{"id":376066,"date":"2026-09-29T19:29:49","date_gmt":"2026-09-29T19:29:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/login-lockout\/"},"modified":"2026-09-29T17:24:38","modified_gmt":"2026-09-29T17:24:38","slug":"phantom-user-lockout","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/phantom-user-lockout\/","author":23574306,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.0","stable_tag":"1.2.0","tested":"7.1.2","requires":"6.2","requires_php":"7.2","requires_plugins":null,"header_name":"Phantom User Lockout","header_author":"Efrain Gutierrez","header_description":"Records login attempts that use a username which does not exist on this site \u2014 username, password tried, IP, location and hosting company \u2014 and blocks that IP from logging in again.","assets_banners_color":"12161e","last_updated":"2026-09-29 17:24:38","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":46,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.0":{"tag":"1.2.0","author":"efraing","date":"2026-09-29 17:24:38","revision":3719513}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3719463,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3719463,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3719463,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3719463,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[1944,2439,598,602,600],"plugin_category":[38,54],"plugin_contributors":[283474],"plugin_business_model":[],"class_list":["post-376066","plugin","type-plugin","status-publish","hentry","plugin_tags-block-ip","plugin_tags-brute-force","plugin_tags-honeypot","plugin_tags-login","plugin_tags-security","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-efraing","plugin_committers-efraing"],"banners":{"banner":"https:\/\/ps.w.org\/phantom-user-lockout\/assets\/banner-772x250.png?rev=3719463","banner_2x":"https:\/\/ps.w.org\/phantom-user-lockout\/assets\/banner-1544x500.png?rev=3719463","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/phantom-user-lockout\/assets\/icon-128x128.png?rev=3719463","icon_2x":"https:\/\/ps.w.org\/phantom-user-lockout\/assets\/icon-256x256.png?rev=3719463","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Bots guess usernames like \"admin\" and \"administrator\". On most sites those names don't exist, so any attempt with them is a bot. Phantom User Lockout records each one and blocks the IP address that made it.<\/p>\n\n<p>For every attempt with a username that doesn't exist on your site, you get:<\/p>\n\n<ul>\n<li>The time, in site time with UTC on hover<\/li>\n<li>The username and the password that was tried<\/li>\n<li>The IP address, shown as <strong>IP Blocked<\/strong>, <strong>Not blocked<\/strong> or <strong>Safe<\/strong><\/li>\n<li>Where the IP is: city, region and country<\/li>\n<li>Who owns it: the hosting company or network (for example \"AS53667 FranTech Solutions\") and the reverse hostname<\/li>\n<li>How the attempt came in: the login form, XML-RPC (every guess inside a system.multicall batch gets its own row), REST API application passwords, or another login form<\/li>\n<li>The user agent and the requested URL<\/li>\n<\/ul>\n\n<h4>Blocking<\/h4>\n\n<ul>\n<li>An IP is blocked after its first attempt with a username that doesn't exist. You can raise that threshold.<\/li>\n<li>Blocks are permanent. They only lift when you press <strong>Unblock<\/strong>.<\/li>\n<li>A blocked visitor gets a 403 page that reads \"IP Blocked\".<\/li>\n<li>By default a block covers the login page, XML-RPC, REST logins and any other form that logs in through WordPress. You can widen it to the whole site.<\/li>\n<li>Optionally, the plugin can also block IPs that enter the wrong password for a real username. This is off by default, and the default threshold is 3 wrong passwords.<\/li>\n<\/ul>\n\n<h4>Built not to lock you out<\/h4>\n\n<ul>\n<li>Real accounts are never recorded unless you turn on the real-account option, and even then their passwords are never stored.<\/li>\n<li>If a username is within two letters of a real login or email, it's treated as a typo by one of your own people. It's logged with the password hidden and never causes a block.<\/li>\n<li><strong>Safe IPs<\/strong> are never recorded or blocked. Add yours with one click: \"Add my current IP address to the list\".<\/li>\n<li>A signed-in administrator is never blocked. Neither are the server's own address and loopback.<\/li>\n<li>Emergency switch: add <code>define( 'BOTLO_DISABLE', true );<\/code> to wp-config.php.<\/li>\n<\/ul>\n\n<p>The plugin never edits .htaccess or any other server file.<\/p>\n\n<h3>External services<\/h3>\n\n<p>To show where an IP address is and who owns its network, the plugin looks the address up with <strong>ipinfo.io<\/strong>.