Search Over 30,000 FREE Plugins from the Official WordPress Plugin Directory Repository

Limit Login Attempts Reloaded

Reloaded version of the original Limit Login Attempts plugin for Login Protection by a team of WordPress developers.

Limit the number of login attempts that possible both through the normal login as well as using the auth cookies. WordPress by default allows unlimited login attempts either through the login page or by sending special cookies. This allows passwords (or hashes) to be cracked via brute-force relatively easily. Limit Login Attempts Reloaded blocks an Internet address from making further attempts after a specified limit on retries has been reached, making a brute-force attack difficult or impossible.


  • Limit the number of retry attempts when logging in (per each IP). This is fully customizable.
  • Limit the number of attempts to log in using authorization cookies in the same way.
  • Informs the user about the remaining retries or lockout time on the login page.
  • Optional logging and optional email notification.
  • Handles server behind the reverse proxy.
  • It is possible to whitelist/blacklist IPs and Usernames.
  • XMLRPC gateway protection.
  • Woocommerce login page protection.
  • Multi-site compatibility with extra MU settings.

Upgrading from the old Limit Login Attempts plugin

  1. Go to the Plugins section in your site's backend.
  2. Remove the Limit Login Attempts plugin.
  3. Install the Limit Login Attempts Reloaded plugin.

All your settings will be kept in tact!

Many languages are currently supported in Limit Login Attempts Reloaded plugin but we welcome any additional ones. Help us bring Limit Login Attempts Reloaded to even more cultures.

Translations: Bulgarian, Brazilian Portuguese, Catalan, Chinese (Traditional), Czech, Dutch, Finnish, French, German, Hungarian, Norwegian, Persian, Romanian, Russian, Spanish, Swedish, Turkish

Plugin uses standard actions and filters only.

Based on the original code from Limit Login Attemps plugin by Johan Eenfeldt.

Author wpchefgadget
Contributors wpchefgadget
Tags authentication, Better Limit Login Attempts, limit login attempts, Limit Login Attempts Reloaded, Limit Login Attempts Renewed, Limit Login Attempts Renovated, Limit Login Attempts Revamped, Limit Login Attempts Updated, Limit Login Attempts Upgraded, login, security
  1. limit-login-attempts-reloaded screenshot 1

    Loginscreen after a failed login with remaining retries

  2. limit-login-attempts-reloaded screenshot 2

    Lockout loginscreen

  3. limit-login-attempts-reloaded screenshot 3

    Administration interface in WordPress 4.5.3






  • The site connection settings are now applied automatically and therefore have been removed from the admin interface.
  • Now compatible with PHP 5.2 to support some older WP installations.


Version 2.5.0

Requires WordPress version: 3.0 or higher

Compatible up to: 4.7.2

Last Updated 30 Jan 2017

Date Added: 03 Aug 2016


4.6 stars
9 ratings


Not Enough Data

Works: 0
Broken: 0

Probably Works.
Considering downloads, would expect problems reported.