Protect your site from automated logins efficiently!
As of April 2026, Orbisius Limit Logins is a WordPress login plugin with 10 active installations and a 0/5 rating0. It has been downloaded 3.2K+ times in total. Requires WordPress 2.6+ and PHP false+. Available on WordPress.org since 2014. Last updated 11 years ago — may have compatibility concerns. Top alternative: WPS Hide Login.
This plugin logs and blocks IP address of users who try to login with known bad usernames such as admin, adm etc.
The plugin intentionally hooks very early (plugins_loaded hook) in order to determine if the user should be blocked or not because that way WordPress doesn’t have to waste resources if the user is supposed to be blocked.
It stores the IP address in the uploads folder (.htaccess protected) so it doesn’t hit the database for the ip checks. This may not work on some setups.
The user will get blocked in these cases:
– Tries to login using one of the bad usernames (admin, adm, root, administrator)
– Tries 7 or more ties to guess any password of any user
Note: If you still have an account whose username matches the logins mentioned above please create a new a…
| WordPress | 2.6+ requiredTested up to 4.1.42 |
| PHP | false+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.