Перейти к содержимому
WordPress.org

Русский

  • Темы
  • Плагины
  • Новости
    • Документация
    • Форумы
  • О WordPress
  • Сообщество
  • Скачать WordPress
Скачать WordPress
WordPress.org

Plugin Directory

Limit Login Attempts Security — Login Security, 2FA, Firewall, Brute Force Prevention

  • Отправить плагин
  • Мои избранные
  • Войти
  • Отправить плагин
  • Мои избранные
  • Войти

Limit Login Attempts Security — Login Security, 2FA, Firewall, Brute Force Prevention

Автор: WPChef
Скачать
  • Детали
  • Отзывы
  • Разработка
Поддержка

Описание

Protect your WordPress website against brute force attacks, bot attacks, and unauthorized login attempts with one of the most trusted login security plugins for WordPress.

Limit Login Attempts Security strengthens your WordPress login security by limiting failed login attempts, blocking malicious IPs, securing wp-login.php, protecting XML-RPC, and adding powerful firewall and 2FA protection without slowing down your website.

Trusted by 2 million WordPress websites, Limit Login Attempts Security is designed specifically to protect the most targeted part of your website: the login page.

Why Use Limit Login Attempts Security?

By default, WordPress allows unlimited login attempts. This creates a major security vulnerability where bots and attackers can repeatedly guess usernames and passwords until they gain access. This is especially important in the age of AI, where attackers now have access to faster and more sophisticated tools than ever before.

Limit Login Attempts Security helps stop:

  • Brute force attacks
  • Bot login attacks
  • Credential stuffing attacks
  • XML-RPC attacks
  • Unauthorized login attempts
  • WooCommerce login abuse
  • Malicious IP access attempts

The plugin automatically blocks excessive login attempts and locks out suspicious IP addresses and usernames before attackers can gain access.

Features Included in the Free Version

Login Security & Brute Force Protection

  • Limit login attempts by IP address and username
  • Automatically lock out suspicious login activity
  • Adjustable lockout duration and retry limits
  • Protect wp-login.php from automated attacks
  • Prevent brute force login attacks

2FA / Multi-Factor Authentication (MFA)

  • Built-in two-factor authentication (2FA)
  • Add an additional layer of login protection
  • Improve WordPress account security
  • Secure administrator and user logins

Firewall & Bot Protection

  • Block malicious login requests
  • Detect suspicious login behavior
  • Reduce bot-based login attacks
  • Lightweight firewall-focused login protection

WooCommerce & Plugin Compatibility

Protects:

  • WooCommerce login pages
  • XML-RPC login requests
  • Custom login pages
  • WordPress multisite installations

Compatible With:

  • Wordfence
  • Sucuri
  • Ultimate Member
  • MemberPress
  • WPS Hide Login
  • Cloudflare and reverse proxy setups

Login Monitoring & Notifications

  • Failed login attempt logs
  • Lockout email notifications
  • Denied attempt tracking
  • Login retry visibility for users

Access Controls

  • IP safelist and denylist support
  • Username safelist and denylist support
  • IPv6 range support
  • Custom IP origin configuration

Premium Features (Start Your Free 14 Day Trial)

Upgrade to Limit Login Attempts Security Premium to extend protection with cloud-based login security and advanced attack prevention.

Advanced Cloud Protection

  • Real-time malicious IP intelligence
  • Global denylist protection
  • Synchronized lockouts across websites
  • Auto IP denylist generation
  • Cloud-based login attack mitigation

Enhanced Performance Protection

  • Offload excessive failed login requests from your server
  • Reduce server strain during attacks
  • Improve stability under heavy attack conditions

Advanced Security Features

  • Country-based login blocking
  • Enhanced throttling and lockout escalation
  • Registration page protection
  • Successful login tracking
  • Enhanced lockout analytics and geolocation data

Multi-Site & Team Features

  • Shared safelist and denylist syncing
  • Shared lockout protection between domains
  • Cloud backups of IP security data
  • CSV exports of login and IP activity

Premium Support

  • Access to security-focused support specialists
  • Faster troubleshooting and assistance

Lightweight Security Built for WordPress

Unlike many large security suites, Limit Login Attempts Security focuses specifically on login security and brute force protection.

