Title: DadsFam Login Security
Author: dadsfam
Published: <strong>September 16, 2026</strong>
Last modified: October 2, 2026

---

Search plugins

![](https://ps.w.org/dadsfam-login-security/assets/banner-772x250.png?rev=3697870)

![](https://ps.w.org/dadsfam-login-security/assets/icon-256x256.png?rev=3697870)

# DadsFam Login Security

 By [dadsfam](https://profiles.wordpress.org/dadsfam/)

[Download](https://downloads.wordpress.org/plugin/dadsfam-login-security.2.6.1.zip)

 * [Details](https://pcd.wordpress.org/plugins/dadsfam-login-security/#description)
 * [Reviews](https://pcd.wordpress.org/plugins/dadsfam-login-security/#reviews)
 *  [Installation](https://pcd.wordpress.org/plugins/dadsfam-login-security/#installation)
 * [Development](https://pcd.wordpress.org/plugins/dadsfam-login-security/#developers)

 [Support](https://wordpress.org/support/plugin/dadsfam-login-security/)

## Description

**DadsFam Login Security** protects the most-attacked part of your WordPress site—
the login form — without making you read a manual or fiddle with servers.

Most login plugins count wrong passwords and lock out whoever hits the number. That
works on bots, and it also locks out your customer who mistyped twice on the same
office connection a bot happens to be using. Version 2.0 gives the plugin its own
Brain, running entirely on your site, so it can tell the two apart.

#### The Brain (free, and it never phones home)

 * **Ask the Brain.** Type a question the way you would ask a person — “is my site
   safe?”, “why can’t Sarah sign in?”, then “unlock her”; “how many attacks this
   month?”, then “and last month?” — and it answers from your own site’s data with
   the numbers, a small chart and the fix as one button. It forgives typos, answers
   in Afrikaans when you ask in Afrikaans, explains every feature, and lives on 
   your dashboard and the WordPress dashboard. Its own language engine runs on your
   site; nothing is sent to an AI service.
 * **Lost phone? One sentence.** “Who is signed in right now?” or “sign Sarah out
   of every device”.
 * **A heat-map of when attacks come**, and a diary of everything the Brain did 
   by itself.
 * **The Brain’s weekly letter** (optional): its plain-English story of the week,
   emailed every Monday.
 * **It learns your real people.** Every correct password teaches it what a real
   sign-in on your site looks like. Every attempt on a username that does not exist
   teaches it what a bot looks like. It only learns from facts, never from its own
   guesses.
 * **It checks its own work.** When a real person it had doubted signs in, it notes
   the mistake; twice in a month and it demands more certainty before it acts.
 * **It learns which usernames only bots use.** Once several different addresses
   try a name nobody on your site has, one try is enough to lock them out — never
   on a network your people use.
 * **It learns from DadsFam AntiSpam.** An address caught spamming your forms is
   treated with suspicion if it then tries to sign in.
 * **It shows which real accounts are being guessed**, and tells the week’s story
   in plain English.
 * **A browser that has signed in before is never locked out by its address.** Its
   typos do not count, even on a shared connection that is being attacked. (After
   a generous number of misses the normal rules apply again, in case a laptop is
   stolen.)
 * **Obvious bots are locked out on the first try** — but only when it is almost
   certain and two hard clues agree, like a script with no browser posting straight
   at the form. A real browser cannot trip it.
 * **Every attempt is explained in plain words:** “97% bot: posted straight at the
   sign-in form without opening it, no language setting.”
 * **Autopilot.** During an attack it raises the shields (strangers get half the
   tries and a longer time-out), keeps whole attacking networks away for a day, 
   then three, then a week — and lowers everything again once it is quiet. Networks
   your people use are never touched.
 * **Unlock by email.** A locked-out person can email themselves a one-time unlock
   link. It only ever goes to the account’s own email address.
 * **Self-repair.** Every day and after every update it checks its own setup and
   fixes what is safe to fix — like the Cloudflare setting that lets one bot lock
   everybody out — then tells you what it did.
 * **Remote control.** On WordPress 6.9+ every action is available as a WordPress
   Ability, so an assistant you trust can check your login security or let someone
   back in.

