Performancing Metrics

WordPress Plugin: Login Lockdown

One of the most common ways your WordPress blog can be compromised would be by brute force attacks. A brute force attack is the most widely known password cracking method. This attack simply tries to use every possible character combination as a password. To recover a one-character password it is enough to try 26 combinations (‘a’ to ‘z’). Luckily, a WordPress plugin is there to protect your blog from such attacks.

Login LockDown records the IP address and timestamp of every failed WordPress login attempt. If more than a certain number of attempts are detected within a short period of time from the same IP range, then the login function is disabled for all requests from that range. This helps to prevent brute force password discovery.

Currently the plugin defaults to a 1 hour lock out of an IP block after 3 failed login attempts within 5 minutes. This can be modified via the Options panel. Admisitrators can release locked out IP ranges manually from the panel.

Installation instructions:

1. Extract into your wp-content/plugins directory into its own folder (note: not the root plugins folder, as this may cause the activation routine to fail).
2. Activate the plugin in the Plugin options.
3. Customize the settings from the Options panel, if desired.

Requires at least WordPress 2.5, tested up to 2.5.1, however, I’m using it on my WordPress 2.7 blog with no problems at all.

Dowmload Login Lockdown here.

Categories: WordPress Plugins

This post was written by . You can visit the for a short bio, more posts, and other information about the author.

Comment with Your Facebook Account


  1. Jack says: 12/28/2008

    That sounds pretty sweet. I don’t use WP myself (various reasons) but I do like the plugins feature, and I think that would be a great way to deter would be blog hackers. The only thing is if you forget your password and try a few that you have, then you’re going to be annoyed if you get stopped!


  2. Outtanames999 says: 12/28/2008

    Why do I think that if I install this on my blog, my own IP address will show up the most?


  3. Mark says: 8/26/2009

    I dont understand how can the IP help you….
    Its not like anybody can track down who this is…

    I understand that login is disabled.. but i think a complex password should work here :)



  4. Arturo Vaughn says: 3/11/2011

    WordPress Video Tutorials-39 Step by Step Videos


Performancing Metrics
EatonWeb Portal