This means:

  • Faster performance
  • Less server overhead
  • Easier configuration
  • Strong protection without unnecessary bloat

Protect More Than Just wp-login.php

Limit Login Attempts Security secures:

  • wp-login.php
  • XML-RPC
  • WooCommerce logins
  • Custom login forms
  • Registration pages
  • Multisite logins

Trusted by Millions of WordPress Websites

Limit Login Attempts Security is one of the most widely used WordPress login security plugins and has helped protect millions of websites from brute force attacks and malicious login activity.

Whether you run:

  • A personal blog
  • WooCommerce store
  • Membership website
  • Агентство
  • Business website
  • Enterprise WordPress network

Limit Login Attempts Security helps secure your login experience with modern WordPress login protection.

Upgrading from the Original Limit Login Attempts Plugin?

Switching is easy:

  1. Remove the old Limit Login Attempts plugin
  2. Install Limit Login Attempts Security
  3. Your settings will remain intact

Translation Support

Currently translated into multiple languages including:

  • Испанский
  • Французский
  • Немецкий
  • Голландский
  • Турецкий
  • Шведский
  • Русский
  • Румынский
  • Китайский (традиционный)
  • Brazilian Portuguese
  • And more

Secure Your WordPress Login Today

Install Limit Login Attempts Security and protect your WordPress website with:

  • Login security
  • Two-Factor Authentication (2FA)
  • Brute force protection
  • Firewall security
  • Bot protection
  • XML-RPC protection
  • WooCommerce login protection

Без замедления работы вашего сайта.

Скриншоты

Часто задаваемые вопросы

Что мне делать, если все пользователи заблокированы?

If you are using contemporary hosting, it’s likely your site uses a proxy domain service like CloudFlare, Sucuri, Nginx, etc. They replace your user’s IP address with their own. If the server where your site runs is not configured properly (this happens a lot) all users will get the same IP address. This also applies to bots and hackers. Therefore, locking one user will lead to locking everybody else out. If the plugin is not using our Cloud App, this can be adjusted using the Trusted IP Origin setting. The cloud service intelligently recognizes the non-standard IP origins and handles them correctly, even if your hosting provider does not.

Как узнать, подвергаюсь ли я атаке?

An easy way to check if the attack is legitimate is to copy the IP address from the lockout notification and check its location using a IP locator tool. If the location is not somewhere you recognize and you have received several failed login attempts, then you are likely being attacked. You might notice dozens or hundreds of IPs each day. Visit our website to learn how can you prevent brute force attacks on your website.

Как определить, что премиум-плагин работает?

After you upgrade to our premium version, you will see a new dashboard in your WordPress admin that shows all attacks that will now relay through our cloud service. On the graph, you’ll see requests and failed login attempts. Each request will represent the cloud app validating an IP, which also includes denied logins.

В некоторых случаях вы можете заметить увеличение скорости и эффективности работы вашего сайта. Кроме того, уменьшится количество уведомлений о блокировке по электронной почте.

Могут ли эти неудачные попытки входа в систему быть поддельными?

Some users find it hard to believe that they could experience numerous unsuccessful login attempts, particularly when their site has just been established or has minimal human traffic. The plugin is not responsible for generating these failed login attempts. Newly created websites are frequently hosted on shared IP addresses, making it easy for hackers to discover them. Additionally, newly registered domain names are often crawled soon after creation, rendering a WordPress website susceptible to attacks. Such websites are attractive targets as security is not a primary concern for their owners. We’ve created an article that delves deeper into the issue of fake login attempts in WordPress.

Что произойдет, если мой сайт превысит установленные планом лимиты запросов?