#### Everything else you get (free)

 * **Smart lockouts** — after too many wrong passwords an address is paused, and
   repeat offenders get a much longer time-out. Choose Relaxed, Balanced or Strict
   with one click.
 * **Instant lockout for bot usernames** — “admin”, “root” and friends lock a bot
   out on the first try, unless someone on your site really uses that name.
 * **Never lock me out** — one click adds your own address to the allow list.
 * **Allow and deny lists** — single addresses, ranges and wildcards.
 * **Activity log** — every sign-in, wrong password, lockout and block, with the
   Brain’s verdict, search, filters and CSV export.
 * **Invisible bot trap and generic error messages** — bots cannot tell whether 
   a username exists.
 * **Hardening** — block username discovery, switch off XML-RPC and pingbacks.
 * **Email alerts** — when someone is locked out, and (optionally) when a person
   signs in from a browser and network they have never used.
 * **Cloudflare and proxy support** — reads the real visitor address, safely.
 * **A recovery switch** — add DFLS_DISABLE_LOCKOUTS to wp-config.php and nobody
   is locked out until you remove it.

#### Privacy

Everything the Brain knows stays in your WordPress database. Nothing is sent to 
DadsFam, to an AI company or to any other service — the free plugin makes no outside
requests at all.

It stores, per person, the browsers they have signed in with (as a random token 
matched by a scrambled fingerprint) and the networks they use (as one-way fingerprints
that cannot be turned back into addresses). A recognised browser gets one first-
party cookie, `dfls_tb`, which only your site can read. The activity log keeps the
address, username and browser name of each attempt for 30 days by default. Uninstalling
the plugin removes all of it.

#### Pro features (DadsFam Login Security Pro add-on)

Two-factor codes, a smart sign-in check that asks for an email code when a sign-
in looks unusual to the Brain, a CAPTCHA, a hidden login address, breached-password
checks, country blocking, sessions control and a full audit trail.

#### A word about PRO

Right, let me be straight with you, because I hate being sold to as much as you 
do.

Everything above is free and it stays free. The lockouts, the allow and deny lists,
the activity log, the live dashboard, the email alerts, the bot traps and the hardening—
none of those are premium features. Those are the things a login-security plugin
should just do, and if I put them behind a paywall I would be taking the mickey.

There is a PRO add-on. It exists because I am a dad in Cape Town, and this is one
of the things that puts food on the table at my house. That is the honest reason.
Not “unlock your potential”, not “supercharge your workflow”. Just: if this plugin
kept the bots off your login page and you can spare it, PRO helps me keep building.

What PRO adds is the second layer you reach for once the door is already locked —
two-factor codes, a CAPTCHA, a hidden login address, breached-password checks, country
blocking. That is extra security and convenience. It is not the plugin working properly,
because the plugin already works properly.

So if the free one does everything you need, brilliant. Genuinely. Use it, and I
hope your activity log stays boring. If you get to the point where a second factor
or a hidden login would let you sleep better, PRO is at plugins.dadsfam.co.za.

Either way, thanks for using something I built. — Zak, DadsFam

## Screenshots

[⌊The dashboard: whether your sign-in page is safe, in one sentence, with the Brain
on duty.⌉⌊The dashboard: whether your sign-in page is safe, in one sentence, with
the Brain on duty.⌉[

The dashboard: whether your sign-in page is safe, in one sentence, with the Brain
on duty.

[⌊The Brain: what it decided and why, the clues it weighs, the Autopilot and self-
repair.⌉⌊The Brain: what it decided and why, the clues it weighs, the Autopilot 
and self-repair.⌉[

The Brain: what it decided and why, the clues it weighs, the Autopilot and self-
repair.

