Limit Login Attempts Reloaded – Login Security, 2FA, Brute Force Protection & Firewall

Limit Login Attempts Reloaded – Login Security, 2FA, Brute Force Protection & Firewall

توسط

Limit Login Attempts Reloaded functions as a robust deterrent against brute force attacks, bolstering your website’s security measures and optimizing its performance. It achieves this by restricting the number of login attempts allowed. This applies not only to the standard login method, but also to XMLRPC, Woocommerce, and custom login pages. With more than 2.5 million active users, this plugin fulfills all your login security requirements.

The plugin functions by automatically preventing further attempts from a particular Internet Protocol (IP) address and/or username once a predetermined limit of retries has been surpassed. This significantly weakens the effectiveness of brute force attacks on your website.

By default, WordPress permits an unlimited number of login attempts, posing a vulnerability where passwords can be easily deciphered through brute force methods.

Limit Login Attempts Reloaded Premium (Try Free with Micro Cloud)
Upgrade to Limit Login Attempts Reloaded Premium to extend cloud-based protection to the Limit Login Attempts Reloaded plugin, thereby enhancing your login security. The premium version includes a range of highly beneficial features, including IP intelligence to detect, counter and deny malicious login attempts. Your failed login attempts will be safely neutralized in the cloud so your website can function at its optimal performance during an attack.

Features (Free Version):

  • 2FA – Enable two-factor authentication for extra login security.
  • Limit Logins – Limit the number of retry attempts when logging in (per each IP).
  • Configurable Lockout Timings – Modify the amount of time a user or IP must wait after a lockout.
  • Remaining Tries – Informs the user about the remaining retries or lockout time on the login page.
  • Lockout Email Notifications – Informs the admin via email of lockouts.
  • Denied Attempt Logs – View a log of all denied attempts and lockouts.
  • IP & Username Safelist/Denylist – Control access to usernames and IPs.
  • New User Registration Protection (Micro Cloud Accounts) – Protects default WP registration.
  • Sucuri compatibility.
  • Wordfence compatibility.
  • Ultimate Member compatibility.
  • WPS Hide Login compatibility.
  • MemberPress compatibility.
  • XMLRPC gateway protection.
  • Woocommerce login page protection.
  • Multi-site compatibility with extra MU settings.
  • GDPR compliant.
  • Custom IP origins support (Cloudflare, Sucuri, etc.).
  • llar_admin own capability.

Features (Premium Version):

  • Performance Optimizer – Offload the burden of excessive failed logins from your server to protect your server resources, resulting in improved speed and efficiency of your website.
  • Enhanced IP Intelligence – Identify repetitive and suspicious login attempts to detect potential brute force attacks. IPs with known malicious activity are stored and used to help prevent and counter future attacks.
  • Enhanced Throttling – Longer lockout intervals each time a malicious IP or username tries to login unsuccessfully.
  • Deny By CountryBlock logins by country by simply selecting the countries you want to deny.
  • Auto IP Denylist – Automatically add IP addresses to your active cloud deny list that repeatedly fail login attempts.
  • New User Registration Protection – Protects default WP registration.
  • Global Denylist Protection – Utilize our active cloud IP data from thousands of websites in the LLAR network.
  • Synchronized Lockouts – Lockout IP data can be shared between multiple domains for enhanced protection in your network.
  • Synchronized Safelist/Denylist – Safelist/Denylist IP and username data can be shared between multiple domains.
  • Premium Support – Email support with a security tech.
  • Auto Backups of All IP Data – Store your active IP data in the cloud.
  • Successful Logins Log – Store successful logins in the cloud including IP info, city, state and lat/long.
  • Enhanced lockout logs – Gain valuable insights into the origins of IPs that are attempting logins.
  • CSV Download of IP Data – Download IP data direclty from the cloud.
  • Supports IPV6 Ranges For Safelist/Denylist
  • Unlock The Locked Admin – Easily unlock the locked admin through the cloud.
  • Registration Page Protection – Protect the registration page based on your rules and a real-time database of malicious IPs. Also protects WooCommerce and other supported plugins.

*Some features require higher level plans.

Upgrading from the old Limit Login Attempts plugin?

  1. Go to the Plugins section in your site’s backend.
  2. Remove the Limit Login Attempts plugin.
  3. Install the Limit Login Attempts Reloaded plugin.

All your settings will be kept intact!

Many languages are currently supported in the Limit Login Attempts Reloaded plugin but we welcome any additional ones.

Help us bring Limit Login Attempts Reloaded to even more countries.

