Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention
by WPChef · Security
Also makes 4 other plugins · 1.0M+ installs across the portfolio →
WordPress login security with brute force protection, Two-factor authentication (2FA/MFA), firewall, IP/country blocking, and login monitoring
88 health vs 64 average across 997 Security plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
1.2M
now · peak 5.6M
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
21
releases in the last 12 months
2mo ago
latest release · v3.3.4
128
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 48% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “1M+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2017-03-28 · 1,463 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent review vibe
read from the latest 12 reviews to 2026-07-16Older reviews still praise it for stopping brute force attacks, but the newest ones complain about an unwanted weekly and monthly report feature quietly turned on without consent, plus a Cloudflare WAF conflict blocking the 2FA endpoint.
Recent reviews
All reviews on wp.org ↗- ★★★★★ apacheleon1mo ago
La versión gratuita que estoy utilizando para mi sencilla pagina web en WordPress funciona a las mil maravillas y no da ningún problema. Muy recomedable.
Read on wp.org ↗ - ★★★★★ Van Tran2mo ago
Great Plugin, I really love it
Read on wp.org ↗ - ★★★★★ Nikolay Bronskiy2mo ago
Avoid! They silently added useless weekly reports. Basically it is just spam
Read on wp.org ↗ - ★★★★★ ellegphoto2mo ago
I feel so much better having installed this on my website. Russian Casino ppl hacked my website and this plugin gives me such peace of mind knowing they cant log in and cause more damage.
Read on wp.org ↗ - ★★★★★ ChrisL2mo ago
Without my requesting it, I’m now getting over a hundred weekly and monthly security summary emails from my clients’ websites. Enabling this on existing sites is a very annoying and ill-thought out decision which would take me a couple of hours of mindless clicking to disable. But why would I bother disabling it when it is quite likely that developer of Limit Login Attempts is likely to reenable the unwanted feature when they next update their plugin??@!# Feel free to set the feature to enabled by default on new installations. But existing sites should have the feature disabled by default when introduced in a plugin update.
Read on wp.org ↗ - ★★★★★ Ankh2472mo ago
Works well. Just what I needed. Thank you.
Read on wp.org ↗ - ★★★★★ spherical2mo ago
Without this service an admin would have no idea of the nefarious activity going on out of sight and right under our noses. Sometimes we get 20 or more notices of attempted logins that are blocked. Those IP#s get added to our growing .htaccess file denying any access at all. Good Work, Guys and Gals! Too bad that it has to be this way. There’s always bad actors lurking and we need all the help we can get. LLAR provides that in spades.
Read on wp.org ↗ - ★★★★★ redescristianas2mo ago
This plugin is a lifesaver! It successfully blocked a brute force attack on my website, preventing unauthorized access attempts. The setup was simple and the detailed logs helped me understand what was going on. Highly recommended for any WordPress site owner who takes security seriously.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 3.3.4 Fixed icon positioning. 3.3.4
- — Version 3.3.3 Fixed the dashboard incorrectly showing a network error when the cloud API is reachable but access is restricted. Fixed a PHP 8.1+ deprecation notice by avoiding implicit float-to-int conversion in the lockout email noti 3.3.3
- — Version 3.3.2 Improved usage information in cloud mode. 3.3.2
- — Version 3.3.1 Fixed email digest behavior in cloud mode. 3.3.1
- — Version 3.3.0 Added daily, weekly, and monthly email digests summarizing lockouts and failed login attempts. 3.3.0
- — Version 3.2.4 Added compatibility with WordPress 7. Earlier versions For the changelog of earlier versions, please refer to the changelog.txt file. 3.2.4
Known vulnerabilities
via Wordfence Intelligence4 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 6.4 Limit Login Attempts Reloaded <= 2.25.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2023-12-20 CVE-2023-6934 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.25.26 Patched in 2.25.27
- 2020-12-14 CVE-2020-35590 Improper Restriction of Excessive Authentication Attempts Affects <= 2.17.3 Patched in 2.17.4
- 2020-12-14 CVE-2020-35589 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.15.2 Patched in 2.17.4
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 41 languages, 10 at 90% or more
Plus 17 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-05-08 2M+ → 1M+ down after 2 days in tier
- 2026-05-06 1M+ → 2M+ up after 1 days in tier
- 2026-05-05 2M+ → 1M+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Wordfence Security – Firewall, Malware Scan, and Login Security 5M+ installs · 4.7★ · 3 shared tags A
-
All-In-One Security (AIOS) – Security and Firewall 1M+ installs · 4.7★ · 3 shared tags A -
Anti-Malware Security and Brute-Force Firewall 100K+ installs · 4.9★ · 3 shared tags A -
WP Ghost (Hide My WP Ghost) – Security & Firewall 100K+ installs · 4.5★ · 3 shared tags A -
Defender Security – Malware Scanner, Login Security & Firewall 80K+ installs · 4.8★ · 3 shared tags A -
Wordfence Login Security 60K+ installs · 3.9★ · 3 shared tags B
Embed this report card
Drop a live Pulse card for Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/limit-login-attempts-reloaded" width="480" height="300" style="border:0" loading="lazy" title="Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention — Plugin Pulse"></iframe> Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention: 1M+ active installs, 4.8★ (1,477 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/limit-login-attempts-reloaded