Advanced IP Blocker
Advanced IP Blocker is your all-in-one security solution to safeguard your WordPress website from a wide range of threats. This plugin provides a comprehensive suite of tools to automatically detect and block malicious activity, including brute-force attacks, vulnerability scanning, and spam bots. With its intuitive interface, you can easily manage whitelists, blocklists, and view detailed security logs to understand exactly how your site is being protected. Important Note on PHP Version: To ensure maximum security and access to all features, we strongly recommend using PHP 8.1 or higher. Some advanced features (like the local MaxMind database or full 2FA management via WP-CLI) require PHP 8.1. Key Features: * (NEW) File Integrity Scanner (Beta): Instantly detect unauthorized changes to core WordPress files and your active plugins/themes. A vital tool to detect malware infections or backdoor placements on your server. * (NEW) Admin Access Control: Granular control over which administrators can access the plugin’s configuration dashboard. Restrict plugin management while keeping firewall rules intact for all editors and admins. * (NEW) Hardening & Core Protection: Powerful tools to disable WordPress application passwords, turn off the dangerous built-in file editor, block PHP execution in the uploads folder, and hide the WordPress version from attackers. * (NEW) Intelligent Zero-Day WAF Sync: Automatically download and apply critical WAF signatures from the AIB Central Server every day. Stay protected against zero-day vulnerabilities (like wp2shell) without needing to update the plugin manually! The rules run completely independent of your custom WAF configuration. * (NEW) Block Ghost IPs: Automatically block IPs without ASN and Reverse DNS to stop anonymous traffic (Warning: Could cause false positives if rDNS is misconfigured by ISPs). * (NEW) Captcha Integrations (Turnstile & hCaptcha): Seamlessly integrate modern verification challenges like Cloudflare Turnstile and hCaptcha, with granular control per module and a smart fallback to our invisible JS Challenge to prevent accidental lockouts. * (NEW) Rate Limiting Advanced Rules: Create highly specific rate limits for different endpoints. For example, set a strict limit with a Turnstile challenge for /login, while keeping a more generous limit with a temporary block for your main API, all without affecting the rest of the site. * (NEW) Distributed Attack Protection (Auto-Panic): Automatically shields your entire site with a global JS challenge during massive traffic spikes, keeping your server online while intelligently bypassing trusted bots and excluded routes. * IP & ASN Diagnostics Tool: A complete Inspector tool integrated directly into the admin bar. Quickly audit any IP or ASN against your Geolocation database, Threat Scoring system, Spamhaus drops, and manual blocking rules in real-time. * Advanced Rules Import/Export: Seamlessly migrate or backup your complex custom security rules across multiple WordPress websites. With full JSON validation, structural deduplication, and “cost-zero” client-side file generation, agency users can clone their perfect firewall setups in seconds. * Granular JS Challenge Modes: You can now choose exactly how the security challenge behaves. Select “Managed” for ultimate security requiring human interaction (a checkbox), or “Automatic” for an invisible, transparent Proof-of-Work execution that stops bots silently. Apply different modes per module! * Country Selector Copy/Paste: Say goodbye to manually selecting 50+ countries. You can now instantly copy and paste a raw list of 2-letter country codes directly into Geoblocking, Geo-Challenge, and Whitelist Login fields. * AIB Cloud Network V3: Upgrade to the next-generation distributed threat intelligence network. The new API V3 provides secure, individual API Keys per site, drastically improving synchronization reliability, threat telemetry, and global network stability. * Whitelist Login Countries: Take absolute control over administrative access. Easily restrict your WordPress login page and XML-RPC to only allow connections from specific, whitelisted countries, instantly blocking unauthorized foreign login attempts. * (IMPROVED) Bulk Import/Export for Blocked IPs & Whitelist: Seamlessly import massive lists of IPs via CSV or manual entry. The system now features a bulletproof “Bulk Import” type, strict duration inheritance, and intelligent conflict resolution. * Internal Security & Forensics: A complete audit suite solely for WordPress. Track every sensitive event (plugin installs, settings changes, user logins) and monitor your critical files for unauthorized modifications with the integrated File Integrity Monitor. * Activity Audit Log: Gain complete visibility into what’s happening on your site. Who deactivated a plugin? Who changed a setting? The Audit Log answers these questions with timestamped, immutable records. * Deep Scan Email Reports: Get a weekly security summary delivered to your inbox, detailing pending updates, vulnerability status, and recent attack trends. * Username Blocking & Rules: Gain granular control over login security. Creating Advanced Rules to block, challenge, or score specific usernames (e.g., “admin”, “test”). * Enhanced Lockdown Notifications: Distributed Lockdowns (404/403) now fully support Email and Push notifications, ensuring you never miss a critical security event. * Improved Logging: New “Endpoint Challenge” event type provides deeper visibility into challenges served during automated lockdowns. * Server IP Reputation Check. Instantly audit your web server’s IP address against major blacklists (Spamhaus, AbuseIPDB) to diagnose SEO and email delivery issues. * **HTTP Security Headers. Easily configure