62 Quality Score
Active Installs
17/30

At 6,000 active installs the plugin sits in a niche used by a small group of developers rather than the general WordPress market, which is reflected in the modest popularity score of 56.

Update Freshness
14/25

The plugin was updated on 2025-07-22 and is tested against WordPress 6.8.5, and despite a 0.0% support resolution rate the maintenance score lands at a middling 67.

User Rating
13/15

The 84/100 rating from 6 reviewers is strong, but the small sample size means this is anecdotal signal rather than a reliable trend.

Support Health
8/15

With zero threads opened and zero resolved, support health is impossible to judge either way and the plugin scores only 50 here.

WP Compatibility
11/15

Testing against WordPress 6.8.5 and requiring only PHP 5.6 or WordPress 3.5 keeps the compatibility bar very low, earning a 75.

Scores higher than 11% of indexed plugins

About

Provides comprehensive security during development by protecting your entire site and your admin pages from brute-force attacks.

Active Installs 6k+
Rating ★★★★ 4.2/5
Last Updated 2025-07-22 2:25pm GMT
Requires WordPress 3.5+
Tested Up To 6.8.8
Requires PHP 5.6+

Security History

1 known vulnerability, all patched
1 Medium

Most recent: July 26, 2023

View details ▸

Powered by Wordfence Intelligence

What It Does

HTTP Auth puts your entire WordPress site behind a web server-level username and password prompt, which means visitors must authenticate before any WordPress code runs. It works at the HTTP layer (Basic Auth or similar), not through WordPress's own login system, so it is particularly useful for blocking crawlers and brute-force bots from reaching the login page at all. An exemption or cookie-based bypass can be configured so you do not lock yourself out.

Who It's For

This plugin is built for developers and agencies who need to lock down staging sites, work-in-progress builds, or pre-launch client work where the public should not see anything until launch day. It is also a good fit for a small team that wants a no-friction way to password-protect the entire site during development without configuring server-level .htpasswd rules manually. Non-technical users running production sites should look elsewhere, as this is squarely a development-stage tool.

Who Should Skip It

If you run a live production site that the public needs to access, this plugin offers no value and will lock out every visitor. Anyone wanting login-specific brute-force protection on a public site should pick a dedicated login firewall such as Limit Login Attempts Reloaded instead.

The Bottom Line

HTTP Auth does one focused job, putting the whole site behind an HTTP password, and it does that job at a quality score of 65.2/100 with minimal features and no track record of community support. It is a reasonable, simple choice for staging and pre-launch protection but is the wrong tool the moment you go live or want real brute-force analytics. For most production WordPress sites one of the alternatives above will serve you better.

Tags

brute attack Brute Force http auth prevent-crawl restrict site