WP PowerSuite Early Bird 50% OFF
Launch offer closes in:
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background

Summarize with AI:

On This Page
Last updated: 24/07/2026

Limit Login Attempts

Slow down password-guessing bots by locking out repeated failed logins for increasing cool-off periods—simple protection for your sign-in form.

Overview

A Pro Security module that locks out repeated failed logins with escalating cool-off periods. Defaults: 3 attempts, 15-minute lockout, escalate after 2 lockouts to 30 minutes, 60-minute attempt window. Lock by IP or IP+username; never-block IP allowlist; covers wp-login, Woo, custom login URL, REST, XML-RPC, and application-password failures. Optional logs/geo and generic error messages. Soft stack with Change Login URL and CAPTCHAs; soft overlap with Generic Login Errors if both invent generic messaging. Requires a valid WP PowerSuite license. Shared NAT can lock many users—use allowlist carefully.

Solid black square
Solid black square
Who is this for?
  • Any public login surface
  • Agencies shipping Pro login hardening baselines
  • Teams pairing rate limits with Change Login URL + CAPTCHA

Features

Failed-login lockouts
Cool-off periods that escalate after repeated abuse.
IP or IP+username
Choose the lockout identity model that fits your traffic.
Never-block allowlist
Keep office/VPN IPs from getting locked.
Wide coverage
wp-login, Woo, custom login URL, REST, XML-RPC, app-password failures.
Logs + optional geo
Review abuse patterns over a retention window.
Optional generic errors
Reduce enumeration hints during lockouts.

Use Cases

  • Public membership logins
    Lock out credential stuffing without a full WAF.
  • Woo My Account
    Rate-limit store login abuse.
  • Agency baseline
    Ship Limit Login + Change Login URL + Turnstile on every client.

Frequently Asked Questions

Related Modules

Always open your dashboard and login screen over a secure https:// link. Anyone using the old http:// address is sent to the...
Disabled
Keep a clear record of important dashboard activity—who logged in, what changed, and when—so you can investigate issues or stay audit-ready without...
Disabled
Two-factor login for selected roles—extra proof beyond the password.
Disabled
Disables WordPress application passwords site-wide: blocks REST/XML-RPC login with app tokens and hides the profile UI. Normal account passwords and logged-in REST...
Disabled
Block anonymous access to WordPress core REST endpoints (users, settings, themes, and similar) while leaving logged-in staff and third-party plugin REST routes...
Disabled
Google reCAPTCHA on logins, forms, comments, and WooCommerce to block bots and spam signups.
Disabled
Tell modern browsers to enforce sensible safety rules—like blocking sneaky scripts and iframe tricks—with strong defaults you can tighten further for HSTS...
Disabled
Closes the old XML-RPC channel many password-guessing tools still target. Fine for most sites; skip if you rely on legacy apps or...
Disabled
Turn off public "forgot password" self-service for everyone. Use only when you reset passwords another way (manual admin password, WP-CLI, or admin-sent...
Disabled
Removes WordPress version from public HTML generator tags, feed generator output, and the admin footer. Does not change ver= on script and...
Disabled
EARLY BIRD OFFER ENDS IN:

Before you go, lock in early bird pricing.

WP PowerSuite launched this month, and we're offering 50% off during our early bird launch. Join before 31 August 2026 and your discounted renewal price stays locked for life.

After the offer ends, prices return to $79 / $239 / $399.
See early bird pricing
Early bird offer ends 31 August 2026 - 11 days left