Translations: Bulgarian, Brazilian Portuguese, Catalan, Chinese (Traditional), Czech, Dutch, Finnish, French, German, Hungarian, Norwegian, Persian, Romanian, Russian, Spanish, Swedish, Turkish

Plugin uses standard actions and filters only.

Based on the original code from Limit Login Attempts plugin by Johan Eenfeldt.

Branding Guidelines

Limit Login Attempts Reloaded™ is a trademark of Atlantic Silicon Inc. When writing about the plugin, please make sure to use Reloaded after Limit Login Attempts. Limit Login Attempts is the old plugin.

  • Limit Login Attempts Reloaded (correct)
  • Limit Login Attempts (incorrect)
راهنمای نصب برای این آیتم موجود نیست.

سوالات متداول

What do I do if all users get blocked?

If you are using contemporary hosting, it’s likely your site uses a proxy domain service like CloudFlare, Sucuri, Nginx, etc. They replace your user’s IP address with their own. If your server is not configured properly, all users will get the same IP address. This also applies to bots and hackers. Therefore, locking one user will lead to locking everybody else out. In the free version of the plugin, this can be adjusted using the Trusted IP Origin setting. In the premium version, the cloud service intelligently recognizes the non-standard IP origins and handles them correctly, even if your hosting provider does not.

How do I know if I’m under attack?

An easy way to check if the attack is legitimate is to copy the IP address from the lockout notification and check its location using a IP locator tool. If the location is not somewhere you recognize and you have received several failed login attempts, then you are likely being attacked. You might notice dozens or hundreds of IPs each day. Visit our website to learn how can you prevent brute force attacks on your website.

How can I tell that the premium plugin is working?

After you upgrade to our premium version, you will see a new dashboard in your WordPress admin that shows all attacks that will now relay through our cloud service. On the graph, you’ll see requests and failed login attempts. Each request will represent the cloud app validating an IP, which also includes denied logins.

In some cases, you may notice an increase in speed and efficiency with your website. Also, a reduction in lockout notifications via email.

Could these failed login attempts be fake?

Some users find it hard to believe that they could experience numerous unsuccessful login attempts, particularly when their site has just been established or has minimal human traffic. The plugin is not responsible for generating these failed login attempts. Newly created websites are frequently hosted on shared IP addresses, making it easy for hackers to discover them. Additionally, newly registered domain names are often crawled soon after creation, rendering a WordPress website susceptible to attacks. Such websites are attractive targets as security is not a primary concern for their owners. We’ve created an article that delves deeper into the issue of fake login attempts in WordPress.

What happens if my site exceeds the request limits in the plan?

The premium plan’s resource limits start from 100,000 requests per month, which should accept almost any heavy brute-force attack. We monitor all of our sites and will alert the user if it appears they are going over their limits. If limits are reached, we will suggest to the user upgrading to the next plan. If you are using the free version, the load caused by brute force attacks will be absorbed by your current hosting bandwidth, which could cause your hosting costs to increase.

What URLs are being attacked and protected?

The URLs being protected are your login page (wp-login.php, wp-admin), xmlrpc.php, WooCommerce login page, and any custom login page you have that uses regular WordPress login hooks.

Why is LLAR more popular than other brute-force protection plugins?

Our main focus is protecting your site from brute force attacks. This allows our plugin to be very lean and effective. It doesn’t require a lot of your web hosting resources and keeps your site well-protected. More importantly, it does all of this automatically as our service learns on its own about each IP it encounters. In contrast, a firewall would require manual blocking of IPs.

What to do when an admin gets blocked?

Open the site from another IP. You can do this from your cell phone, or using Opera browser and enabling free VPN there. You can also try turning off your router for a few minutes and then see if you get a different IP address. These will work if your hosting server is configured correctly. If that doesn’t work, connect to the site using FTP or your hosting control panel file manager. Navigate to wp-content/plugins/ and rename the limit-login-attempts-reloaded folder. Log in to the site then rename that folder back and whitelist your IP. By upgrading to our premium app, you will have the unlocking functionality right from the cloud so you’ll never have to deal with this issue.

What settings should I use In the plugin?

The settings are explained within the plugin in great detail. If you are unsure, use the default settings as they are the recommended ones.

Can I share the safelist/denylist throughout all of my sites?

By default, you will need to copy and paste the lists to each site manually. For the premium service, sites are grouped within the same private cloud account. Each site within that group can be configured if it shares its lockouts and access lists with other group members. The setting is located in the plugin’s interface. The default options are recommended.

