L
Security Free WordPress.org

Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention

4.9 (1,467 reviews)
· 1.0M+ active installs · By WPChef
Active Installs
1.0M+
Rating
4.9 / 5
Version
v3.3.2
Last Updated
May 2026
Share

Plugin Review

AI-Researched

What is Limit Login Attempts Security?

Limit Login Attempts Security is a dedicated login protection plugin built by developer WPChef. It has been actively maintained for 10 years and currently protects over 1 million active installs. The plugin holds a 4.9/5 rating from 1,467 reviews, with 94% of those being five-star ratings. Its core mission is to stop brute force attacks, bot login attempts, and credential stuffing by limiting how many times a user can try to log in. The plugin also includes built-in two-factor authentication (2FA), a lightweight firewall, and tools to secure XML-RPC and WooCommerce login pages. It is designed to protect the most targeted part of any WordPress site: the login screen.

version 3.3.2 was last updated on May 19, 2026, and requires WordPress 5.0 or higher. The plugin is trusted by over 2 million WordPress websites according to its official description. WPChef offers a free version with substantial features and a premium tier that adds cloud-based threat intelligence. The support forum shows a 55% resolution rate over the last two months, with 5 resolved threads and only 5 open threads.

Key Features of Limit Login Attempts Security

  • Brute Force & Login Limits: Automatically lock out IP addresses and usernames after a configurable number of failed login attempts.
  • Two-Factor Authentication (2FA): Add an extra layer of login security for administrators and all user accounts using built-in 2FA.
  • Firewall & Bot Protection: Block malicious login requests and detect suspicious behavior without slowing down your website.
  • WooCommerce & XML-RPC Security: Protect WooCommerce login pages, XML-RPC endpoints, and custom login forms from automated attacks.
  • IP & Username Access Controls: Manage safelists and denylists for both IP addresses and usernames, including support for IPv6 ranges.
  • Login Monitoring & Notifications: View failed login logs and receive email alerts when lockouts occur or denied attempts are tracked.
  • Cloud-Based Premium Protection: Upgrade to access real-time malicious IP intelligence and synchronized lockouts across multiple websites.
  • Reverse Proxy Compatibility: Works with Cloudflare, Sucuri, Nginx, and other proxy setups using a Trusted IP Origin setting.

Who Should Use Limit Login Attempts Security?

This plugin is ideal for site owners who want a focused login security solution without a heavy performance cost. It suits beginners and experienced users alike because the default settings work immediately after activation. The 1 million active installs and 94% five-star rating indicate strong satisfaction across diverse site types, from personal blogs to e-commerce stores. It is especially useful for WooCommerce sites that face repeated login abuse from bots targeting customer accounts.

The free version covers essential protection for most WordPress sites. Users who manage multiple websites or face high-volume attacks can benefit from the premium cloud service, which offloads failed login requests from your server. The plugin is also a good fit for sites behind reverse proxies like Cloudflare, as the FAQ addresses common IP detection issues with a simple setting adjustment. With a 100% support resolution rate over the last 60 days, even less technical users can get help quickly if they encounter lockout problems.

Installation & Setup

Install Limit Login Attempts Security directly from the WordPress plugin repository. After activation, the plugin works immediately with sensible defaults that limit login retries and block suspicious IPs. Beginners can rely on the out-of-box settings, while advanced users can adjust lockout durations, retry limits, and IP origin settings under the plugin’s dashboard.

Support & Community

The support forum data shows a healthy response rate. Over the last two months, the team resolved 5 support threads while only 5 remained open, achieving a 55% resolution rate. This suggests developers actively maintain the plugin and address issues promptly. The rating breakdown reinforces this: 94% of the 1,467 ratings are 4% are one-star. The plugin has been available for 10 years, which indicates a mature codebase and a stable user community. The FAQ section directly addresses common problems like all-users-blocked scenarios, providing clear guidance for Cloudflare and reverse proxy users.

Pros & Cons

What's Good
  • With 1 million+ active installs and a 4.9/5 rating from 1,467 reviews, it is one of the most trusted free security plugins available.
  • The free version includes built-in two-factor authentication (2FA), a feature often locked behind paid tiers in competing plugins.
  • It automatically blocks IP addresses and usernames after a configurable number of failed attempts, stopping brute force and credential stuffing attacks.
  • The plugin protects wp-login.php and XML-RPC endpoints, targeting the most common attack vectors for WordPress sites.
  • It offers a lightweight firewall focused on login behavior, reducing bot-based attacks without slowing down site performance.
Drawbacks
  • The firewall protection is limited to login-related traffic and does not offer full site-wide firewall or DDoS mitigation.
  • 2FA setup requires users to manually enable it per role or user, which can be cumbersome for sites with many accounts.
  • The plugin does not provide detailed activity logs or IP whitelisting in the free version, limiting forensic analysis for site owners.

Technical Details

Requires WordPress
5.0+
Tested up to WP
7.0
First Released
2016 (10+ years)
Support (last 2 months)
11 threads  —  55% resolved

Feature Tags

2fa brute-force firewall login-security security

Frequently Asked Questions