Lockdown plugin. WordPress protection – Login LockDown plugin. Installing and configuring the Login LockDown security plugin

(Last update: 02.12.2019)

Hi all! Today we'll talk about the security of your WordPress website/blog. To sleep peacefully, you need to ensure safety. The most common way to hack it is to select a password and username to log into your admin panel (protection against this is). If for some reason bad people find out your login, then choosing a password for them will not be difficult.

WordPress Admin: Hacking Protection

Don't wait until your site is hacked before you start caring about security practices. Now is the time to limit the number of login attempts on your WP site. Let us, dear friends, make this task more difficult for attackers. How to limit login attempts in WordPress? Using the free Login LockDown plugin.

Security is a priority when working on any website, so we use every opportunity to ensure it. An additional level of protection is provided by the Login Lockdown plugin. It protects the WordPress admin from hacking by guessing the login password. If an excessive number of login attempts are made from an IP range, when the limit is reached, Login Lockdown blocks all requests from that range.

Every WordPress website owner runs into problems from time to time that could probably be solved with some handy back-end plugins. You don’t need to go fast or far. That's what made WordPress so popular, right? Plugins are convenient and can solve many problems, which is especially useful if you are not a developer or lack professional skills.

WordPress Security – Login LockDown Plugin

An additional level of protection is provided by the Login Lockdown plugin

Plugin for WordPress Login LockDown Limits the number of login attempts from a given range of IP addresses within a specified period of time. It is for reliable protection of your WordPress control panel.

About the Login LockDown plugin

Login LockDown records the IP address and timestamp of each failed login attempt. If more than a certain number of attempts are detected from the same IP address range within a short period of time, the login feature will be disabled for all requests from that range. This helps prevent brute force discovery of the password.

Currently the plugin is blocked by default for 1 hour from the IP block after 3 unsuccessful attempts login within 5 minutes. In other words, you will be blocked for one hour if you enter the password incorrectly 3 times in 5 minutes. This can be changed through the Settings panel. Administrators can release blocked IP ranges manually from the panel.

Installing and configuring plugin

Of course, one plugin cannot completely protect your blog; additional measures are needed, which I will write about on the pages of my blog. But this will happen later, but now please go to the admin panel to install the plugin. Section - Plugins - Add new. Enter the name Login LockDown into the search box:

Search for a plugin

The plugin you are looking for will be the first in the list, click “Install”, then “Activate plugin”:

Installing the plugin using the standard method

The next step is to configure it. Section Settings - click on the name of the module.

WordPress admin protection

On the page that opens - Login Blocking Options - specify:

  • The maximum number of login attempts is for example 3;
  • Limit the repeat time period (minutes) for example, 5;
  • Blocking time in minutes, for example, 180;
  • Blocking invalid usernames? - Yes;
  • Login errors? - Yes.

Plugin settings page

Click "Update Settings". Ready. This is what the admin login form looked like without the plugin:

Login to WordPress admin panel

And now it will be something like this:

Login form with plugin


The first layer of security for your WordPress site is the password itself. You must always choose strong password for your web resource. Just in case, read what to do if you... No website is 100% secure, as bad people always find new ways to bypass security. That is why it is extremely important to maintain full backups your WordPress site.

I hope this post helped you add a login attempt limit to your WordPress site. That's all for me. Good luck to you. All the best friends. Bye bye!

