Brute-force protection for WordPress

Failed logins earn escalating lockouts, blockable usernames waste a guessing script's attempts, and an emergency recovery URL ensures you can always get back in.

Login notifications and digest emails are Pro.

4
failed attempts before the first lockout (default, adjustable)
10 min
default lockout, escalating for repeat offenders
12 h
until failed-attempt counters reset (default)
Recovery URL
an emergency address that always lets the real owner in

What it does

Password-guessing scripts rely on unlimited tries. This module makes every failed attempt cost something: after a handful of failures the account is locked out, and continued failures earn progressively longer lockouts.

The part most lockout plugins get wrong is the owner's escape hatch. Ultimate Security keeps a recovery URL: an emergency address that lets you back in even if an attacker has burned through the attempt limit on your username.

How it works

Out of the box: four failed logins trigger a ten-minute lockout, six further failures escalate to a longer one, and counters reset after twelve hours of quiet. Every number is adjustable.

You can also block specific usernames outright ("admin" being the classic) so guessing scripts waste their attempts on accounts that can never log in.

  • Escalating lockouts with adjustable thresholds
  • Blockable usernames
  • Emergency recovery URL for the site owner

Free today, deeper with Pro

Pro adds the visibility layer: email notifications when lockouts happen and digest summaries of login activity.

Documentation

Login attempts

Thresholds, lockouts and counter resets.

Read the guide →

Locked users

See and release active lockouts.

Read the guide →

Lockout notifications (Pro)

Get told when lockouts fire.

Read the guide →

Login notifications (Pro)

Alerts and digests for login activity.

Read the guide →

Brute-force protection questions

Can I lock myself out?

The recovery URL exists exactly for this. It always lets the site owner back in. As a last resort, renaming the plugin folder over SFTP disables the plugin entirely.

Are the thresholds configurable?

Yes. Attempts before lockout, lockout length, escalation and counter reset are all settings. The defaults (4 attempts, 10 minutes) are a sensible starting point.

Does this replace hiding the login page?

They complement each other: hiding the login removes the easy target, limiting makes any attack that finds it expensive. Both ship free.

Related features

Free

Hide login page

Move wp-login behind an address only you know.

Learn more →
Free

Two-factor authentication

Email codes and authenticator apps with per-role enforcement.

Learn more →
Free

CAPTCHA

reCAPTCHA or Turnstile on login, registration and comments.

Learn more →

All features →

Secure your site today

Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.