Limit Login Attempts Security - Login Security, 2FA, Firewall, Brute Force Prevention
by WPChef 4.8 (1,483 reviews)

Limit Login Attempts Security - Login Security, 2FA, Firewall, Brute Force Prevention

WordPress login security with brute force protection, Two-factor authentication (2FA/MFA), firewall, IP/country blocking, and login monitoring

Limit Login Attempts Security ranks #33 among WordPress.org plugins with 1,000,000+ active installations, is #4 of 1,575 in the Authentication category, a 4.8/5 rating from 1,483 reviews, and was last updated Sep 10, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v3.3.8 Current Version v3.3.8
Updated 5 days ago Last Update on 10 Sep, 2026
Refreshed 9 hours ago Last Refreshed on
#4 of 1,575 in Authentication Top 1% by installs Downloads -47.2% this week Actively maintained
View on WordPress.org
Rank
#33
No change
Active Installs
1M+
-47.9%
KW Avg Position
3
No change
Downloads
82M
+19,409 today
Support Resolved
52%
No change
Rating
96%
Review 4.8 out of 5
4.8 (1,483 reviews)

Next Milestone 2M

Total Progress 89.7%
1M+ 2M+
4
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 102,565 more installs to reach 2M+

Rank Changes

13 23 33 43 53 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
13 23 33 43 53 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Current #33
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 100K 200K 300K 400K 500K 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
0 100K 200K 300K 400K 500K 600K 700K 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.8
1,483 reviews
Overall 96%
5
1,397 (94%)
4
31 (2%)
3
8 (1%)
2
10 (1%)
1
37 (2%)

Support Threads Overview

Resolved
Unresolved
23
Total Threads
12
Resolved
11
Unresolved
52%
Resolution Rate

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners, including WooCommerce store owners, membership sites, agencies, and multisite networks, who need to secure their login pages. It solves the problem of brute force, bot, and credential stuffing attacks by limiting failed login attempts, blocking malicious IPs, and adding two-factor authentication and firewall protection.

  • Limit login attempts by IP/username
  • Built-in two-factor authentication (2FA)
  • Firewall and bot protection
  • XML-RPC protection
  • WooCommerce login protection
  • IP and username safelist/denylist
  • Failed login attempt logs
  • Multisite support

Frequently Asked Questions

Common questions about Limit Login Attempts Security - Login Security, 2FA, Firewall, Brute Force Prevention

If you are using contemporary hosting, it's likely your site uses a proxy domain service like CloudFlare, Sucuri, Nginx, etc. They replace your user's IP address with their own. If the server where your site runs is not configured properly (this happens a lot) all users will get the same IP address. This also applies to bots and hackers. Therefore, locking one user will lead to locking everybody else out. If the plugin is not using our Cloud App, this can be adjusted using the Trusted IP Origin setting. The cloud service intelligently recognizes the non-standard IP origins and handles them correctly, even if your hosting provider does not.
An easy way to check if the attack is legitimate is to copy the IP address from the lockout notification and check its location using a IP locator tool. If the location is not somewhere you recognize and you have received several failed login attempts, then you are likely being attacked. You might notice dozens or hundreds of IPs each day. Visit our website to learn how can you prevent brute force attacks on your website.
After you upgrade to our premium version, you will see a new dashboard in your WordPress admin that shows all attacks that will now relay through our cloud service. On the graph, you'll see requests and failed login attempts. Each request will represent the cloud app validating an IP, which also includes denied logins. In some cases, you may notice an increase in speed and efficiency with your website. Also, a reduction in lockout notifications via email.
Some users find it hard to believe that they could experience numerous unsuccessful login attempts, particularly when their site has just been established or has minimal human traffic. The plugin is not responsible for generating these failed login attempts. Newly created websites are frequently hosted on shared IP addresses, making it easy for hackers to discover them. Additionally, newly registered domain names are often crawled soon after creation, rendering a WordPress website susceptible to attacks. Such websites are attractive targets as security is not a primary concern for their owners. We've created an article that delves deeper into the issue of fake login attempts in WordPress.
The premium plan’s resource limits start from 100,000 requests per month, which should accept almost any heavy brute-force attack. We monitor all of our sites and will alert the user if it appears they are going over their limits. If limits are reached, we will suggest to the user upgrading to the next plan. If you are using the free version, the load caused by brute force attacks will be absorbed by your current hosting bandwidth, which could cause your hosting costs to increase.
The URLs being protected are your login page (wp-login.php, wp-admin), xmlrpc.php, WooCommerce login page, and any custom login page you have that uses regular WordPress login hooks.
Our main focus is protecting your site from brute force attacks. This allows our plugin to be very lean and effective. It doesn’t require a lot of your web hosting resources and keeps your site well-protected. More importantly, it does all of this automatically as our service learns on its own about each IP it encounters. In contrast, a firewall would require manual blocking of IPs.
Open the site from another IP. You can do this from your cell phone, or using Opera browser and enabling free VPN there. You can also try turning off your router for a few minutes and then see if you get a different IP address. These will work if your hosting server is configured correctly. If that doesn’t work, connect to the site using FTP or your hosting control panel file manager. Navigate to wp-content/plugins/ and rename the limit-login-attempts-reloaded folder. Log in to the site then rename that folder back and whitelist your IP. By upgrading to our premium app, you will have the unlocking functionality right from the cloud so you’ll never have to deal with this issue.
The settings are explained within the plugin in great detail. If you are unsure, use the default settings as they are the recommended ones.
By default, you will need to copy and paste the lists to each site manually. For the premium service, sites are grouped within the same private cloud account. Each site within that group can be configured if it shares its lockouts and access lists with other group members. The setting is located in the plugin's interface. The default options are recommended.

More plugins by WPChef

Sign In / Register

You need to sign in or register to use this feature.