• Resolved Ricardo

    (@rhormazar)


    I love how this plugin looks and works, but I am still getting bot login attempts with the plugin activated and tested. I use Sucuri security plugin for login attempt alerts and I still get 30+ attempts a day for ‘admin’ username and blank password.

    I really thought this plugin would help with that, but am I doing something wrong?

    https://wordpress.org/plugins/wp-login-recaptcha/

Viewing 3 replies - 1 through 3 (of 3 total)
  • Did those attempts happen quickly? (for example under 1 second delay)

    I’ve tried to install Sucuri and if the user does not pass the reCAPTCHA challenge, Sucuri will not send the notification.
    So it means the “user” has passed the reCAPTCHA challenge.

    Thank you.

    Thread Starter Ricardo

    (@rhormazar)

    It seems like it fixed itself. I don’t know if they built up and were just delayed, but it just stopped happening and my tests show that a login attempt CANNOT go through without completing the re-CAPTCHA.

    Thank you.

    Yes, without completing the re-CAPTCHA, my plugin will “cancel” the login process.

    Thank you.

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Not blocking bot's brute force login attempts’ is closed to new replies.