Login Lockdown & Protection icon

Login Lockdown & Protection

by WebFactory

View on WordPress.org
83 Quality Score
Active Installs
23/30

75 active installs per 30 points is modest, but 100,000 installs shows real-world traction for a single-purpose utility.

Update Freshness
25/25

100 is a perfect score, with an update released in April 2026 and tested against WordPress 7.0, which signals an actively maintained codebase.

User Rating
13/15

An 86 average from 60 ratings is solid, though the small sample size means the score can shift quickly with a few new reviews.

Support Health
8/15

50 is the weakest dimension: zero support threads resolved out of zero opened, which is fine in volume but tells us nothing about how the author responds when users do ask questions.

WP Compatibility
15/15

100 is warranted, with a minimum of WordPress 4.0 and PHP 5.2, meaning it will run on virtually any host still serving WordPress.

Scores higher than 90% of indexed plugins

About

Protect, lockdown & secure login form by limiting login attempts from the same IP & banning IPs.

Active Installs 100k+
Rating ★★★★ 4.3/5
Last Updated 2026-08-16 1:32pm GMT
Requires WordPress 4.0+
Tested Up To 7.1
Requires PHP 5.2+

Security History

5 known vulnerabilities, all patched
1 High 4 Medium

Most recent: December 12, 2025

View details ▸

Powered by Wordfence Intelligence

What It Does

Login Lockdown & Protection limits how many login attempts a single IP address can make within a set window, locking out or banning IPs that exceed the threshold. It is a straightforward IP-based brute-force defence for the default WordPress login screen, not a full security suite. The plugin does not include malware scanning, firewall rules, or two-factor authentication.

Who It's For

This plugin suits small site owners who want a lightweight, set-and-forget layer against password guessing attacks without the complexity of a full security stack. It fits blogs, small business sites, and membership sites running standard WordPress logins where the only realistic threat vector is credential stuffing on /wp-login.php.

Who Should Skip It

Anyone already running Wordfence, AIOS, or a host-level firewall (such as Cloudflare) does not need this, since brute-force protection is already bundled. Sites that require CAPTCHA challenges, 2FA, or country-based access control should look at alternatives, as this plugin does not provide those features.

The Bottom Line

At an overall score of 82.79, Login Lockdown & Protection does one job, IP-based login throttling, and does it on a maintained, modern WordPress install footprint. The lack of any meaningful support track record and the absence of broader security features keep it from competing with Wordfence or AIOS, but as a cheap, simple brute-force stopper it is genuinely useful. Not a replacement for a full security plugin, but a reasonable add-on or starter choice for low-stakes sites.

Tags

block login captcha firewall login protect login