LoginPress – Limit Login Attempts is a lightweight WordPress security add-on that protects your site from brute-force attacks by limiting failed login attempts and blocking malicious IPs. It works seamlessly with LoginPress and core WordPress, offering smart lockouts, whitelisting, and detailed logs to keep your login page safe without slowing your site.
- Limit failed login attempts to stop brute-force attacks
- Automatic lockouts after configurable retry thresholds
- IP blocking and temporary lock durations
- Allowlist/denylist for trusted and suspicious IPs
- Detailed logs for attempts, IPs, usernames, and timestamps
- Customizable lockout messages and error notices
- Instant unlock or reset for locked users
- Supports LoginPress custom login pages
- Works with default WordPress login and wp-login.php
- GDPR-friendly data handling options
- Email alerts for repeated failed attempts
- reCAPTCHA compatibility for extra protection
- Lightweight, fast, and easy to configure
- Multisite and multilingual ready
- Compatible with popular caching and security plugins