WordPress.org
  • News
  • Showcase
  • Hosting
    • Themes
    • Plugins
    • Patterns
    • Blocks
    • Openverse ↗︎
    • Learn WordPress
    • Documentation
    • Forums
    • Developers
    • WordPress.tv ↗︎
    • Make WordPress
    • Photo Directory
    • Five for the Future
    • Events
    • Job Board ↗︎
    • About WordPress
    • Enterprise
    • Gutenberg ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Login Lockdown & Protection

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Login Lockdown & Protection

By WebFactory
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Login Lockdown records the IP address and timestamp of failed login attempts. If more than a selected number of attempts are detected within a set period of time from the same IP, then the login is disabled for all requests from that IP address (or the IP is completely blocked from accessing the site). This secures the site and helps prevent brute force password attacks & discovery.

The plugin defaults to a 1 hour lock out of an IP block after 3 failed login attempts within 5 minutes. This can be modified in options. Administrators can release locked out IPs manually from the panel. A detailed log is available for all failed login attempts and all IP locks to control lockdown.

Configure the plugin from Settings – Login Lockdown.

Country blocking (PRO feature)

Block unwanted countries from accessing the site, or block them from being able to log in. Display a custom message to blocked visitors so they know why they can’t access the site.

Captcha

The simplest way to get rid of bots and brute-force password attacks. Choose from 5 different versions – built-in one, two from Google (PRO feature), Cloudflare Turnstile, and hCaptcha (PRO feature). Built-in captcha is GDPR compatible.

2FA – Two Factor Authentication (PRO feature)

Provide an extra layer of security without 2FA code generating apps such as Google Authenticator. Even if somebody knows your username & password they won’t be able to log in because it needs to be confirmed by clicking a unique link sent to your email. Since you’re the only one that has access to your inbox, you’ll never get hacked.

Cloud Protection (PRO feature)

Manage IP Whitelists and Blacklists in your Login Lockdown Dasard (a SaaS service for managing all your sites) and apply them to protect all the sites you manage from a single location.

Temporary Access (PRO feature)

Give temporary access to other people without giving them a username & password. Set the lifetime of the link and the maximum number of times it can be used to prevent abuse. Access level rights can be any you pick – admin, editor, author…

Screenshots

  • Protect the login form by banning IPs with multiple failed login attempts
  • Activity shows all failed login attempts and currently banned IPs
  • Country blocking (PRO feature) allows you to block selected countries from accessing the site

Installation

  1. Extract the zip file into your plugins directory into its own folder.
  2. Activate the plugin in the Plugin options.
  3. Customize the settings from Settings – Login Lockdown panel.

FAQ

How to disable this plugin?

Just use standard Plugin overview page in WordPress admin section and deactivate it; or rename the plugin folder /wp-content/plugins/login-lockdown/ using FTP access.

Will it slow my site down?

No, it won’t. The majority of the code is only run when logging in.

How can I report security bugs?

You can report security bugs through the stack Vulnerability Disclosure Program. The stack team help validate, triage and handle any security vulnerabilities. Report a security vulnerability.

Reviews

Free but total adware

Foliovision: Making the web work for you February 22, 2024
WP Login Lockdown is free. At one point it did its work discreetly. It now auto installs a huge widget in the admin dasard. In the back it covers the entire interface with huge ads. Almost all of the functionality is now pro and is front row and center, with an interface so covered in pro functions it’s impossible use the free plugin. Frankly this kind of simple functionality should not require a pro plugin at all. A sad example of the slow degradation of the wonderful WordPress developer community into adware and bloatware. Should mark WP Login Lockdown two stars really, but will leave it at three stars as it could be useful if way trimmed back again.

Awesome Plugin, Saved My Servers!

jonahcoyote January 24, 2024 1 reply
This plugin works wonders to protect your WordPress website from brute force attacks. It literally saved my servers where before implementing I had high CPU and memory usage and after installing it cut CPU use by up to 100% and memory by 50%. It’s not perfect and still has some areas to improve (reporting & unblocking are two) but the core functionality works really really well. HIGHLY RECOMMENDED!

Things have started that aren’t quite finished

johnyyw November 25, 2023
The plugin looks promising, but things have started that aren’t quite finished… 1) Captcha – It doesn’t show captcha at “lost password”, “woocommerce product comment”, probably somewhere else and no option to enable or simple to show everywhere.. It shows only at login form.. 2) 2FA – Two Factor Authentication. There is only email 2FA.. this plugin did not offer the option with “2FA code generating apps such as Google Authenticator, Authy”.. which is very sad.. I always use 2FA code generating apps for everything, and I will never use 2FA email authentication by choice! It seems that the author is working on too many projects and this particular one doesn’t have too much time to make the plugin really great! These are the reasons why I don’t use this plugin, if they improve it with this and more other functions, I will give it a chance and install it again. Currently only 3 stars! ★★★✩✩

“Unknown” login attempts after installation

marcioshibukawa July 20, 2023
After I installed the plugin, I started getting login attempts by the user “Unknown” (on the 3 sites I installed), detected by Wordfence. This is why I changed the login path through the plugin, so in theory, only they could know the login address.

Great security, updated with new features, responsive support

Jim Krenz June 24, 2023
Thus far, I am very happy with the pro version of Login Lockdown. It is not flawless, but the developers are responsive, and they are improving and updating the software regularly. Worth the money for pro!

Great plugin

tatof May 30, 2023
Plugin makes your website really safer. Easy to setup and many options. Edit: They fixed the bug! 🙂 back to 5 stars!!! ————————————————- Old review: If you login and forget to fillout the recaptcha or fill it out wrongly it will log you as “failed” attempt and show your password in the log list. This way every admin that can see the settings will know your password. There is no need to show the failed login attempt password. Please remove this terrible function. Big data . 1 star until they fix this.
Read all 58 reviews

Contributors & Developers

“Login Lockdown & Protection” is open source software. The following people have contributed to this plugin.

Contributors
  • WebFactory

“Login Lockdown & Protection” has been translated into 8 locales. Thank you to the translators for their contributions.

Translate “Login Lockdown & Protection” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

v2.12

  • 2025/05/02
  • security fixes
  • import/export function removed due to security issues

v2.11

  • 2024/07/08
  • minor security fixes

v2.10

  • 2024/05/18
  • made more strings translatable

v2.09

  • 2024/02/09
  • security fix

v2.08

  • 2023/12/09
  • security/fatal error fix

v2.07

  • 2023/11/19
  • security fix

v2.06

  • 2023/05/11
  • minor bug fixes

v2.05

  • 2023/05/09
  • bug fix – IP wasn’t showing in lockdowns and log tables

v2.02

  • 2023/04/24
  • fixed a few captcha bugs
  • added captcha verification when activating it in admin

v2.0

  • 2023/04/18
  • new codebase
  • new GUI
  • new features
  • added captcha
  • introduced PRO version

v1.83

  • 2022/10/04
  • fixed timezone bug

v1.82

  • 2022/09/23
  • WebFactory took over development
  • a full rewrite will follow soon, for now we ed some urgent things
  • prefixed function names that are in global namespace
  • properly escaped all inputs

v1.0

  • 2007/08/29
  • initial release

Meta

  • Version 2.12
  • Last updated 1 week ago
  • Active installations 100,000+
  • WordPress version 4.0 or higher
  • Tested up to 6.8.1
  • PHP version 5.2 or higher
  • Languages

    Dutch, Dutch (Belgium), English (US), Galician, Japanese, Russian, Spanish (Chile), Spanish (Spain), and Swedish.

    Translate into your language

  • Tags
    block logincaptchafirewallloginprotect login
  • Advanced View

Ratings

4.3 out of 5 stars.
  • 47 5-star reviews 5 stars 47
  • 0 4-star reviews 4 stars 0
  • 4 3-star reviews 3 stars 4
  • 0 2-star reviews 2 stars 0
  • 8 1-star reviews 1 star 8

Add my review

See all reviews

Contributors

  • WebFactory

Support

Issues resolved in last two months:

4 out of 4

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org
  • Visit our Facebook page
  • Visit our X (formerly Twitter) account
  • Visit our Mastodon account
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our YouTube channel
Code is Poetry