For WordPress
GitHub
Home Modules Documentation FAQ Download
Docs Login Security

Login Security

Comprehensive login protection including attempt limiting and customization.

Overview

Comprehensive login protection including attempt limiting, customization, and brute-force prevention.

Features

FeatureDescription
Login Attempt LimitingLockout after X failed attempts
IP-Based TrackingUses transients for lockout data
XML-RPC Auth DisableBlock authentication via XML-RPC
App Passwords DisablePrevent API key generation
Generic Error MessagesHide whether username exists
Custom Login LogoReplace WordPress logo
Custom Login ColorsBackground and form styling
Lockout LoggingTrack blocked IPs and usernames

Configuration

OptionDefaultDescription
max_attempts5Attempts before lockout
lockout_duration15Lockout duration in minutes
disable_xmlrpc_authtrueBlock XML-RPC authentication
hide_login_errorstrueShow generic error messages