×

نظرات کاربران

3/5
★★★☆☆

Works but Annoying

By hunterfox3 on April 21, 2026

It does protect login with limits, so that part is good. But got some false lockouts which was a bit frustrating. Setup is ok, just needs better control 👍

Excellent

By qykzoo on April 21, 2026

Used in conjunction with WPS Hide Login I have successfully gotten rid of "hackers" ... went from 1-200 attempts per month to lest than 0. I am using this on all 6 sites where I am webmaster / developer / dogsbody

Thanks..David

Save my life

By bkursawe on April 19, 2026

Thanx to the mail support, otherwise I hadn't recognize the attemps to login on my page!

Nice Security Addon

By zane97 on April 8, 2026

Installed Limit Login Attempts Reloaded recently. Setup was quick, and it just works. Blocks unwanted tries and keeps things safe. No issues till now. Simple but does its job well 👍

Good Security Help

By roseday on March 30, 2026

Does a good job of limiting login tries. Helps reduce spam logins and brute force attempts. The setup was simple and is running fine. Could be a bit more flexible, but still useful 👍

Very very effective. You can even see where the IP address trying to hack you

By marenmaren on March 28, 2026

This plugin is first effective in blocking (limiting) login attempts from hackers. Second, it even shows you the IP address with its location.

Skydd mot attacker

By huno1943wor0816 on March 25, 2026

En utmärkt hjälp föratt skydda min hemsida mot attacker

Essential for all my wordpress sites

By carlos6623 on March 24, 2026

This plugin has protected me from many attacks, and arned me just it time. Essential for all my wordpress sites.

Best Security Solution

By otohaharuka on March 16, 2026

Because WordPress cannot run as a standalone application, security measures are essential.

The fact that a feature that detects and alerts users via email about irregular unauthorized access from overseas is available for free is extremely helpful.

Of course, it goes without saying that 2FA should be used in conjunction with this feature, but since 2FA alone doesn't guarantee security, I think this plugin should be installed.

