Skip to content
WordPress.org

Ch’ti

  • Themes
  • Plugins
  • About
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

360 Orbit Login Guard

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

360 Orbit Login Guard

By Jörg Liwa
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Login Guard addresses the most common WordPress attack of all: automated password guessing against /wp-login.php.

  • Rate limiting: locks an IP address out after too many failed attempts, for a configurable duration.
  • Login history (7 days): every attempt with a pseudonymous fingerprint instead of the raw IP address, success or failure, and the user name tried (only readable if the account exists).
  • Generic error messages: never reveals whether a user name exists.
  • Safe allowlist behaviour: an IP address from which someone with administrator rights recently signed in successfully is only locked out after ten times the usual number of failed attempts, so a few typos never lock you out.
  • Disable XML-RPC: closes the known bypass of rate limiting via system.multicall.
  • Protection against user name enumeration (?author= parameter and the public REST user list).
  • Export and import of all settings as JSON, to set up several sites the same way.
  • WP-CLI: inspect the status and unlock IP addresses even when wp-admin itself is unreachable.

Free version vs. Pro

The free version is complete on its own: rate limiting, login history, generic error messages, XML-RPC and enumeration protection, and settings export/import.

Login Guard Pro adds:

  • Two-factor authentication (TOTP) for individual accounts or entire roles, compatible with common authenticator apps.
  • A custom login URL instead of /wp-login.php, with a 404 for the real address.
  • Notification when an account signs in from an unknown device.
  • A fixed allow/block list for IP addresses.
  • Automatic update notifications directly in the WordPress admin.

Login Guard Pro is a separate plugin available from the author; it is not required to use the free version.

Screenshots

Status overview with currently locked IP addresses and the most recent login attempts.
Status overview with currently locked IP addresses and the most recent login attempts.
Settings: rate limiting, generic error messages, proxy header handling and lockout notification.
Settings: rate limiting, generic error messages, proxy header handling and lockout notification.

Installation

  1. Upload the plugin ZIP under Plugins → Add New → Upload Plugin, or install it from the plugin directory.
  2. Activate the plugin.
  3. Open the Login Guard menu and review the defaults under “Settings” (they already suit most sites).

FAQ

Can I lock myself out?

This is exactly the scenario the safety net protects against: an IP address from which a person with administrator rights recently signed in successfully is only locked out after ten times the usual number of failed attempts. In addition, every lockout can be lifted with one click under “Status & Lockouts”, and if wp-admin is unreachable, via WP-CLI (wp 360-orbit-login-guard unlock <ip>).

Are raw IP addresses stored?

No. The login history only stores a pseudonymous fingerprint (a hash of the IP address and a secret random value generated by the plugin). The plugin does not send any data to external services.

What happens on deactivation?

Rate limiting and all other protections stop immediately and the daily clean-up cron job is unscheduled. The existing login history and all settings are kept and are back immediately after reactivation. Only “Delete” in the plugin list removes them permanently.

Which languages does the admin interface support?

The admin interface follows the language configured in WordPress. Translations are delivered as WordPress.org language packs (translate.wordpress.org, text domain 360-orbit-login-guard); German is maintained by the author. You are welcome to contribute further languages there.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“360 Orbit Login Guard” is open source software. The following people have contributed to this plugin.

Contributors
  • Jörg Liwa

Translate “360 Orbit Login Guard” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.0.17

  • The 360 WP Orbit overview now also lists the new plugin 360 Orbit Database Cleaner.

Meta

  • Version 1.0.17
  • Last updated 6 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.4 or higher
  • Tested up to 7.1.3
  • PHP version 8.1 or higher
  • Language
    English (US)
  • Tags
    Brute Forcelimit login attemptsloginsecurity
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • Jörg Liwa

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Support
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

Ch’ti

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry.