360 Orbit Login Guard Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Login Guard addresses the most common WordPress attack of all: automated password guessing against /wp-login.php.
- Rate limiting: locks an IP address out after too many failed attempts, for a configurable duration.
- Login history (7 days): every attempt with a pseudonymous fingerprint instead of the raw IP address, success or failure, and the user name tried.
- Generic error messages: never reveals whether a user name exists.
- Safe allowlist behaviour: an IP address from which someone with administrator rights recently signed in successfully is never locked out automatically.
- Disable XML-RPC: closes the known bypass of rate limiting via system.multicall.
- Protection against user name enumeration (?author= parameter and the public REST user list).
- Export and import of all settings as JSON, to set up several sites the same way.
- WP-CLI: inspect the status and unlock IP addresses even when wp-admin itself is unreachable.
Free version vs. Pro
The free version is complete on its own: rate limiting, login history, generic error messages, XML-RPC and enumeration protection, and settings export/import.
Login Guard Pro adds:
- Two-factor authentication (TOTP) for individual accounts or entire roles, compatible with common authenticator apps.
- A custom login URL instead of /wp-login.php, with a 404 for the real address.
- Notification when an account signs in from an unknown device.
- A fixed allow/block list for IP addresses.
- Automatic update notifications directly in the WordPress admin.
Login Guard Pro is a separate plugin available from the author; it is not required to use the free version.
Screenshots
No screenshots provided