[⌊The activity log with the Brain's verdict on every attempt.⌉⌊The activity log 
with the Brain's verdict on every attempt.⌉[

The activity log with the Brain’s verdict on every attempt.

[⌊Settings, with the Brain's switches and plain-English explanations.⌉⌊Settings,
with the Brain's switches and plain-English explanations.⌉[

Settings, with the Brain’s switches and plain-English explanations.

[⌊Ask the Brain: plain-English questions, answered from your own site with numbers,
a chart and the fix as one button.⌉⌊Ask the Brain: plain-English questions, answered
from your own site with numbers, a chart and the fix as one button.⌉[

Ask the Brain: plain-English questions, answered from your own site with numbers,
a chart and the fix as one button.

[⌊The Brain on the WordPress dashboard: ask a question without leaving it.⌉⌊The 
Brain on the WordPress dashboard: ask a question without leaving it.⌉[

The Brain on the WordPress dashboard: ask a question without leaving it.

## Installation

 1. Upload the plugin through **Plugins  Add New  Upload Plugin**, or search for “DadsFam
    Login Security”.
 2. Activate it. Protection starts straight away with safe defaults, and the Brain 
    starts learning from your next sign-in (it also reads your existing activity log
    if you are updating).
 3. Open **Login Security** in the admin menu and click **Never lock me out**.

## FAQ

### How does the Brain understand what I mean?

It listens for ideas, not just exact words. It has a small thesaurus (“burglars”,“
culprits” and “baddies” all mean attackers), example questions for every topic, 
and a table of word meanings worked out from GloVe word vectors (Stanford NLP, public
domain). All three are plain text files in the plugin’s data folder, and it all 
runs on your site – nothing is sent anywhere. Understanding by meaning only ever
picks what to show you; anything that changes something still needs exact words 
and your click.

### Does the Brain send my data to an AI company?

No. It is not a connection to ChatGPT, Claude or anything else. It is a small learning
engine written into the plugin, and it runs on your own server. Ask the Brain works
the same way: it understands your question with its own language engine and answers
from your site’s data. Nothing leaves your site.

### Will this lock me out of my own site?

It is built not to. Add yourself to the allow list with the **Never lock me out**
button, and once you have signed in once your browser is recognised and cannot be
locked out by its address. If you are ever stuck, use the “Email me an unlock link”
link on the lockout message, or add `define( 'DFLS_DISABLE_LOCKOUTS', true );` to
wp-config.php, sign in, and remove the line again.

### Can the Brain lock out a real person by mistake?

It is designed so it cannot. It only acts alone when it is almost certain and at
least two hard clues agree — things a real browser in a person’s hands does not 
do, like having no browser name at all. Recognised browsers and the networks your
people use are excluded from that entirely.

### Does it work behind Cloudflare or a load balancer?

Yes. Choose **Cloudflare** or **Another proxy or load balancer** under Settings  
Where visitors’ addresses come from, and it reads the real visitor address — only
when the request really came through your proxy, so the header cannot be faked. 
Self-repair switches Cloudflare on for you when it detects Cloudflare.

### Is it compatible with WooCommerce login forms?

Yes. The shop’s account page is protected the same way as wp-login.php.

### Will disabling XML-RPC break anything?

Only apps that still use XML-RPC, such as the old WordPress mobile app or some remote
publishing tools. It is off by default.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“DadsFam Login Security” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ dadsfam ](https://profiles.wordpress.org/dadsfam/)

[Translate “DadsFam Login Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/dadsfam-login-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/dadsfam-login-security/),
check out the [SVN repository](https://plugins.svn.wordpress.org/dadsfam-login-security/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/dadsfam-login-security/)
by [RSS](https://plugins.trac.wordpress.org/log/dadsfam-login-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.6.1

 * Fixed: when something happened exactly once, the Brain and the screens said “
   1 addresses in 1 networks”, “signed in 1 times from 1 recognised browsers”, “
   1 real sign-ins” and “1 lockouts”. Every count now uses the singular for one –
   including the Dashboard tiles as their numbers update live, and the lockout page
   when the time-out is set to one minute.