essential security headers like HSTS, X-Frame-Options, and Permissions-Policy to harden your site against clickjacking, sniffing, and other browser-based attacks. Includes a “Report-Only” mode for CSP. * Site Health & Vulnerability Scanner. Audit your WordPress environment instantly. Detects outdated plugins, insecure PHP versions, and checks your installed plugins against a database of 30,000+ known vulnerabilities. * **PERFORMANCE BOOST: High-Speed Community Database. Migrated the “Community Defense Network” blocklist to a dedicated, indexed database table. This allows checking thousands of malicious IPs in microseconds with zero impact on site memory usage. * **Community Defense Network. Join forces with other WordPress admins. The plugin now shares anonymous attack data to build a global, real-time blocklist of verified threats. Protect your site with community-powered intelligence. * **Auto-Cleaning Logic. Smart expiration handling ensures your blocklists stay fresh and performant, automatically removing stale IPs from both the database and external firewalls (Cloudflare/.htaccess). * **Cloud Edge Defense (Cloudflare). Connect your site directly to Cloudflare’s global network. Automatically sync your blocklists to the cloud to stop attackers before they reach your server. Zero server load protection. * **Server-Level Firewall (.htaccess). Extreme performance upgrade. Write blocking rules and file hardening protections directly to your .htaccess file. Blocks threats instantly without loading PHP or WordPress. * **IMPROVED: Smart Bot Verification. Enhanced logic to correctly identify legitimate traffic from iOS devices (iCloud Private Relay) and social media previews, eliminating false positives while keeping impostors out. * **File Hardening. Protect your most sensitive files (wp-config.php, readme.html, .git) at the server level with a single click. * AbuseIPDB Integration. Proactively block attackers before they strike. The plugin can now check visitor IPs against AbuseIPDB’s real-time, crowdsourced database of malicious IPs and block those with a high abuse score on their very first request. * Edge Firewall Mode! Protect any PHP file or standalone application within your WordPress directory (even if it’s not part of WordPress). Ideal for securing custom scripts, legacy applications, or folders like /scan/. (Requires manual configuration). * Advanced Rules Engine! Create powerful, custom security rules with multiple conditions (IP, Country, ASN, URI, User-Agent, Request Method, Referer) and actions (Block, Challenge, or add Threat Score). * Known Bot Verification. A powerful new security layer that uses reverse DNS lookups to verify legitimate crawlers like Googlebot and Bingbot. This completely neutralizes attackers who try to bypass security rules by faking their User-Agent, assigning high threat scores to impostors. * Verify Monitoring Bots (IP List). A brand new feature that downloads and caches official IP lists from popular uptime monitoring services (like UptimeRobot and Pingdom) to ensure they are never incorrectly blocked or challenged. * Onboarding Setup Wizard. A brand new step-by-step wizard that guides new users through the essential security configurations (IP whitelisting, WAF, and bot traps) in under a minute, ensuring a strong security posture from day one. * Major Refactor: Codebase Modernization. The entire plugin architecture has been refactored into a modern, modular structure. Logic for admin pages, AJAX, actions, and settings is now handled by dedicated classes, making the plugin more stable, performant, and easier to maintain and extend in the future. * Advanced IP Spoofing Protection. A zero-trust “Trusted Proxies” system ensures the plugin always identifies the true visitor IP, even behind complex setups like Cloudflare or a custom reverse proxy. It neutralizes attacks that attempt to fake their IP, preventing block evasion and the framing of innocent users. * Geo-Challenge. A smarter way to handle traffic from high-risk countries. Instead of a hard block, it presents a quick, invisible JavaScript challenge that stops bots but is seamless for human visitors. This reduces unwanted traffic without affecting potential legitimate users. * ENHANCEMENT: Full Bulk-Action Support. IP management is now faster than ever. Both the Whitelist and the Blocked IPs list now support full bulk actions, allowing you to select and remove multiple entries at once, or unblock all IPs with a single click. * Endpoint Lockdown Mode: Automatically shields wp-login.php and xmlrpc.php with a JavaScript challenge during sustained distributed attacks, preventing server overload. * Two-Factor Authentication (2FA): Secure user accounts with industry-standard TOTP authentication, backup codes, role enforcement, and a central admin management dashboard. * IP Trust & Threat Scoring System: An intelligent defense that assigns “threat points” to IPs for malicious actions, blocking them only when they reach a configurable score. More accurate and context-aware than simple rules. * Attack Signature Engine: Proactively stops distributed botnet attacks by identifying and blocking the attacker’s “fingerprint” (signature) instead of just individual IPs. * Web Application Firewall (WAF): Block malicious requests (SQLi, XSS, etc.) with a customizable ruleset. * File Integrity Monitor & Quarantine Vault: Automatically scans WordPress core files and the uploads directory for malware, unauthorized modifications, and hidden PHP shells. Safely neutralize threats by moving them to an encrypted Quarantine Vault. * And much more: Rate Limiting, Country & ASN Blocking (with Spamhaus support), ASN Whitelisting, Push Notifications, Google reCAPTCHA, Honeypots, Active User Session Management, and Full WP-CLI Support.
