Skip to main content
Limit Login Attempts Security logo

Limit Login Attempts Security

Focuses on WordPress login security with brute-force protection, 2FA, lockouts, monitoring, IP controls, and optional cloud-based attack mitigation.
SecurityRecommendedBest Value
Visit Plugin
Last Updated: September 9, 2026

Plugin Health & Stats

Checked 2 weeks agoSource: WordPress.org
Active installs
1,000,000+Official WordPress.org tier
WP.org rating
4.8/51,483 ratings
Version
3.3.9Current repository release
Last updated
1 week agoSep 23, 2026
Total downloads96,821,589
Tested with WP7.1.1
Requires WP5.0+
Requires PHPNot reported
Support resolved (2 mo.)13 of 22 (59%)
Plugin age10 years, 1 month
Updates observed1
Tracking sinceSep 12, 2026
Repository data is older than 3 days. Showing the latest successful snapshot.

Historical overview

364-day WordPress.org history
Download trendDaily package downloads · last 90 days
7d624,327 30d4,184,659 90d7,173,337 Peak day678.1KJul 9
Jul 3Aug 1Aug 31Sep 30
Active version adoptionCurrent usage share
3.3 60.0%2.26 19.3%other 12.6%2.25 8.0%

Quick take

This Limit Login Attempts review focuses on one job: WordPress brute force protection. Limit Login Attempts Security is a focused WordPress login-security plugin rather than a full malware or site-scanning suite. The free version limits failed login attempts by IP address and username, adds lockouts, two-factor authentication, login monitoring, safelists and denylists, XML-RPC protection, and compatibility with WooCommerce and custom login pages.

I would use it when brute-force protection and login abuse are the main problem you are trying to solve. Premium moves more of that protection into a cloud service, adding malicious-IP intelligence, a global denylist, country blocking, synchronized protection across sites, more detailed login data, and offloading of attack traffic before it reaches the WordPress database.

Best fit: Limit Login Attempts Security makes the most sense for WordPress sites that want focused brute-force protection, 2FA, login monitoring, and lockout controls without deploying a broad security suite. It is less compelling for sites looking for malware scanning, file-integrity monitoring, managed cleanup, or broad protection for non-login application traffic.

What the free plugin actually protects

WordPress normally allows repeated authentication attempts unless another security layer intervenes. Limit Login Attempts Security changes that behavior by tracking failed attempts and locking out suspicious IP addresses or usernames after the configured retry threshold is reached.

The plugin protects standard WordPress login routes, wp-admin authentication, XML-RPC, WooCommerce logins, and compatible custom login forms that use normal WordPress authentication hooks. It also supports WordPress Multisite.

Features that matter for WordPress login security

Retry limits and lockout rules

You can control the number of allowed retries and the lockout duration. The current documentation uses four allowed retries as the default and recommends keeping the default unless your host or security setup requires something different. Setting the threshold too low can lock out legitimate users, while setting it too high weakens the protection.

2FA is included in the free plugin

Current Limit Login Attempts Security includes built-in two-factor authentication in Free. That adds another login step beyond the password, which is useful because rate limiting alone does not protect an account if an attacker already has valid credentials.

Logs, notifications, safelists, and denylists

The free version records failed login activity and can send lockout notifications. Administrators can maintain IP and username safelists and denylists, including IPv6 ranges. Those controls are useful when a known office IP, service, or administrator should avoid accidental lockouts, or when a known abusive source needs to be blocked.

Proxy and CDN configuration matters

Login-limiting tools depend on identifying the visitor’s real IP address. If a CDN, reverse proxy, or hosting layer makes every request appear to come from the same proxy IP, a single lockout can affect legitimate users. The free plugin includes Trusted IP Origin settings for this scenario, while the cloud service is designed to handle non-standard IP origins more automatically.

Premium offloads more attack handling to the cloud

Premium adds cloud-based login protection with IP intelligence, throttling, enhanced logs, successful-login tracking, country blocking on higher plans, and access to a global malicious-IP denylist. The practical benefit is not only more data. Cloud mode can absorb failed-login requests before they consume as much of the site’s local hosting resources.