Ограничения на ресурсы в премиум-плане начинаются от 100 000 запросов в месяц, что позволяет выдержать практически любую мощную брутфорс-атаку. Мы следим за всеми нашими сайтами и предупреждаем пользователя о превышении лимита. Если лимиты превышены, мы предложим пользователю перейти на следующий тарифный план. Если вы используете бесплатную версию, то нагрузка, вызванная атаками грубой силы, будет поглощаться текущей пропускной способностью хостинга, что может привести к увеличению стоимости хостинга.

Какие URL-адреса подвергаются атакам и защищаются?

Защищаемые URL-адреса — это страница входа в систему (wp-login.php, wp-admin), xmlrpc.php, страница входа в систему WooCommerce, а также любая пользовательская страница входа в систему, использующая обычные крючки входа в WordPress.

Почему плагин Limit Login Attempts Security пользуется большей популярностью, чем другие плагины защиты от брутфорс-атак?

Our main focus is protecting your site from brute force attacks. This allows our plugin to be very lean and effective. It doesn’t require a lot of your web hosting resources and keeps your site well-protected. More importantly, it does all of this automatically as our service learns on its own about each IP it encounters. In contrast, a firewall would require manual blocking of IPs.

Что делать, если администратор заблокирован?

Open the site from another IP. You can do this from your cell phone, or using Opera browser and enabling free VPN there. You can also try turning off your router for a few minutes and then see if you get a different IP address. These will work if your hosting server is configured correctly. If that doesn’t work, connect to the site using FTP or your hosting control panel file manager. Navigate to wp-content/plugins/ and rename the limit-login-attempts-reloaded folder. Log in to the site then rename that folder back and whitelist your IP. By upgrading to our premium app, you will have the unlocking functionality right from the cloud so you’ll never have to deal with this issue.

Какие настройки я должен использовать в плагине?

Настройки подробно описаны в плагине. Если вы не уверены, используйте настройки по умолчанию, так как они рекомендуются.

Can I share the safelist/denylist throughout all of my sites?

By default, you will need to copy and paste the lists to each site manually. For the premium service, sites are grouped within the same private cloud account. Each site within that group can be configured if it shares its lockouts and access lists with other group members. The setting is located in the plugin’s interface. The default options are recommended.

Отзывы

blocked so many bots

riana71 20.05.2026
was getting sm spammy login attempts lately. installed this & it instantly blocked the bots. love that it shows who is trying to get in cz now i feel way safer. literally a lifesaver

très efficace et rassurant

mcaudibert 04.05.2026
Permet d’être informé des tentatives de connexion et de réajuster le niveau de protection … Très simple d’utilisation et très sécurisant

Great plugin

tonyburgess100 28.04.2026
Brilliant plugin, great to know that internet users determined to hack your site are stopped from maliciously accessing. I think this is an essential plugin for all wordpress admin.

Very glad to have this

plannerk 28.04.2026
There seem to be plenty of folks who have nothing better to do than try logging into random sites. If they really like that kind of things, become a certified pen tester. LOTS of good paying jobs there.

it works

nasy8 28.04.2026 1 ответ
good plugin and works well expert, too forcing to get rate.

Works but Annoying

hunterfox3 21.04.2026 1 ответ
It does protect login with limits, so that part is good. But got some false lockouts which was a bit frustrating. Setup is ok, just needs better control 👍
Посмотреть все 1 454 отзыва

Участники и разработчики

«Limit Login Attempts Security — Login Security, 2FA, Firewall, Brute Force Prevention» — проект с открытым исходным кодом. В развитие плагина внесли свой вклад следующие участники:

Участники
  • WPChef
  • nikita.global

«Limit Login Attempts Security — Login Security, 2FA, Firewall, Brute Force Prevention» переведён на 36 языков. Благодарим переводчиков за их работу.

Перевести «Limit Login Attempts Security — Login Security, 2FA, Firewall, Brute Force Prevention» на ваш язык.

Заинтересованы в разработке?

Посмотрите код, проверьте SVN репозиторий, или подпишитесь на журнал разработки по RSS.

