Limit Login Attempts
by Automattic · Login & Users
Also makes 68 other plugins · 18.2M+ installs across the portfolio →
Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.
51 health vs 59 average across 1,440 Login & Users plugins
Removal-risk signals
45/100Maintenance and integrity signals that tend to precede a WordPress.org removal. Not an official status, a heads-up to act.
- Long abandoned. No update in 3+ years — the top precursor to removal once a vulnerability is found.
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Room to improve
Biggest win: Update recency
To rank higher: Last updated 1239 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
4.0K
now · peak 176.9K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
No release in a yearHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
0
releases in the last 12 months
3.4y ago
latest release · v1.7.2
20
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 100% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “300K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-06-01 · 1,500 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ wiitguru1.4y ago
Thanks, Automattic!!!! This plugin has thwarted over 100 hacking attempts on my website in the last few months! I won’t operate without this plugin!!!
Read on wp.org ↗ - ★★★★★ Guido2.7y ago
I absolutely hate bloated plugins, so I love this one. It’s simple and works as expected. Guess it’s wise to use a plugin such as this one, against brute force attacks. Guido
Read on wp.org ↗ - ★★★★★ doreenhawdon2.9y ago
Does what it says on the tin. Like another similar plugin before it became bloatware. The only feature I would request is the ability to send notifications to another email address, I like to keep my admin email clean.
Read on wp.org ↗ - ★★★★★ inakijm5.7y ago
Se lo pone más dicícil a los hackers que quieren acceder a tu blog ya que les limita el número de accesos.
Read on wp.org ↗ - ★★★★★ wroot6.3y ago
Would be good to get new versions and fix possible security issues (if any), but it seems to still work.
Read on wp.org ↗ - ★★★★★ purpslisfeedb6.4y ago
Works very well
Read on wp.org ↗ - ★★★★★ brightvesseldev6.9y ago
We had initial issues and tried again and it is working better. This topic was modified 4 years, 9 months ago by brightvesseldev.
Read on wp.org ↗ - ★★★★★ naimansari6.9y ago
Awesome Plugin
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 1.7.2 Security fixes. 1.7.2
- — Version 1.7.1 This version fixes a security bug in version 1.6.2 and 1.7.0. Please upgrade immediately. “Auth cookies” are special cookies set at login that authenticating you to the system. It is how WordPress “remembers” that you ar 1.7.1
- — Version 1.7.0 Added filter that allows whitelisting IP. Please use with care!! Update to Spanish translation, thanks to Marcelo Pedra Updated Swedish translation Tested against WordPress 3.3.2 1.7.0
- — Version 1.6.2 Fix bug where log would not get updated after it had been cleared Do plugin setup in ‘init’ action Small update to Spanish translation file, thanks to Marcelo Pedra Tested against WordPress 3.2.1 1.6.2
- — Version 1.6.1 (WordPress 3.0+) An invalid cookie can sometimes get sent multiple times before it gets cleared, resulting in multiple failed attempts or even a lockout from a single invalid cookie. Store the latest failed cookie to mak 1.6.1
- — Version 1.6.0 Happy New Year Tested against WordPress 3.1-RC1 Plugin now requires WordPress version 2.8+. Of course you should never ever use anything but the latest version Fixed deprecation warnings that had been piling up with the 1.6.0
Known vulnerabilities
via Wordfence Intelligence3 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 6.4 Limit Login Attempts <= 1.7.1 - Authenticated(Subscriber+) Stored Cross-Site Scripting ↗2023-04-10 CVE-2023-1861 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.7.1 Patched in 1.7.2
- 2023-04-06 CVE-2023-1912 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.7.1 Patched in 1.7.2
- Critical · 9.8 Limit Login Attempts <= 1.7.0 - Brute Force Bypass ↗
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 6.2.1
Languages
via translate.wordpress.orgTranslated into 72 languages, 38 at 90% or more
Plus 48 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-07-10 400K+ → 300K+ down after 388 days in tier
- 2024-06-17 500K+ → 400K+ down after 304 days in tier
- 2023-08-18 600K+ → 500K+ down after 1 days in tier
- 2023-08-17 500K+ → 600K+ up after 4 days in tier
- 2023-08-13 600K+ → 500K+ down after 245 days in tier
- 2022-12-11 700K+ → 600K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
WPS Limit Login 100K+ installs · 4.8★ · 3 shared tags A -
Google Authenticator 20K+ installs · 4.3★ · 3 shared tags A -
Loginizer 1M+ installs · 4.8★ · 2 shared tags A -
Security Optimizer – The All-In-One Protection Plugin 1M+ installs · 4.5★ · 2 shared tags A -
WP Ghost (Hide My WP Ghost) – Security & Firewall 100K+ installs · 4.5★ · 2 shared tags A -
Two Factor 100K+ installs · 4.7★ · 2 shared tags A
Embed this report card
Drop a live Pulse card for Limit Login Attempts into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/limit-login-attempts" width="480" height="300" style="border:0" loading="lazy" title="Limit Login Attempts — Plugin Pulse"></iframe> Limit Login Attempts: 300K+ active installs, 4.6★ (202 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/limit-login-attempts