Limit Login Attempts Free vs Premium

For WordPress login security, the free plugin is enough when you need local brute-force protection, configurable lockouts, 2FA, login logs, access lists, notifications, XML-RPC protection, and protection for standard WordPress or WooCommerce login forms.

Premium is easier to justify when the site is under sustained automated attack, when you want cloud IP intelligence and global denylist protection, when country blocking matters, or when an agency needs shared protection and centralized controls across multiple sites.

Choose Limit Login Attempts Security if

  • Your main risk is repeated login attempts, credential stuffing, or bot abuse.
  • You want a focused login-security layer with 2FA rather than a large all-purpose security suite.
  • You want the option to offload login attack handling to a cloud service later.

Choose a broader security product if

  • You need malware scanning, file-integrity monitoring, vulnerability management, or incident cleanup in the same plugin.
  • Your host or external security platform already handles rate limiting and login protection at the edge.
  • You need security controls for parts of the application unrelated to authentication.

Where the trade-offs show up

The biggest operational risk with login limiting is false lockout. Shared office networks, VPNs, proxies, and misconfigured CDNs can make several legitimate users appear to share one IP address. I would verify the IP-origin setting before tightening retry limits on a production membership or WooCommerce site.

The free plugin also absorbs attack traffic on your own hosting infrastructure. That is usually acceptable for ordinary brute-force noise, but a sustained attack can still consume PHP, database, or bandwidth resources. Premium’s cloud model is designed to reduce that local burden.

Finally, focused login security is not full-site security. Limit Login Attempts Security does not replace backups, software updates, vulnerability management, malware scanning, or a web application firewall that protects non-login traffic.

Limit Login Attempts Security pricing

Pricing checked September 9, 2026. Limit Login Attempts pricing currently starts with the Personal plan. The current Personal promotion is $1.25/month per domain billed annually for the first year, discounted from $2.50/month. That works out to $15 for the promotional first year versus a $30 annualized regular rate.

For a second Limit Login Attempts pricing reference, Business is currently $4.17/month per domain billed annually for the first year, discounted from $8.33/month. The current Agency offer starts at $224.99/year for up to 10 domains, with additional domain bands priced separately. The pricing page states that the promotional discount applies to the first year.

PluginSuggest verdict

My Limit Login Attempts review conclusion is that this is a good fit when you want to solve a specific problem: automated abuse of WordPress authentication. The free plugin already covers the essential local controls, including 2FA, and it can coexist with broader security products because its scope is comparatively focused.

For WordPress brute force protection at higher attack volumes, I would consider Premium when attack volume, country blocking, centralized agency management, or cloud IP intelligence materially changes the risk or server load. I would not buy it expecting malware cleanup or whole-site threat detection, because that is not the job it is built to do.

Limit Login Attempts Security FAQs

Is Limit Login Attempts Security free?

Yes. The free plugin includes configurable login-attempt limits, lockouts, 2FA, logs, notifications, safelists and denylists, and protection for standard WordPress login routes.

Does the free version include 2FA?

Yes. Built-in two-factor authentication is currently listed as a free feature.

Does it protect WooCommerce login pages?

Yes. The official plugin listing includes WooCommerce login pages, XML-RPC, WordPress Multisite, and compatible custom login forms among the protected login surfaces.

Why can login-attempt plugins block legitimate users?

If a proxy, CDN, VPN, or hosting configuration makes multiple visitors appear to share one IP address, one user’s lockout can affect others. Correct IP-origin configuration is important before tightening lockout settings.

How much does Limit Login Attempts Premium cost?

At pricing checked September 9, 2026, Personal is $1.25/month per domain billed annually for the first year under the current promotion, with a regular listed rate of $2.50/month.

What does version 3.3.7 support?

The current WordPress.org listing requires WordPress 5.0 or higher and lists Limit Login Attempts Security 3.3.7 as tested through WordPress 7.1.

Similar Plugins

Community Reviews

0 community reviews
Log in or create an account to write a review.
No published community reviews yet.