Protect, lockdown & secure login form by limiting login attempts from the same IP & banning IPs.
As of April 2026, Login Lockdown & Protection is a WordPress login plugin with 100K+ active installations and a 4.3/5 rating from 60 reviews. It has been downloaded 1.9M+ times in total. Requires WordPress 4.0+ and PHP 5.2+. Available on WordPress.org since 2008. Download volume is stable this week. Support resolution rate: 100%. Top alternative: WPS Hide Login.
Login Lockdown records the IP address and timestamp of failed login attempts. If more than a selected number of attempts are detected within a set period of time from the same IP, then the login is disabled for all requests from that IP address (or the IP is completely blocked from accessing the site). This secures the site and helps prevent brute force password attacks & discovery.
The plugin defaults to a 1 hour lock out of an IP block after 3 failed login attempts within 5 minutes. This can be modified in options. Administrators can release locked out IPs manually from the panel. A detailed log is available for all failed login attempts and all IP locks to control lockdown.
Configure the plugin from Settings – Login Lockdown.
Block unwanted coun…
This plugin keeps the wp-login.php locked indefinitely even if the 60 minutes have passed.
WP Login Lockdown is free. At one point it did its work discreetly.
It now auto installs a huge widget in the admin dashboard. In the back it covers the entire interface with huge ads. Almost all of the functionality is now pro and is front row and center, with an interface so covered in pro functions it’s impossible use the free plugin.
Frankly this kind of simple functionality should not require a pro plugin at all.
A sad example of the slow degradation of the wonderful WordPress developer community into adware and bloatware.
Should mark WP Login Lockdown two stars really, but will leave it at three stars as it could be useful if way trimmed back again.
This plugin works wonders to protect your WordPress website from brute force attacks. It literally saved my servers where before implementing I had high CPU and memory usage and after installing it cut CPU use by up to 100% and memory by 50%.
It’s not perfect and still has some areas to improve (reporting & unblocking are two) but the core functionality works really really well.
HIGHLY RECOMMENDED!
The plugin looks promising, but things have started that aren’t quite finished…
1) Captcha – It doesn’t show captcha at “lost password”, “woocommerce product comment”, probably somewhere else and no option to enable or simple to show everywhere.. It shows only at login form..
2) 2FA – Two Factor Authentication. There is only email 2FA.. this plugin did not offer the option with “2FA code generating apps such as Google Authenticator, Authy”.. which is very sad..
I always use 2FA code generating apps for everything, and I will never use 2FA email authentication by choice!
It seems that the author is working on too many projects and this particular one doesn’t have too much time to make the plugin really great!
These are the reasons why I don’t use this plugin, if they improve it with this and more other functions, I will give it a chance and install it again.
Currently only 3 stars! ★★★✩✩
After I installed the plugin, I started getting login attempts by the user “Unknown” (on the 3 sites I installed), detected by Wordfence. This is why I changed the login path through the plugin, so in theory, only they could know the login address.
| WordPress | 4.0+ requiredTested up to 6.9.4 |
| PHP | 5.2+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.