Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection
by Themepaste 5 (4 reviews)

Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection

Stop brute force attacks for free. Limit login attempts, add 2FA and reCAPTCHA, hide wp-login.php, block IPs and see every login on your site.

Admin Safety Guard ranks #27,662 among WordPress.org plugins with 20+ active installations, is #558 of 1,590 in the Authentication category, a 5/5 rating from 4 reviews, and was last updated Aug 13, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.5 (Current: 7.1.2)
v1.4.1 Current Version v1.4.1
Updated 1 month ago Last Update on 13 Aug, 2026
Refreshed 11 hours ago Last Refreshed on
#558 of 1,590 in Authentication Top 50% by installs Downloads -44.6% this week
View on WordPress.org
Rank
#27,662
-160 this week
Active Installs
20+
-23.1%
KW Avg Position
96.8
0.5 worse
Downloads
2.9K
+3 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (4 reviews)

Next Milestone 30

Total Progress 50%
20+ 30+
4,932
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 5 more installs to reach 30+

Rank Changes

23,647 24,791 25,935 27,079 28,223 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
23,131 24,421 25,711 27,000 28,290 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
Current #27,662
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
0 10 20 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
4 reviews
Overall 100%
5
4 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection

Yes. Everything listed under Free Features works with no limits, no trial period and no account. Pro exists for magic links, app-based 2FA, social login, password policies and the web application firewall, but nothing in the free version is crippled to push you towards it.
No. The admin JavaScript and CSS only load on the plugin's own screens, and even there only the bundle for the screen you're viewing. Your front end gets nothing extra. The login checks themselves are a couple of indexed database queries.
That's the risk worth taking seriously, so two things protect you. Add your own IP to the trusted list and login limiting will never apply to you. And if you change your login URL, bookmark the new address before saving, because wp-login.php will return a 404 afterwards. If it does happen: wait out the lockout (15 minutes by default), or rename the plugin folder over FTP to switch everything off.
Each failed password is recorded against the IP address it came from. Hit your limit (3 by default) and that address is locked out for your chosen duration (15 minutes by default). If the same address collects several lockouts in a day, it's blocked for a full 24 hours. Trusted addresses are skipped entirely, and everything is logged.
Per-IP limiting stops the overwhelming majority of automated attacks, because most run from a small number of addresses. For anything more determined, a custom login URL is the stronger layer: a bot that can't find the login form has nothing to attack. Running both is the usual answer.
The plugin points your new slug at the WordPress login system and makes wp-login.php and wp-register.php return 404 for logged-out visitors. Slugs that would collide with a real WordPress path are rejected. Permalinks are flushed automatically when you save.
Yes. Paths are resolved relative to the site's own home path, so root installs, WordPress in a subfolder, and both subdomain and subdirectory networks all behave the same.
Only the roles you choose. Leave the role list empty to cover everyone, or tick just Administrator and Editor so sign-in stays simple for customers and subscribers.
Yes. Edit the subject and the body in the Two-Factor Authentication settings. Use {otp} where the code should appear and {site_name} for your site name. Leave the body empty to use the styled default.
It controls how long a signed-in session stays valid, and every part of it is off until you turn it on. The idle timeout is the one most sites want: 30 to 60 minutes. Tying a session to an IP address is the strict option - it stops stolen cookies working elsewhere, but it will sign out anyone on a mobile connection whose IP changes, so it suits fixed office networks best.

Sign In / Register

You need to sign in or register to use this feature.