Top keywords
- security17×1.06%
- ip14×0.87%
- rules13×0.81%
- wordpress13×0.81%
- block12×0.75%
- ips12×0.75%
- php11×0.68%
- challenge10×0.62%
- site10×0.62%
- file9×0.56%
- now9×0.56%
- server9×0.56%
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention
Protect your WordPress website against brute force attacks, bot attacks, and unauthorized login attempts with one of the most trusted login security plugins for WordPress. Limit Login Attempts Security strengthens your WordPress login security by limiting failed login attempts, blocking malicious IPs, securing wp-login.php, protecting XML-RPC, and adding powerful firewall and 2FA protection without slowing down your website. Trusted by 2 million WordPress websites, Limit Login Attempts Security is designed specifically to protect the most targeted part of your website: the login page. Why Use Limit Login Attempts Security? By default, WordPress allows unlimited login attempts. This creates a major security vulnerability where bots and attackers can repeatedly guess usernames and passwords until they gain access. This is especially important in the age of AI, where attackers now have access to faster and more sophisticated tools than ever before. Limit Login Attempts Security helps stop: Brute force attacks Bot login attacks Credential stuffing attacks XML-RPC attacks Unauthorized login attempts WooCommerce login abuse Malicious IP access attempts The plugin automatically blocks excessive login attempts and locks out suspicious IP addresses and usernames before attackers can gain access. Features Included in the Free Version Login Security & Brute Force Protection Limit login attempts by IP address and username Automatically lock out suspicious login activity Adjustable lockout duration and retry limits Protect wp-login.php from automated attacks Prevent brute force login attacks 2FA / Multi-Factor Authentication (MFA) Built-in two-factor authentication (2FA) Add an additional layer of login protection Improve WordPress account security Secure administrator and user logins Firewall & Bot Protection Block malicious login requests Detect suspicious login behavior Reduce bot-based login attacks Lightweight firewall-focused login protection WooCommerce & Plugin Compatibility Protects: WooCommerce login pages XML-RPC login requests Custom login pages WordPress multisite installations Compatible With: Wordfence Sucuri Ultimate Member MemberPress WPS Hide Login Cloudflare and reverse proxy setups Login Monitoring & Notifications Failed login attempt logs Lockout email notifications Denied attempt tracking Login retry visibility for users Access Controls IP safelist and denylist support Username safelist and denylist support IPv6 range support Custom IP origin configuration Premium Features (Start Your Free 14 Day Trial) Upgrade to Limit Login Attempts Security Premium to extend protection with cloud-based login security and advanced attack prevention. Advanced Cloud Protection Real-time malicious IP intelligence Global denylist protection Synchronized lockouts across websites Auto IP denylist generation Cloud-based login attack mitigation Enhanced Performance Protection Offload excessive failed login requests from your server Reduce server strain during attacks Improve stability under heavy attack conditions Advanced Security Features Country-based login blocking Enhanced throttling and lockout escalation Registration page protection Successful login tracking Enhanced lockout analytics and geolocation data Multi-Site & Team Features Shared safelist and denylist syncing Shared lockout protection between domains Cloud backups of IP security data CSV exports of login and IP activity Premium Support Access to security-focused support specialists Faster troubleshooting and assistance Lightweight Security Built for WordPress Unlike many large security suites, Limit Login Attempts Security focuses specifically on login security and brute force protection. This means: Faster performance Less server overhead Easier configuration Strong protection without unnecessary bloat Protect More Than Just wp-login.php Limit Login Attempts Security secures: wp-login.php XML-RPC WooCommerce logins Custom login forms Registration pages Multisite logins Trusted by Millions of WordPress Websites Limit Login Attempts Security is one of the most widely used WordPress login security plugins and has helped protect millions of websites from brute force attacks and malicious login activity. Whether you run: A personal blog WooCommerce store Membership website Agency Business website Enterprise WordPress network Limit Login Attempts Security helps secure your login experience with modern WordPress login protection. Upgrading from the Original Limit Login Attempts Plugin? Switching is easy: Remove the old Limit Login Attempts plugin Install Limit Login Attempts Security Your settings will remain intact Translation Support Currently translated into multiple languages including: Spanish French German Dutch Turkish Swedish Russian Romanian Chinese (Traditional) Brazilian Portuguese And more Secure Your WordPress Login Today Install Limit Login Attempts Security and protect your WordPress website with: Login security Two-Factor Authentication (2FA) Brute force protection Firewall security Bot protection XML-RPC protection WooCommerce login protection Without slowing down your website.