Hardens WordPress with two-factor authentication, login protection, vulnerability detection, SSL tools, and security controls.
Limit Login Attempts Security
Plugin Health & Stats
Historical overview
364-day WordPress.org historyQuick take
This Limit Login Attempts review focuses on one job: WordPress brute force protection. Limit Login Attempts Security is a focused WordPress login-security plugin rather than a full malware or site-scanning suite. The free version limits failed login attempts by IP address and username, adds lockouts, two-factor authentication, login monitoring, safelists and denylists, XML-RPC protection, and compatibility with WooCommerce and custom login pages.
I would use it when brute-force protection and login abuse are the main problem you are trying to solve. Premium moves more of that protection into a cloud service, adding malicious-IP intelligence, a global denylist, country blocking, synchronized protection across sites, more detailed login data, and offloading of attack traffic before it reaches the WordPress database.
Best fit: Limit Login Attempts Security makes the most sense for WordPress sites that want focused brute-force protection, 2FA, login monitoring, and lockout controls without deploying a broad security suite. It is less compelling for sites looking for malware scanning, file-integrity monitoring, managed cleanup, or broad protection for non-login application traffic.
What the free plugin actually protects
WordPress normally allows repeated authentication attempts unless another security layer intervenes. Limit Login Attempts Security changes that behavior by tracking failed attempts and locking out suspicious IP addresses or usernames after the configured retry threshold is reached.
The plugin protects standard WordPress login routes, wp-admin authentication, XML-RPC, WooCommerce logins, and compatible custom login forms that use normal WordPress authentication hooks. It also supports WordPress Multisite.
Features that matter for WordPress login security
Retry limits and lockout rules
You can control the number of allowed retries and the lockout duration. The current documentation uses four allowed retries as the default and recommends keeping the default unless your host or security setup requires something different. Setting the threshold too low can lock out legitimate users, while setting it too high weakens the protection.
2FA is included in the free plugin
Current Limit Login Attempts Security includes built-in two-factor authentication in Free. That adds another login step beyond the password, which is useful because rate limiting alone does not protect an account if an attacker already has valid credentials.
Logs, notifications, safelists, and denylists
The free version records failed login activity and can send lockout notifications. Administrators can maintain IP and username safelists and denylists, including IPv6 ranges. Those controls are useful when a known office IP, service, or administrator should avoid accidental lockouts, or when a known abusive source needs to be blocked.
Proxy and CDN configuration matters
Login-limiting tools depend on identifying the visitor’s real IP address. If a CDN, reverse proxy, or hosting layer makes every request appear to come from the same proxy IP, a single lockout can affect legitimate users. The free plugin includes Trusted IP Origin settings for this scenario, while the cloud service is designed to handle non-standard IP origins more automatically.
Premium offloads more attack handling to the cloud
Premium adds cloud-based login protection with IP intelligence, throttling, enhanced logs, successful-login tracking, country blocking on higher plans, and access to a global malicious-IP denylist. The practical benefit is not only more data. Cloud mode can absorb failed-login requests before they consume as much of the site’s local hosting resources.
Limit Login Attempts Free vs Premium
For WordPress login security, the free plugin is enough when you need local brute-force protection, configurable lockouts, 2FA, login logs, access lists, notifications, XML-RPC protection, and protection for standard WordPress or WooCommerce login forms.
Premium is easier to justify when the site is under sustained automated attack, when you want cloud IP intelligence and global denylist protection, when country blocking matters, or when an agency needs shared protection and centralized controls across multiple sites.
Where the trade-offs show up
The biggest operational risk with login limiting is false lockout. Shared office networks, VPNs, proxies, and misconfigured CDNs can make several legitimate users appear to share one IP address. I would verify the IP-origin setting before tightening retry limits on a production membership or WooCommerce site.
The free plugin also absorbs attack traffic on your own hosting infrastructure. That is usually acceptable for ordinary brute-force noise, but a sustained attack can still consume PHP, database, or bandwidth resources. Premium’s cloud model is designed to reduce that local burden.
Finally, focused login security is not full-site security. Limit Login Attempts Security does not replace backups, software updates, vulnerability management, malware scanning, or a web application firewall that protects non-login traffic.
Limit Login Attempts Security pricing
Pricing checked September 9, 2026. Limit Login Attempts pricing currently starts with the Personal plan. The current Personal promotion is $1.25/month per domain billed annually for the first year, discounted from $2.50/month. That works out to $15 for the promotional first year versus a $30 annualized regular rate.
For a second Limit Login Attempts pricing reference, Business is currently $4.17/month per domain billed annually for the first year, discounted from $8.33/month. The current Agency offer starts at $224.99/year for up to 10 domains, with additional domain bands priced separately. The pricing page states that the promotional discount applies to the first year.
PluginSuggest verdict
My Limit Login Attempts review conclusion is that this is a good fit when you want to solve a specific problem: automated abuse of WordPress authentication. The free plugin already covers the essential local controls, including 2FA, and it can coexist with broader security products because its scope is comparatively focused.
For WordPress brute force protection at higher attack volumes, I would consider Premium when attack volume, country blocking, centralized agency management, or cloud IP intelligence materially changes the risk or server load. I would not buy it expecting malware cleanup or whole-site threat detection, because that is not the job it is built to do.
Limit Login Attempts Security FAQs
Is Limit Login Attempts Security free?
Yes. The free plugin includes configurable login-attempt limits, lockouts, 2FA, logs, notifications, safelists and denylists, and protection for standard WordPress login routes.
Does the free version include 2FA?
Yes. Built-in two-factor authentication is currently listed as a free feature.
Does it protect WooCommerce login pages?
Yes. The official plugin listing includes WooCommerce login pages, XML-RPC, WordPress Multisite, and compatible custom login forms among the protected login surfaces.
Why can login-attempt plugins block legitimate users?
If a proxy, CDN, VPN, or hosting configuration makes multiple visitors appear to share one IP address, one user’s lockout can affect others. Correct IP-origin configuration is important before tightening lockout settings.
How much does Limit Login Attempts Premium cost?
At pricing checked September 9, 2026, Personal is $1.25/month per domain billed annually for the first year under the current promotion, with a regular listed rate of $2.50/month.
What does version 3.3.7 support?
The current WordPress.org listing requires WordPress 5.0 or higher and lists Limit Login Attempts Security 3.3.7 as tested through WordPress 7.1.
Compare before you install
Similar Plugins
Protects WordPress with a web application firewall, malware scanner, two-factor authentication, and security monitoring tools.
Hardens WordPress with login protection, two-factor authentication, vulnerability scanning, firewall controls, and security tools.