Plugin Pulse
← Pulse

Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention

by WPChef · Security

Also makes 4 other plugins · 1.0M+ installs across the portfolio →

WordPress login security with brute force protection, Two-factor authentication (2FA/MFA), firewall, IP/country blocking, and login monitoring

How scoring works →
88 Health · A
Maintenance 100/100
Rating quality 97/100
Support 56/100

88 health vs 64 average across 997 Security plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

91 / 100

Excellent listing optimization

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 96/100
Listing tuning 100/100
Support resolution 43/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-10% vs prior 30d
0Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

1.2M

now · peak 5.6M

1.23M30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Limit Login Attempts · #33 you Wordfence Security · #11 All-In-One Security · #62 Anti-Malware Securit · #303

Rating trend

Star average over time · dips mark rough releases

4.8Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

1.2Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

21

releases in the last 12 months

2mo ago

latest release · v3.3.4

128

tagged releases on record

Recent releases

3.3.4 · 2mo ago3.3.3 · 2mo ago3.3.2 · 2mo ago3.3.1 · 2mo ago3.3.0 · 2mo ago3.2.4 · 3mo ago3.2.3 · 3mo ago3.2.2 · 4mo ago3.2.1 · 4mo ago3.2.0 · 4mo ago3.1.0 · 5mo ago3.0.2 · 5mo ago3.0.1 · 5mo ago3.0.0 · 5mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 48% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v3.3 48%
v2.26 25%
v2.25 8.6%
v3.2 8.5%
Older / other versions 11%

Estimated active installs

The public count shows “1M+”. Our estimate pins where the real number sits.

tracked estimate
1M–2M ≈1.5M

Refined from the date this plugin crossed into its current band.

Install history · since 2017-03-28 · 1,463 observations

1MInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.

Details

Version
3.3.5
Last updated
13d ago
Added
2016-08-03 · 10 yrs old
Requires WP
5.0
Tested up to
7.0.4
Requires PHP

Recent review vibe

read from the latest 12 reviews to 2026-07-16
Deteriorating PraiseBroken updatesCompatibility

Older reviews still praise it for stopping brute force attacks, but the newest ones complain about an unwanted weekly and monthly report feature quietly turned on without consent, plus a Cloudflare WAF conflict blocking the 2FA endpoint.

Recent reviews

All reviews on wp.org ↗
  1. apacheleon
    1mo ago

    La versión gratuita que estoy utilizando para mi sencilla pagina web en WordPress funciona a las mil maravillas y no da ningún problema. Muy recomedable.

    Read on wp.org ↗
  2. Van Tran
    2mo ago

    Great Plugin, I really love it

    Read on wp.org ↗
  3. Nikolay Bronskiy
    2mo ago

    Avoid! They silently added useless weekly reports. Basically it is just spam

    Read on wp.org ↗
  4. ellegphoto
    2mo ago

    I feel so much better having installed this on my website. Russian Casino ppl hacked my website and this plugin gives me such peace of mind knowing they cant log in and cause more damage.

    Read on wp.org ↗
  5. ChrisL
    2mo ago

    Without my requesting it, I’m now getting over a hundred weekly and monthly security summary emails from my clients’ websites. Enabling this on existing sites is a very annoying and ill-thought out decision which would take me a couple of hours of mindless clicking to disable. But why would I bother disabling it when it is quite likely that developer of Limit Login Attempts is likely to reenable the unwanted feature when they next update their plugin??@!# Feel free to set the feature to enabled by default on new installations. But existing sites should have the feature disabled by default when introduced in a plugin update.

    Read on wp.org ↗
  6. Ankh247
    2mo ago

    Works well. Just what I needed. Thank you.

    Read on wp.org ↗
  7. spherical
    2mo ago

    Without this service an admin would have no idea of the nefarious activity going on out of sight and right under our noses. Sometimes we get 20 or more notices of attempted logins that are blocked. Those IP#s get added to our growing .htaccess file denying any access at all. Good Work, Guys and Gals! Too bad that it has to be this way. There’s always bad actors lurking and we need all the help we can get. LLAR provides that in spades.

    Read on wp.org ↗
  8. redescristianas
    2mo ago

    This plugin is a lifesaver! It successfully blocked a brute force attack on my website, preventing unauthorized access attempts. The setup was simple and the detailed logs helped me understand what was going on. Highly recommended for any WordPress site owner who takes security seriously.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 3.3.4 Fixed icon positioning. 3.3.4
  2. Version 3.3.3 Fixed the dashboard incorrectly showing a network error when the cloud API is reachable but access is restricted. Fixed a PHP 8.1+ deprecation notice by avoiding implicit float-to-int conversion in the lockout email noti 3.3.3
  3. Version 3.3.2 Improved usage information in cloud mode. 3.3.2
  4. Version 3.3.1 Fixed email digest behavior in cloud mode. 3.3.1
  5. Version 3.3.0 Added daily, weekly, and monthly email digests summarizing lockouts and failed login attempts. 3.3.0
  6. Version 3.2.4 Added compatibility with WordPress 7. Earlier versions For the changelog of earlier versions, please refer to the changelog.txt file. 3.2.4

Known vulnerabilities

via Wordfence Intelligence

4 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2023-12-20 CVE-2023-6934 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.25.26 Patched in 2.25.27
  2. 2023-11-06 CVE-2023-5525 Missing Authorization Affects <= 2.25.25 Patched in 2.25.26
  3. 2020-12-14 CVE-2020-35590 Improper Restriction of Excessive Authentication Attempts Affects <= 2.17.3 Patched in 2.17.4
  4. 2020-12-14 CVE-2020-35589 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.15.2 Patched in 2.17.4

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 41 languages, 10 at 90% or more

Dutch 100%
Dutch (Formal) 100%
English (Australia) 100%
English (New Zealand) 100%
English (UK) 100%
Spanish (Argentina) 100%
Spanish (Chile) 100%
Spanish (Spain) 100%
French (France) 99%
Korean 98%
Norwegian (Bokmål) 86%
English (Canada) 83%
Chinese (Taiwan) 82%
Polish 82%
Asturian 80%
German 79%
German (Formal) 79%
Russian 74%
Catalan 72%
Portuguese (Portugal) 72%
Swedish 71%
Ukrainian 48%
Dutch (Belgium) 33%
Galician 32%

Plus 17 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-05-08 2M+ → 1M+ down after 2 days in tier
  2. 2026-05-06 1M+ → 2M+ up after 1 days in tier
  3. 2026-05-05 2M+ → 1M+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/limit-login-attempts-reloaded" width="480" height="300" style="border:0" loading="lazy" title="Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention — Plugin Pulse"></iframe>
Preview card ↗

Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention: 1M+ active installs, 4.8★ (1,477 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/limit-login-attempts-reloaded