gute Abwehr

By tekwar on March 11, 2026

dieses Plugin ist klasse

0 0 رای ها
امتیازدهی
اشتراک در
اطلاع از
0 نظرات
قدیمی‌ترین
تازه‌ترین بیشترین رأی
بازخورد (Feedback) های اینلاین
مشاهده همه دیدگاه ها
نسخه حجم فایل SHA256 تغییرات دانلود
3.2.0 3 مگابایت
دانلود
3.1.0 3 مگابایت
دانلود
2.5.0 103 کیلوبایت -
دانلود
2.6.1 104 کیلوبایت -
دانلود
2.6.2 104 کیلوبایت -
دانلود
2.6.3 104 کیلوبایت -
دانلود
2.7.0 105 کیلوبایت -
دانلود
2.7.1 106 کیلوبایت -
دانلود
2.7.2 106 کیلوبایت -
دانلود
2.7.3 106 کیلوبایت -
دانلود
2.7.4 106 کیلوبایت -
دانلود
2.8.0 106 کیلوبایت -
دانلود
2.8.1 106 کیلوبایت -
دانلود
2.9.0 107 کیلوبایت -
دانلود
3.0.0 3 مگابایت -
دانلود
3.0.1 3 مگابایت -
دانلود
3.0.2 3 مگابایت -
دانلود
2.0.0 103 کیلوبایت -
دانلود
2.1.0 102 کیلوبایت -
دانلود
2.10.0 108 کیلوبایت -
دانلود
2.10.1 108 کیلوبایت -
دانلود
2.11.0 108 کیلوبایت -
دانلود
2.12.0 138 کیلوبایت -
دانلود
2.12.1 139 کیلوبایت -
دانلود
2.12.2 139 کیلوبایت -
دانلود
2.12.3 139 کیلوبایت -
دانلود
2.13.0 156 کیلوبایت -
دانلود
2.14.0 156 کیلوبایت -
دانلود
2.15.0 156 کیلوبایت -
دانلود
2.15.1 155 کیلوبایت -
دانلود
2.15.2 156 کیلوبایت -
دانلود
2.16.0 168 کیلوبایت -
دانلود
2.17.0 169 کیلوبایت -
دانلود
2.17.1 169 کیلوبایت -
دانلود
2.17.2 169 کیلوبایت -
دانلود
2.17.3 170 کیلوبایت -
دانلود
2.17.4 178 کیلوبایت -
دانلود
2.18.0 247 کیلوبایت -
دانلود
2.19.0 247 کیلوبایت -
دانلود
2.19.1 524 کیلوبایت -
دانلود
2.19.2 524 کیلوبایت -
دانلود
2.2.0 103 کیلوبایت -
دانلود
2.20.0 667 کیلوبایت -
دانلود
2.20.1 667 کیلوبایت -
دانلود
2.20.2 666 کیلوبایت -
دانلود
2.20.3 666 کیلوبایت -
دانلود
2.20.4 690 کیلوبایت -
دانلود
2.20.5 691 کیلوبایت -
دانلود
2.20.6 691 کیلوبایت -
دانلود
2.21.0 692 کیلوبایت -
دانلود
2.21.1 696 کیلوبایت -
دانلود
2.22.0 697 کیلوبایت -
دانلود
2.22.1 697 کیلوبایت -
دانلود
2.23.0 617 کیلوبایت -
دانلود
2.23.1 617 کیلوبایت -
دانلود
2.23.2 617 کیلوبایت -
دانلود
2.24.0 618 کیلوبایت -
دانلود
2.24.1 618 کیلوبایت -
دانلود
2.25.0 622 کیلوبایت -
دانلود
2.25.1 622 کیلوبایت -
دانلود
2.25.10 691 کیلوبایت -
دانلود
2.25.11 699 کیلوبایت -
دانلود
2.25.12 699 کیلوبایت -
دانلود
2.25.13 700 کیلوبایت -
دانلود
2.25.14 705 کیلوبایت -
دانلود
2.25.15 705 کیلوبایت -
دانلود
2.25.16 705 کیلوبایت -
دانلود
2.25.17 710 کیلوبایت -
دانلود
2.25.18 710 کیلوبایت -
دانلود
2.25.19 711 کیلوبایت -
دانلود
2.25.2 622 کیلوبایت -
دانلود
2.25.20 710 کیلوبایت -
دانلود
2.25.21 712 کیلوبایت -
دانلود
2.25.22 715 کیلوبایت -
دانلود
2.25.23 715 کیلوبایت -
دانلود
2.25.24 715 کیلوبایت -
دانلود
2.25.25 715 کیلوبایت -
دانلود
2.25.26 716 کیلوبایت -
دانلود
2.25.27 716 کیلوبایت -
دانلود
2.25.28 717 کیلوبایت -
دانلود
2.25.29 717 کیلوبایت -
دانلود
2.25.3 623 کیلوبایت -
دانلود
2.25.4 623 کیلوبایت -
دانلود
2.25.5 623 کیلوبایت -
دانلود
2.25.6 623 کیلوبایت -
دانلود
2.25.7 624 کیلوبایت -
دانلود
2.25.8 624 کیلوبایت -
دانلود
2.25.9 626 کیلوبایت -
دانلود
2.26.0 3 مگابایت -
دانلود
2.26.1 3 مگابایت -
دانلود
2.26.10 3 مگابایت -
دانلود
2.26.11 3 مگابایت -
دانلود
2.26.12 3 مگابایت -
دانلود
2.26.13 3 مگابایت -
دانلود
2.26.15 3 مگابایت -
دانلود
2.26.16 3 مگابایت -
دانلود
2.26.17 3 مگابایت -
دانلود
2.25.22 715 کیلوبایت -
دانلود
2.26.18 3 مگابایت -
دانلود
2.26.14 3 مگابایت -
دانلود
2.26.19 3 مگابایت -
دانلود
2.26.2 3 مگابایت -
دانلود
2.26.20 3 مگابایت -
دانلود
2.26.21 3 مگابایت -
دانلود
2.26.21 3 مگابایت -
دانلود
2.26.22 3 مگابایت -
دانلود
2.26.23 3 مگابایت -
دانلود
2.26.24 3 مگابایت -
دانلود
2.26.25 3 مگابایت -
دانلود
2.26.26 3 مگابایت -
دانلود
2.26.27 3 مگابایت -
دانلود
2.26.28 3 مگابایت -
دانلود
2.26.3 3 مگابایت -
دانلود
2.26.4 3 مگابایت -
دانلود
2.26.6 3 مگابایت -
دانلود
2.26.7 3 مگابایت -
دانلود
2.26.8 3 مگابایت -
دانلود
2.26.9 3 مگابایت -
دانلود
2.26.5 3 مگابایت -
دانلود
2.26.5 3 مگابایت -
دانلود
2.3.0 103 کیلوبایت -
دانلود
2.4.0 103 کیلوبایت -
دانلود
×
★★★★★
★★★★★
4.9 /5 (1,449 نظر)

قیمت:

رایگان

نگارش

3.2.0

آخرین انتشار

6 اردیبهشت 1405

آخرین بروزرسانی

2 ماه پیش

نصب های فعال

2,000,000+

نگارش وردپرس

وردپرس 3.0+

تست شده از نسخه

وردپرس 6.9.4

نگارش PHP

-

نسخه ها

123 نسخه