A litte more secure
by EdwardBock 5 (1 reviews)

A litte more secure

Stop bots from brute force hacking your wp-login.php

A litte more secure ranks #13,752 among WordPress.org plugins with 100+ active installations, is #791 of 4,541 in the Security category, a 5/5 rating from 1 reviews, and was last updated Aug 3, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 6.7 (Current: 7.1.1)
v1.1.0 Current Version v1.1.0
Updated 1 month ago Last Update on 03 Aug, 2026
Refreshed 7 hours ago Last Refreshed on
#791 of 4,541 in Security Top 25% by installs
View on WordPress.org
Rank
#13,752
+17 this week
Active Installs
100+
-44.4%
KW Avg Position
N/A
No change
Downloads
2.6K
+1 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (1 reviews)

Next Milestone 200

Total Progress 83%
100+ 200+
719
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 17 more installs to reach 200+

Rank Changes

13,735 13,772 13,809 13,845 13,882 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
13,735 13,772 13,809 13,845 13,882 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
Current #13,752
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
0 10 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
1 reviews
Overall 100%
5
1 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Security History

Source: WPVulnerability

No known vulnerabilities on record for A litte more secure. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners who want to slow down automated brute force attempts against wp-login.php. It requires visitors to pass through a JavaScript-redirected holding page and carry a matching nonce before a login form or POST is accepted, raising the cost of naive bot automation without acting as a full lockout.

  • Blocks naive wp-login.php automation
  • Holding page with countdown redirect
  • Nonce required for login POST
  • No configuration needed to activate
  • Filter to customize unlock logic
  • Filter to rename unlock parameter
  • Filter to adjust redirect delay
  • Rotating unlock parameter via token

Frequently Asked Questions

Common questions about A litte more secure

No. Activate the plugin and it works. Everything that can be changed is changed with the filters described above, in a theme or a small plugin of your own.
That is intentional. A request to wp-login.php without the unlock parameter is answered with a 404 so that automated scanners see a missing page. Your browser still shows the holding page and is redirected to the real form a few seconds later. Uptime monitors and scanners pointed at wp-login.php will report it as missing — point them at a different URL, or exclude wp-login.php. I cannot log in. It says "Sorry, this feels not very secure". That message means the login form was submitted without a valid nonce. The usual causes: Something is caching wp-login.php. It must not be cached — the page carries a nonce that goes stale. Your theme renders its own login form that posts to wp-login.php without the nonce field. Call a_little_more_secure_nonce_field() inside the form. The login page sat open in a tab for more than a day. Nonces expire after at most 24 hours. Reload the page and log in again.
No. The redirect to the unlocked form is done in JavaScript, and only the unlocked form carries the nonce a login needs. Without JavaScript you will see the login page but the submission is rejected. If that is a problem for you, add your own rule with the a_little_more_secure_is_unlocked filter.
No. The plugin only guards wp-login.php. Brute force attempts against xmlrpc.php, the REST API or application passwords are unaffected, and those are common targets. If you do not use XML-RPC, disable it separately.
Yes. The unlock parameter is a fixed name by default, so a bookmark such as example.com/wp-login.php?a-little-more-secure keeps working and skips the wait. That changes only if you set up a rotating parameter as described above.
Yes, network activated or per site. The plugin stores nothing and has no per-site setup, so both work the same way.
No. It writes no options, sets no cookies and creates no database tables. The only thing it looks at is whether the unlock parameter is present in the request.
More secure than before, but this is a speed bump, not a lock. The unlock parameter and the nonce both have to be handed to a browser that is not logged in yet, so anything that fetches the page can read them too. It defeats bots that post blindly at wp-login.php, which is most of them. It does not defeat a determined attacker, and it does nothing about weak passwords or repeated attempts from the same source — combine it with strong passwords and rate limiting.

More plugins by EdwardBock

Sign In / Register

You need to sign in or register to use this feature.