Журнал изменений

3.2.4

  • Added compatibility with WordPress 7.

3.2.3

  • Broadened MFA state cookie scope to the site root for wider path coverage.
  • Fixed Active Lockouts counter not showing on the local Logs page.

3.2.2

  • Improved MFA rescue link compatibility on hosts with external object cache enabled.

3.2.1

  • Fixed rescue link behavior and updated the format.
  • 2FA is pre-selected for administrators; when no user groups are selected, 2FA stays disabled.

3.2.0

  • Improved WooCommerce registration protection in cloud mode.
  • Refactored third-party integrations into a unified architecture (WooCommerce, MemberPress).

3.1.0

  • Added technical details to the network issue notice.
  • Fixed logo rendering in Gmail MFA notifications.
  • Improved local risk indicator thresholds and refactored rendering.
  • Improved compatibility with WPS Hide Login, WooCommerce, and MemberPress login flows; added WooCommerce cloud registration checks.

3.0.2

  • Hardened admin tab parameter (whitelist, strict checks) before loading tab views.
  • Onboarding: redirect to Dashboard when setup is incomplete and a tab other than Dashboard is opened.
  • Failed-login email subject: numbered placeholders for translation-friendly word order (e.g. for Dutch).
  • Onboarding popup: hide body scroll while open, restore on close; focus modal content.

3.0.1

  • Hardened MFA security.
  • MFA UI improved.
  • Refactored the codebase.

Earlier versions

For the changelog of earlier versions, please refer to the changelog.txt file.

Мета

  • Версия 3.2.4
  • Обновление: 22 часа назад
  • Активных установок: 1+ млн
  • Версия WordPress 5.0 или выше
  • Совместим вплоть до: 7.0
  • Языки

    Asturian, Catalan, Chinese (China), Chinese (Taiwan), Czech, Danish, Dutch, Dutch (Belgium), English (Australia), English (Canada), English (New Zealand), English (South Africa), English (UK), English (US), French (Canada), French (France), Galician, German, Italian, Japanese, Korean, Norwegian (Bokmål), Persian, Polish, Portuguese (Brazil), Portuguese (Portugal), Romanian, Russian, Spanish (Chile), Spanish (Colombia), Spanish (Ecuador), Spanish (Mexico), Spanish (Spain), Spanish (Venezuela), Swedish, Turkish и Ukrainian.

    Перевести на ваш язык

  • Метки:
    2FABrute Forcefirewalllogin securitysecurity
  • Дополнительно

Оценки

4.9 из 5 звёзд.
  • 1 374 5-звездный отзыв 5 звёзд 1 374
  • 29 4-звездный отзыв 4 звезды 29
  • 7 3-звездный отзыв 3 звезды 7
  • 10 2-звездный отзыв 2 звезды 10
  • 34 1-звездный отзыв 1 звезда 34

Your review

Посмотреть всеотзывы

Участники

  • WPChef
  • nikita.global

Поддержка

Решено проблем за последние 2 месяца:

8 из 8

Перейти в форум поддержки

Пожертвование

Хотите поддержать улучшение этого плагина?

Пожертвовать на развитие плагина

  • О нас
  • Новости
  • Хостинг
  • Приватность
  • Витрина
  • Темы
  • Плагины
  • Паттерны
  • Обучение
  • Поддержка
  • Разработчики
  • WordPress.TV ↗
  • Присоединиться
  • События
  • Поддержать ↗
  • Пять для будущего
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Русский

  • Посетите нас в X (ранее Twitter)
  • Посетите нашу учётную запись в Bluesky
  • Посетите нашу ленту в Mastodon
  • Посетите нашу учётную запись в Threads
  • Посетите нашу страницу на Facebook
  • Посетите наш Instagram
  • Посетите нашу страницу в LinkedIn
  • Посетите нашу учётную запись в TikTok
  • Посетите наш канал YouTube
  • Посетите нашу учётную запись в Tumblr
Код — это поэзия.
The WordPress® trademark is the intellectual property of the WordPress Foundation.