#### 2.6.0

The Brain understands what you mean, not just the words it was taught.
 * New: questions
are understood by their meaning – “who are the burglars?”, “anyone in the penalty
box?”, “give me the rundown” – using a thesaurus of the ideas it listens for, example
questions for every topic, and a table of word meanings. * New: when it is not sure,
it asks “Is it one of these?” and shows the likely questions as buttons. * Safe 
by design: understanding by meaning only ever chooses what to show you. Blocking,
unlocking or changing a setting still needs the exact words and your click, and 
questions about something else entirely (the weather, a joke) still get “I did not
quite catch that”. * Private: it all runs on your site. The three small word files
ship inside the plugin as plain text, and nothing is sent anywhere. * Fixed: “who
is …?” and “what did …?” questions with no address or name were answered with the
lockout list. * Fixed: “who is on the …?” and “who is in …?” questions were taken
to mean “who is online”.

#### 2.5.0

The Brain, attacked on purpose: every change below came from throwing everyday, 
odd and hostile questions at it until it answered them all.
 * New: the Brain understands
far more everyday questions — “has anyone tried breaking in?”, “show me the baddies”,“
something feels wrong”. * New: “I think someone got into my account” gets a real
answer — everyone who actually signed in over the last 14 days, and a button that
signs you out of your other devices. * New: ask “do you send my data to OpenAI?”,“
what are you?”, “what version is this?” or “what is new?” and it answers plainly.*
New: type “undo” to take back your last settings change; “forget Sarah’s browsers”
works after a lost phone. * Fixed: the typo-fixer rewrote real words — “strong” 
was read as “strict”, “offline” as “online”, “ever” as “never”. Checked against 
the 10,000 most common English words, it now leaves real words alone. * Fixed: questions
about two-factor, CAPTCHA, country blocking and password strength get the right 
answer about what Pro adds; “change my password” shows where WordPress does that.*
Hardened: questions are trimmed to 500 characters, so a huge paste can never slow
the Brain down. * Hardened: tested against “ignore previous instructions”, SQL and
script text — the Brain never obeys them, and a question never changes anything 
by itself; every change still needs your click.

#### 2.4.0

Security release — every fix below was proven with a real attack against a test 
site.
 * Security: strikes are counted inside the database in one step, so many 
guesses fired at the same moment can no longer slip past the limit. * Security: 
IPv6 lockouts cover the whole /64 block, so an attacker cannot hop to a fresh IPv6
address after each lockout. * Security: when strangers from several addresses guess
one real account’s password, every further stranger is locked out on the first wrong
try. Recognised browsers and your own people’s networks are never affected. * Security:“
Lost your password?” is rate-limited (5 requests per connection per 30 minutes, 
3 emails per account per hour) and never reveals whether an account exists — on 
the WordPress and WooCommerce forms. * Security: wrong application passwords over
the REST API count toward lockouts, locked-out addresses cannot use them, and the
error no longer reveals whether a username exists. * Security: the Activity CSV 
export can no longer carry spreadsheet formulas typed in as usernames.

#### 2.3.0

 * New: ask the Brain in Afrikaans and it answers in Afrikaans — the answers, the
   buttons, the numbers and the times. Switch language mid-conversation and it follows
   you.
 * New: an Undo button after blocking or trusting an address, changing the protection
   level or flipping a switch from the chat.
 * Improved: the Dashboard and Ask the Brain now fit a phone screen (no sideways
   scrolling, full-width answers).
 * Fix: the lost-phone answer for your own account said “Forget my’s browsers”.

#### 2.2.0

 * New: Ask the Brain is on your Login Security dashboard and on the WordPress dashboard
   too.
 * New: it holds a real conversation — forgives typos, understands Afrikaans, remembers
   what you were talking about (“unlock her”, “and last month?”).
 * New: answers with numbers, the trend and a small chart; the last attack, when
   attacks come, which usernames bots try, your own IP; plain-English explanations
   of every feature and how-tos with a button.
 * New: “who is signed in right now?” and “sign Sarah out of every device” for lost
   or stolen phones.
 * New: a heat-map of when attacks come, the Brain’s diary, and an optional weekly
   letter by email.

