Plugin Pulse
← Pulse

Limit Login Attempts (Spam Protection)

by wp-buy · Security

Also makes 13 other plugins · 345.2K+ installs across the portfolio →

Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.

⚠ Stale⚠ Few reviews
How scoring works →
64 Health · C
Maintenance 53/100
Rating quality 72/100
Support 70/100

64 health vs 63 average across 997 Security plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

78 / 100

Well optimized

Biggest win: Update recency

Update recency 60/100
WP compatibility 100/100
Rating quality 58/100
Listing tuning 100/100

To rank higher: Last updated 443 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,427 days · wp.org + Plugin Pulse archive

+21% vs prior 30d
4Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

130

now · peak 594

13030d downloads · Sep 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Limit Login Attempts · #12071 you NinjaFirewall (WP Ed · #350 Zero Spam for WordPr · #1193 Forget Spam Comment · #2210

Rating trend

Star average over time · dips mark rough releases

3.9Stars · Sep 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

650per 1k installs · Sep 26

Release cadence

No release in a year
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

0

releases in the last 12 months

1.2y ago

latest release · v5.6

21

tagged releases on record

Recent releases

5.6 · 1.2y ago5.5 · 1.8y ago5.4 · 1.9y ago5.3 · 2.6y ago5.2 · 3.4y ago5.1 · 3.4y ago4.9.1 · 4.5y ago4.9 · 4.5y ago4.8 · 4.5y ago4.7 · 4.7y ago4.6 · 4.8y ago4.5 · 4.9y ago4.4 · 5.0y ago4.3 · 5.1y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 93% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v5.6 93%
v5.3 7.2%

Estimated active installs

The public count shows “200+”. Our estimate pins where the real number sits.

tracked estimate
200–300 ≈250

Refined from the date this plugin crossed into its current band.

Install history · since 2022-07-19 · 1,383 observations

200Installs · Sep 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.

Details

Version
5.6
Last updated
1.2y ago
Added
2020-02-20 · 6 yrs old
Requires WP
4.6
Tested up to
6.8.8
Requires PHP
7.2

Recent reviews

All reviews on wp.org ↗
  1. thecelticcroft
    4.1y ago

    I contacted my server host for help because this plugin keeps telling me that my site is under possible brute-force attack. I change lockout settings to lockout for 4 days following a failed attempt, but this plugin’s log was still apparently filling up with failed attempts and lockouts for the same couple of accounts that shouldn’t have been possible if it was doing it’s job. So I provided a list of IP addresses to my server host, and they checked logs at the server level and said there was no sign that any of those IP addresses had attempted to log into the site. I uninstalled the plugin. This topic was modified 3 years, 10 months ago by thecelticcroft. This topic was modified 3 years, 10 months ago by thecelticcroft.

    Read on wp.org ↗
  2. rickgravelin
    5.3y ago

    With this tool I realize that after two weeks of being live our site has had world renown popularity. Every Continet, evey country and sovergnty has recognized us, yet only 6 out of 171 of our council members have signed on to use our site. Thank you for showing me this.

    Read on wp.org ↗
  3. bonaventuradibello
    5.7y ago

    A good solution if you don’t use heavier plugins like WordFence or Ithemes Security.

    Read on wp.org ↗
  4. ahmednabubaker
    5.8y ago

    Really a helpful plugin. Support is very active too. This topic was modified 5 years, 8 months ago by ahmednabubaker.

    Read on wp.org ↗
  5. mohmmed alagha
    5.8y ago

    Working fine, thank you.

    Read on wp.org ↗
  6. bigfly
    5.8y ago

    Installed it to try dealing with brute force attacks and it successfully logs all failed attempts but never locked them out. Yes, it was enabled and set to 3 invalid logins. Lockout period was increased too but they kept coming. Uninstlled.

    Read on wp.org ↗
  7. CODEPRESS
    6.5y ago

    Working fine, Recommended

    Read on wp.org ↗

Known vulnerabilities

via Wordfence Intelligence

5 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2024-12-05 CVE-2024-54234 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.5 Patched in 5.6
  2. 2024-10-07 CVE-2022-4534 Use of Less Trusted Source Affects <= 5.3 Patched in 5.4
  3. 2022-03-02 CVE-2022-0787 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.9.1 Patched in 5.1
  4. 2021-04-22 Cross-Site Request Forgery (CSRF) Affects <= 2.9 Patched in 3.1
  5. 2021-04-22 CVE-2021-24194 Improper Authorization Affects < 2.9 Patched in 2.9

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 6.7.2

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 3 languages, 0 at 90% or more

Spanish (Spain) 87%
Swedish 54%
Spanish (Ecuador) 14%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-02-27 100+ → 200+ up after 1 days in tier
  2. 2026-02-26 200+ → 100+ down after 15 days in tier
  3. 2026-02-11 100+ → 200+ up after 2 days in tier
  4. 2026-02-09 200+ → 100+ down after 5 days in tier
  5. 2026-02-04 100+ → 200+ up after 1 days in tier
  6. 2026-02-03 200+ → 100+ down after 2 days in tier
  7. 2026-02-01 100+ → 200+ up after 10 days in tier
  8. 2026-01-22 200+ → 100+ down after 2 days in tier

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Limit Login Attempts (Spam Protection) into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/wp-limit-failed-login-attempts" width="480" height="300" style="border:0" loading="lazy" title="Limit Login Attempts (Spam Protection) — Plugin Pulse"></iframe>
Preview card ↗

Limit Login Attempts (Spam Protection): 200+ active installs, 3.9★ (7 reviews). Plugin Pulse (WP Mayor), as of 2026-09-01. https://plugins.wpmayor.com/plugin/wp-limit-failed-login-attempts