead of juggling five numbers \u2014 the numbers are still there for people who want them.<\/li>\n<li>New: Cloudflare and proxy support. Behind Cloudflare, every visitor used to look like the same address, so one bot could lock out your whole site. Choose \u201cCloudflare\u201d or \u201cAnother proxy\u201d under Settings \u2192 Where visitors' addresses come from; forwarded headers are only ever trusted when the request genuinely came from the proxy, so nobody can fake their address. The dashboard warns you if it spots Cloudflare and the setting is still on \u201cplain hosting\u201d.<\/li>\n<li>New: a recovery valve for the free plugin. Add <code>define( 'DFLS_DISABLE_LOCKOUTS', true );<\/code> to wp-config.php and every lockout is switched off until you remove it. The dashboard shows a red warning while it is in place.<\/li>\n<li>New: \u201cLet everyone back in\u201d clears every active lockout at once; \u201cBlock for good\u201d on any row moves an address to the deny list.<\/li>\n<li>New: the activity log shows \u201cChrome on Windows\u201d instead of a 200-character user agent, filters with pills, and lets you block an attacker straight from the row.<\/li>\n<li>Improved: locked-out addresses hammering a real account no longer cost a password-hash check per attempt \u2014 the lockout is now applied before the (deliberately slow) password comparison.<\/li>\n<li>Improved: dashboard statistics come from one query instead of five, and are memoised per request.<\/li>\n<li>Improved: the live dashboard pauses when the tab is hidden and refreshes the moment you come back.<\/li>\n<li>Changed: minimum WordPress version is now 6.0. Tested up to 7.0.<\/li>\n<\/ul>\n\n<h4>1.5.5<\/h4>\n\n<ul>\n<li>Fixed: the honeypot bot trap could block genuine sign-ins when a password manager (1Password, LastPass, Bitwarden, browser autofill) filled the hidden field on the visitor's behalf. The trap now ignores values that simply mirror what the visitor legitimately typed, so real people get in and bots still get caught.<\/li>\n<li>Improved: the honeypot field now carries the ignore hints password managers actually respect, so most of them skip it entirely.<\/li>\n<\/ul>\n\n<h4>1.5.4<\/h4>\n\n<ul>\n<li>New: a clear warning on the plugin\u2019s admin pages when a known conflicting login\/2FA plugin (e.g. Loginizer) is active at the same time \u2014 running two can break sign-in.<\/li>\n<li>Improved: translation-ready \u2014 the plugin now loads its text domain from a \/languages folder.<\/li>\n<\/ul>\n\n<h4>1.5.3<\/h4>\n\n<ul>\n<li>Performance: added a composite database index (status + time) so the dashboard statistics and charts stay fast even with very large activity logs. The index is added automatically on update.<\/li>\n<\/ul>\n\n<h4>1.5.2<\/h4>\n\n<ul>\n<li>Improved: the Activity Log now labels email-link (magic-link) sign-ins from the Pro add-on.<\/li>\n<li>Hardened: the new-sign-in email alert is wrapped so it can never interfere with logging in.<\/li>\n<\/ul>\n\n<h4>1.5.1<\/h4>\n\n<ul>\n<li>Improved: the Activity Log now labels passkey events (passkey added, removed, sign-in) written by the Pro add-on.<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>New: optional new-sign-in email alert \u2014 the account owner is emailed when their account is signed into from an IP not seen before (opt-in under Settings \u2192 Notifications; the first login is remembered silently).<\/li>\n<li>New: export the activity log to CSV from the Activity Log page.<\/li>\n<li>New: filter the Activity Log by two-factor \/ security audit events (2FA on\/off, device trusted\/removed, codes reset).<\/li>\n<\/ul>\n\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Improved: the Activity Log now shows two-factor audit events (2FA on\/off, device trusted\/removed, backup codes reset) with their own clear labels.<\/li>\n<li>Improved: the live dashboard ticker stays focused on genuine login attempts.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>New: live attack arcs \u2014 glowing comet trails streak across the threat sphere from each attacker to a marker representing your site.<\/li>\n<li>New: ambient pulse rings radiate from the security-score gauge, tinted to your current status.<\/li>\n<li>New: a soft cursor-follow spotlight glides across each panel for a premium, fluid feel.<\/li>\n<li>New: unblocking an IP now plays a satisfying \u201czap\u201d as the row clears.<\/li>\n<li>Accessibility: all new effects switch off with \u201creduce motion\u201d.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>New: rotating 3D wireframe \u201cthreat sphere\u201d that plots live attack activity.<\/li>\n<li>New: hacker-style \u201cdecode\u201d animation \u2014 stat numbers and the security score scramble, then lock in, on load.<\/li>\n<li>New: a glowing scan line sweeps across the failed-logins chart.<\/li>\n<li>New: subtle animated aurora glow behind the whole dashboard (light &amp; dark).<\/li>\n<li>Accessibility: all of the above switch off automatically with \u201creduce motion\u201d.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New: live \u201csecurity console\u201d dashboard \u2014 an animated Protection Score gauge that reacts to real-time conditions.<\/li>\n<li>New: live activity ticker and a sweeping attack radar that plots your top attacking IPs.<\/li>\n<li>New: animated constellation backdrop, 3D-tilt stat cards, and glowing animated panel borders.<\/li>\n<li>New: one-click Dark Mode (remembered between visits) and an optional alert sound when a new lockout happens.<\/li>\n<li>Accessibility: every effect is disabled automatically when \u201creduce motion\u201d is on; sound is off by default.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: live, self-refreshing security dashboard \u2014 stats update automatically every 12 seconds with no page reload.<\/li>\n<li>New: animated 14-day failed-login chart with hover tooltips and smooth transitions.<\/li>\n<li>New: animated count-up stat cards, and at-a-glance summary cards on the Activity Log page.<\/li>\n<li>Improved: premium glass UI across the dashboard, log and settings pages.<\/li>\n<li>Accessibility: all animations honour the \u201creduce motion\u201d system setting.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: brute-force lockouts, IP allow\/deny lists, activity log, dashboard, email alerts, honeypot, generic errors, and hardening (user-enumeration, XML-RPC, pingback).<\/li>\n<\/ul>","raw_excerpt":"Stop brute-force attacks dead. Smart login lockouts, IP rules, a full activity log and WordPress hardening \u2014 in plain English, no manual needed.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/367859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=367859"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dadsfam"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=367859"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=367859"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=367859"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=367859"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=367859"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=367859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}