#### 2.1.0

 * New: Ask the Brain. Ask in plain English and it answers from your site’s own 
   data, with the fix as one button. It runs on your site; nothing is sent to an
   AI service.
 * New: it checks its own work and demands more certainty after doubting a real 
   person, easing back after a clean month.
 * New: it learns which usernames only bots use and locks them out on the first 
   try (never on your people’s networks).
 * New: it learns from DadsFam AntiSpam, shows which accounts are being guessed,
   and tells the week’s story in plain English.
 * Fix: bots stopped by a CAPTCHA were never shown, so an attacked site could look
   quiet. They are now counted, never as a strike.

#### 2.0.0

 * New: the Brain. The plugin learns, on your site only, who your real people are
   and how bots behave, and explains every attempt in plain words.
 * New: browsers that have signed in before are never locked out by their address,
   and their typos do not count.
 * New: obvious bots are locked out on the first try when the Brain is almost certain
   and two hard clues agree.
 * New: Autopilot raises the shields during attacks and blocks attacking networks
   for a while, never your people’s networks.
 * New: unlock by email, self-repair, smarter new-sign-in alerts, WordPress Abilities,
   and Support and What’s new tabs.
 * Fix: opening the sign-in page was counted as a wrong password (with “Don’t say
   which part was wrong” on, the default), which could lock real people out. Fixed,
   the false records are removed on update, and anyone who had signed in successfully
   before is let back in.

#### 1.7.1

 * Removed the small “Powered by DadsFam” line from the bottom of the lockout and
   new-login emails. Those emails go to your users, and nothing of ours belongs 
   in them unless you have asked for it.
 * Corrected the plugin’s homepage link in its header, which pointed at a page that
   no longer exists.

#### 1.7.0

 * New: find any setting. A search box above the Settings cards filters every switch
   and field by a word in its label or description, opens the “actual numbers” section
   when a match is inside it, and says plainly when nothing matches.
 * New: the save bar tells you. It lights up the moment something on the page changes
   and the browser warns before you leave with unsaved changes.
 * Readme: added the standing “A word about PRO” note — what stays free, why the
   optional add-on exists, and what it actually adds — and the line that nothing
   in the free plugin is disabled, blurred out, time-limited or reduced. Tested 
   up to WordPress 7.1.

#### 1.6.1

 * Fixed: cleared every WordPress.org Plugin Check violation — six request values
   read without sanitising, a discouraged text-domain call, and a set of table-name
   and nonce false positives now carry the justification the checker needs. Zero
   violations.
 * Fixed: a CAPTCHA refusal raised by another plugin was counted as a failed password.
   A visitor turned away by a bot check a few times was then locked out here as 
   well — two plugins compounding one problem. Any error whose code mentions a CAPTCHA
   is now ignored when counting failed attempts, whichever plugin raised it. Wrong
   passwords still count exactly as before.

Older versions are listed in changelog.txt.

## Meta

 *  Version **2.6.1**
 *  Last updated **19 hours ago**
 *  Active installations **20+**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/dadsfam-login-security/)
 * Tags
 * [Brute Force](https://pcd.wordpress.org/plugins/tags/brute-force/)[limit login attempts](https://pcd.wordpress.org/plugins/tags/limit-login-attempts/)
   [lockout](https://pcd.wordpress.org/plugins/tags/lockout/)[login](https://pcd.wordpress.org/plugins/tags/login/)
   [security](https://pcd.wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://pcd.wordpress.org/plugins/dadsfam-login-security/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/dadsfam-login-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/dadsfam-login-security/reviews/)

## Contributors

 *   [ dadsfam ](https://profiles.wordpress.org/dadsfam/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/dadsfam-login-security/)