S
by webvitalii 4.3 (11 reviews)

Security-Protection

Protection from login, registration and reset-password brute-force attacks. No captcha.

Security-Protection ranks #9,920 among WordPress.org plugins with 400+ active installations, is #255 of 1,584 in the Authentication category, a 4.3/5 rating from 11 reviews, and was last updated Sep 5, 2020. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 5.5 (Current: 7.1)
v2.3 Current Version v2.3
Updated 6 years ago Last Update on 05 Sep, 2020
Refreshed 9 hours ago Last Refreshed on
#255 of 1,584 in Authentication Top 25% by installs No update in over a year
View on WordPress.org
Rank
#9,920
-8 this week
Active Installs
400+
-8.9%
KW Avg Position
17
No change
Downloads
15.4K
+4 today
Support Resolved
0%
No change
Rating
86%
Review 4.3 out of 5
4.3 (11 reviews)

Next Milestone 500

Total Progress 34%
400+ 500+
698
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 66 more installs to reach 500+

Rank Changes

9,907 9,913 9,919 9,924 9,930 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
9,866 9,883 9,900 9,916 9,933 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
Current #9,920
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
0 10 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.3
11 reviews
Overall 86%
5
9 (82%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
2 (18%)

Security History

Source: WPVulnerability

No known vulnerabilities on record for Security-Protection. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners who want to stop brute-force login attacks without inconveniencing users. It blocks brute-force attempts on login, registration, and password-reset forms without using captchas or configuration options.

  • Blocks login brute-force attacks
  • Blocks registration brute-force attacks
  • Blocks reset-password brute-force attacks
  • No captcha required
  • No configuration options

Frequently Asked Questions

Common questions about Security-Protection

The blocking algorithm is based on 2 methods: 'invisible js-captcha' and 'invisible input trap'. The 'invisible js-captcha' method is based on fact that bots does not have javascript on their user-agents. The 'invisible input trap' method is based on fact that almost all the bots will fill inputs with name 'email' or 'url'.
Two extra hidden fields are added to login, register and reset-password forms. First field is the invisible captcha (copy and paste the code). Second field should be empty. If the user visits site, than first field is answered automatically with javascript, second field left blank and both fields are hidden by javascript and css and invisible for the user. If the brute-forcer tries to submit the form, he will make a mistake with answer on first field or tries to submit an empty field and brute-force attack will be automatically rejected.
If Security-Protection check was not passed than it is brute-force request and the login attempt (or registration, or reset password) is blocked even if username and password are correct. Plugin sends fake WordPress login cookies to the brute-force bot and redirects it to the admin section to emulate that the password is cracked and many brute-forcers stop their attacks after this. It is really awesome :)
You may enable sending info about blocked brute-force attacks to admin email. Edit security-protection.php file and find "$secprot_send_brute_force_log_to_admin" and make it "true".
If all plugins does not help you to stop brute-force attacks - you can simply rename wp-login.php file (for example 'wp-login-new.php') for now and maybe this can help you to reduce load on your site. And also create empty wp-login.php file for not raising WordPress 404 error because it will start whole WordPress site again during each wp-login.php access. While wp-login.php renamed - users cannot login, register and reset password. If you want to have ability to login while you renamed wp-login.php file you should replace all 'wp-login.php' strings inside of the wp-login.php file to your new filename (for example 'wp-login-new.php').

More plugins by webvitalii

Sign In / Register

You need to sign in or register to use this feature.