JupJup Limit Login Attempts
Lightweight WordPress plugin protecting the login page against brute-force attacks. Tracks failed attempts per IP in a custom DB table and permanently blacklists offenders at the threshold. Covers login form and auth cookie attacks. Includes whitelist, manual blacklist management, and email notifications.
by Alex · github.com/alsiesta/wordpress-limit-login-attempts · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/alsiesta/wordpress-limit-login-attempts/archive/refs/heads/main.zipA lightweight WordPress plugin that protects the login page against brute-force attacks by tracking failed attempts per IP address and permanently blacklisting offending IPs.
How It Works
Every time someone enters wrong credentials — either through the login form or via auth cookies — the attempt is counted in a custom database table. Once an IP reaches the configured threshold (default: 5 attempts), it is permanently added to a blacklist. From that point on, any login attempt from that IP is blocked immediately with no time limit and no automatic expiry.
On a successful login, the attempt counter for that IP is reset — but blacklist entries are never removed automatically. This means a determined attacker cannot simply wait out a timeout and try again.
Features
- Tracks failed login attempts per IP in a dedicated database table
- Auto-blacklists IPs that reach the failure threshold
- Blocks both login form attempts and auth cookie brute-force attacks
- Manual blacklisting of known malicious IPs via the admin panel
- One-click removal of IPs from the blacklist (e.g. for legitimate users blocked by mistake)
- Optional email notification to the administrator on each auto-blacklist event
- Configurable failure threshold
- Full attempt log in the admin panel (last 50 entries)
- Clean uninstall — removes all tables and options on deletion
Installation
- Copy the
jupjup-limit-login-attemptsfolder intowp-content/plugins/ - Go to WP Admin → Plugins and activate JupJup Limit Login Attempts
- The required database tables are created automatically on activation
- Configure settings under Settings → Limit Logins
Configuration
Navigate to Settings → Limit Logins in the WordPress admin panel.
| Setting | Default | Description |
|---|---|---|
| Failed attempts before blacklist | 5 | Number of failures before an IP is permanently blocked |
| Email notification | On | Send an email to the admin when an IP is auto-blacklisted |
| Notification email | Admin email | The address that receives blacklist notifications |
Database Tables
The plugin creates two custom tables on activation:
wp_lla_login_attempts— tracks attempt counts per IP while below the thresholdwp_lla_blacklist— stores permanently blocked IPs with reason and timestamp
Both tables are removed cleanly when the plugin is deleted via the WordPress admin.
Admin Panel
Settings → Limit Logins provides:
- Settings form (threshold, email notification)
- Blacklisted IPs table with per-IP remove button
- Manual IP blacklist form
- Recent attempt log (last 50 entries)
Releasing from Localhost to Production
This plugin is part of the jupjup.de WordPress setup. Deployment is handled via GitHub Actions with FTP to shared hosting, scoped to the custom theme and plugin directories.
Changelog
1.2.0
- Replaced timed lockout with permanent auto-blacklist
- Added
wp_lla_blacklisttable - Added manual blacklist management in admin panel
- Added auth cookie brute-force protection
1.1.0
- Added auth cookie failure hooks (
auth_cookie_bad_username,auth_cookie_bad_hash) - Added cookie-based lockout check via
auth_cookie_valid
1.0.0
- Initial release
- Login form protection with custom DB table
- Admin settings page with attempt log and unlock functionality
License
GPL-2.0+