<\/p>\n\n<ul>\n<li><strong>What is sent:<\/strong> only the IP address that made the login attempt, plus your ipinfo.io token if you entered one in Settings. No information about your site, your users or your visitors is sent.<\/li>\n<li><strong>When:<\/strong> once per new IP address, in the background shortly after its first attempt, or when an administrator opens the Phantom User Lockout screen while a lookup is still pending.<\/li>\n<li><strong>Turning it off:<\/strong> Settings \u2192 Location lookups.<\/li>\n<li>ipinfo.io terms of service: https:\/\/ipinfo.io\/terms-of-service<\/li>\n<li>ipinfo.io privacy policy: https:\/\/ipinfo.io\/privacy-policy<\/li>\n<\/ul>\n\n<h3>Privacy<\/h3>\n\n<p>The plugin stores IP addresses, user agents, usernames and passwords from failed login attempts that used usernames which don't exist. It adds suggested wording to Settings \u2192 Privacy \u2192 Policy Guide.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin through Plugins \u2192 Add New \u2192 Upload Plugin, or install it from the directory.<\/li>\n<li>Activate it.<\/li>\n<li>Open <strong>Phantom User Lockout<\/strong> in the admin menu, go to <strong>Blocked &amp; Safe IPs<\/strong> and click <strong>Add my current IP address to the list<\/strong>. Do the same from every place you or your staff log in.<\/li>\n<li>If your site is behind a proxy or CDN and every visitor shows the same IP, change <strong>Visitor IP comes from<\/strong> in Settings.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"i%20locked%20myself%20out.\"><h3>I locked myself out.<\/h3><\/dt>\n<dd><p>Add <code>define( 'BOTLO_DISABLE', true );<\/code> to wp-config.php, or rename the plugin's folder over FTP. Then log in, unblock your IP, add it to Safe IPs, and remove the line.<\/p><\/dd>\n<dt id=\"why%20record%20the%20password%3F\"><h3>Why record the password?<\/h3><\/dt>\n<dd><p>It shows you which password lists are being used against your site. It's only recorded for usernames that don't exist, so it never belongs to a real account. You can turn it off under Settings \u2192 Passwords.<\/p><\/dd>\n<dt id=\"does%20it%20replace%20a%20lockout%20plugin%20like%20limit%20login%20attempts%3F\"><h3>Does it replace a lockout plugin like Limit Login Attempts?<\/h3><\/dt>\n<dd><p>It can run next to one. Those plugins lock an IP out for a while after failed logins. Phantom User Lockout records what was tried and blocks the IP permanently.<\/p><\/dd>\n<dt id=\"can%20it%20block%20the%20whole%20site%2C%20not%20just%20the%20login%20page%3F\"><h3>Can it block the whole site, not just the login page?<\/h3><\/dt>\n<dd><p>Yes: Settings \u2192 \"A blocked IP cannot reach\". Pages served from a caching plugin's disk cache never reach WordPress, so those can't be covered.<\/p><\/dd>\n<dt id=\"where%20is%20the%20data%20kept%3F\"><h3>Where is the data kept?<\/h3><\/dt>\n<dd><p>In two database tables of the plugin's own. Attempt rows are removed after 180 days or 100,000 rows, whichever comes first, and you can change both limits. Blocked IPs are kept until you unblock them. Deactivating the plugin keeps everything. Deleting the plugin removes the tables and the settings.<\/p><\/dd>\n<dt id=\"where%20do%20i%20get%20help%3F\"><h3>Where do I get help?<\/h3><\/dt>\n<dd><p>Post in the plugin's support forum at https:\/\/wordpress.org\/support\/plugin\/phantom-user-lockout\/. Include your WordPress and PHP versions, and what you see in the Attempts log. Don't post passwords or your own IP address there, because the forum is public.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Renamed from Login Lockout to Phantom User Lockout.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>First public release.<\/li>\n<li>Records login attempts with usernames that don't exist, including the password tried, the IP's location and its hosting company.<\/li>\n<li>Permanent IP blocks, lifted only by Unblock.<\/li>\n<li>Safe IPs, with a one-click \"Add my current IP address to the list\".<\/li>\n<li>Optional blocking after wrong passwords for real accounts (default 3).<\/li>\n<li>Option to stop recording passwords.<\/li>\n<li>CSV export.<\/li>\n<\/ul>","raw_excerpt":"Records logins that use usernames which don&#039;t exist (username, password tried, IP, location, host) and blocks the IP until you unblock it.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/376066","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=376066"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/efraing"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=376066"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=376066"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=376066"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=376066"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=376066"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=376066"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}