ModernAmusement Login Guard
Brute-force protection for WordPress login with per-user and per-IP lockout, exponential backoff and Telegram alerts.
by Shady Tawfik · github.com/modernamusements/modern-amusement-login-guard · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/modernamusements/modern-amusement-login-guard/archive/refs/heads/main.zipBrute-force protection for the WordPress login with per-user and per-IP lockout, exponential backoff, REST/XML-RPC rate limiting and Telegram/webhook alerts. An improved "Limit Login Attempts Reloaded".
Version: 1.0.0 · Requires: WordPress 6.0+, PHP 7.4+ · License: GPL-2.0-or-later
🇩🇪 Deutsch
ModernAmusement Login Guard schützt deinen WordPress-Login gegen Brute-Force-Angriffe und sichert dabei beide Identitäten ab: die IP-Adresse und den Benutzernamen.
Funktionen
- Doppelter Auslöser — sperrt bei zu vielen Fehlversuchen von einer IP oder für einen Benutzernamen — je nachdem, was zuerst erreicht ist.
- Exponentieller Backoff — die erste Sperre ist kurz; jede Wiederholung ist um ein Vielfaches länger, bis zu einem konfigurierbaren Maximum. Hartnäckige Angreifer werden so schneller eingefroren, ohne die Seite zu beeinträchtigen.
- REST- & XML-RPC-Rate-Limit — API-Endpoints werden ebenfalls pro IP gedrosselt und schließen den Seitenkanal, den viele Passwort-Cracker nutzen.
- Benachrichtigungen — optional per E-Mail, generischem Webhook und Telegram, damit du von Angriffen sofort erfährst.
- Privacy by design — gespeicherte IPs werden maskiert und nach einer konfigurierbaren Anzahl Tagen automatisch gelöscht (GDPR/Datenminimierung).
- Manuelle Kontrolle — IP mit einem Klick entsperren oder alle Sperrdaten leeren; WP-CLI via
wp ma-login-guard. - Hinterlässt keine Daten — Cron und beide Optionen werden bei der Deinstallation entfernt.
- Übersetzungsbereit.
Installation
- Lade den Ordner
modern-amusement-login-guardnach/wp-content/plugins/hoch (oder installiere über Plugins → Installieren). - Aktiviere das Plugin.
- Gehe zu Einstellungen → Login Guard, um Schwellwerte, Whitelists und Benachrichtigungen anzupassen.
FAQ
Ich habe mich beim Testen selbst ausgesperrt — Hilfe!
Gehe zu Einstellungen → Login Guard → „Alle Sperrdaten leeren" oder führe wp ma-login-guard reset aus.
Wie funktioniert der exponentielle Backoff?
Nach N Fehlversuchen wird eine IP für initial lockout Sekunden gesperrt. Kommt später eine neue Sperre hinzu, dauert sie jedes Mal factor-mal länger, begrenzt durch max lockout.
Speichert ihr die IPs meiner Besucher?
Nur bei Fehlversuchen, und der gespeicherte Wert ist maskiert (z. B. 203.0.113.xxx) und wird nach Ablauf des konfigurierten Purge-Zeitraums automatisch gelöscht. Whitelistete IPs werden nie getrackt.
Wie richte ich Telegram-Alerts ein? Erstelle einen Bot mit @BotFather, notiere Token und deine Chat-ID und füge beides in Einstellungen → Login Guard ein. Das Plugin nutzt die offizielle Telegram-Bot-API.
Changelog
- 1.0.0 — Erstveröffentlichung.
🇬🇧 English
ModernAmusement Login Guard protects your WordPress login against brute-force attacks, protecting both identities: the IP address and the username.
Features
- Double trigger — locks out on too many failures from one IP or for one username, whichever is exceeded first.
- Exponential backoff — the first lockout is short; each repeat is many times longer, up to a configurable ceiling, so persistent attackers get frozen out faster without hurting the sites.
- REST & XML-RPC rate limiting — API endpoints are throttled per IP too, closing the side channel used by many password crackers.
- Notifications — optional e-mail, generic webhook and Telegram so you know about attacks the moment they happen.
- Privacy by design — stored IPs are masked and auto-purged after a configurable number of days (GDPR / data minimalisation).
- Manual control — unlock an IP with one click, or clear all lock data; WP-CLI via
wp ma-login-guard. - No data left behind — the schedule and both options are cleaned up on uninstall.
- Translations ready.
Installation
- Upload the
modern-amusement-login-guardfolder to/wp-content/plugins/(or install via Plugins → Add New). - Activate the plugin.
- Go to Settings → Login Guard to tune thresholds, whitelists and notifications.
FAQ
I locked myself out during testing - help!
Go to Settings → Login Guard → "Clear all lock data", or run wp ma-login-guard reset from the command line.
How does the exponential backoff work?
After N failures an IP is locked for initial lockout seconds. Should a new lockout come later, it lasts factor times longer each time, capped at max lockout.
Do you store my visitors' IPs?
Only on failed attempts, and the stored value is masked (e.g. 203.0.113.xxx) and automatically deleted after the configured purge period. Whitelisted IPs are never tracked.
How do I set up Telegram alerts? Create a bot with @BotFather, note its token and your chat ID, then paste both into Settings → Login Guard. The plugin calls the official Telegram Bot API.
Changelog
- 1.0.0 — Initial release.
License
GPL-2.0-or-later — see LICENSE.
Author
Shady Tawfik · https://modern-amusement.dev/de