WP Limit Login Attempts icon

WP Limit Login Attempts

by Arshid

View on WordPress.org
79 Quality Score
Active Installs
18/30

Popularity scores modestly at 60/30 because 10,000 active installs is meaningful but small compared to million-install alternatives like Loginizer or WPS Hide Login.

Update Freshness
25/25

Maintenance earns a full 100/25, reflecting a recent update on 2026-05-20 and tested compatibility with WordPress 7.0.

User Rating
14/15

User ratings are strong at 92/15, based on 300 reviews indicating consistent satisfaction among current users.

Support Health
8/15

Support health lands at 50/15 because there are zero support threads and zero resolutions, leaving no track record of responsive help.

WP Compatibility
15/15

Compatibility scores 100/15 thanks to tested support through WordPress 7.0 and a low PHP 5.6 floor that works on most hosts.

Scores higher than 73% of indexed plugins

About

Limit rate of login attempts and block IP temporarily. Brute force attack protection. GDPR compliant. Captcha enabled.

Active Installs 10k+
Rating ★★★★½ 4.6/5
Last Updated 2026-09-15 8:44am GMT
Requires WordPress 6.0+
Tested Up To 7.1
Requires PHP 5.6+

Security History

2 known vulnerabilities, all patched
1 Critical 1 Medium

Most recent: December 27, 2022

View details ▸

Powered by Wordfence Intelligence

What It Does

WP Limit Login Attempts throttles and blocks repeated failed login attempts by IP address, helping protect WordPress login pages from automated brute force attacks. It offers CAPTCHA support and positions itself as GDPR compliant by avoiding the storage of personally identifiable data. In practical terms, it adds a defensive lockout layer on top of the default wp-login.php screen.

Who It's For

This plugin suits small business owners, membership site operators, and administrators of healthcare, legal, and financial sites who want a straightforward brute force defence without installing a heavy security suite. It is a reasonable fit for sites that need login hardening but do not want to manage a full firewall or malware scanner.

Who Should Skip It

Site owners already running a full-featured security suite such as SG Security or Security Ninja should skip this plugin since login throttling is built in. Anyone needing 2FA, country-based blocking, or detailed security logs will also find this tool too narrow in scope.

The Bottom Line

WP Limit Login Attempts is a focused, well-maintained tool with an overall score of 79.21, strong ratings, and a confusingly empty support queue that should make buyers cautious. It does one job reliably but lacks the depth, community proof, and ecosystem of alternatives like Loginizer. Recommended only if you want a lightweight throttling layer and have no support expectations.

Tags

authentication limit login login