{"id":367859,"date":"2026-09-16T03:07:49","date_gmt":"2026-09-16T03:07:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/dadsfam-login-security\/"},"modified":"2026-10-03T14:46:43","modified_gmt":"2026-10-03T14:46:43","slug":"dadsfam-login-security","status":"publish","type":"plugin","link":"https:\/\/pcd.wordpress.org\/plugins\/dadsfam-login-security\/","author":23486748,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.0.1","stable_tag":"3.0.1","tested":"7.1.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"DadsFam Login Security","header_author":"DadsFam","header_description":"Hardens your WordPress login against brute-force attacks, bots and username scanning. Smart lockouts, IP allow\/deny lists, a full login activity log, email alerts and built-in hardening \u2014 all free, no forced upsells.","assets_banners_color":"bbcbdf","last_updated":"2026-10-03 14:46:43","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/plugins.dadsfam.co.za\/dadsfam-login-security-free-and-pro\/","header_author_uri":"https:\/\/plugins.dadsfam.co.za\/","rating":0,"author_block_rating":0,"active_installs":20,"downloads":322,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.7.1":{"tag":"1.7.1","author":"dadsfam","date":"2026-09-16 03:07:16","revision":3697870},"2.0.0":{"tag":"2.0.0","author":"dadsfam","date":"2026-09-28 14:57:22","revision":3717419},"2.2.0":{"tag":"2.2.0","author":"dadsfam","date":"2026-09-29 16:23:57","revision":3719432},"2.6.1":{"tag":"2.6.1","author":"dadsfam","date":"2026-10-02 12:54:41","revision":3724817},"2.6.2":{"tag":"2.6.2","author":"dadsfam","date":"2026-10-03 11:53:00","revision":3726216},"2.8.0":{"tag":"2.8.0","author":"dadsfam","date":"2026-10-03 13:21:25","revision":3726306},"2.9.0":{"tag":"2.9.0","author":"dadsfam","date":"2026-10-03 13:37:46","revision":3726315},"3.0.1":{"tag":"3.0.1","author":"dadsfam","date":"2026-10-03 14:46:43","revision":3726380}},"upgrade_notice":{"3.0.1":"<p>The Brain no longer mistakes an attacker for the account owner, and blocks slow unscored guessing by itself.<\/p>","3.0.0":"<p>The self-learning Brain: it learns how you ask things, and blocks slow password guessing by itself (with Undo).<\/p>","2.9.0":"<p>The Brain now tells you what it noticed by itself, and can show how it knows.<\/p>","2.8.0":"<p>The Brain now tells you how it went after you helped someone, and a &quot;Needs a hand&quot; card shows who is stuck signing in.<\/p>","2.7.0":"<p>Ask the Brain &quot;Why can&#039;t Rene sign in?&quot; - one person&#039;s sign-in trouble explained in a sentence, with the fix.<\/p>","2.6.2":"<p>Closes a gap that let bots find the admin username through \/?author=1 and author pages on sites with normal web addresses.<\/p>","2.6.1":"<p>Wording fix: &quot;1 address&quot;, not &quot;1 addresses&quot; - everywhere the Brain and the screens count things.<\/p>","2.6.0":"<p>The Brain now understands questions by their meaning, and asks &quot;Is it one of these?&quot; when it is not sure. Still private: it all runs on your site.<\/p>","2.5.0":"<p>The Brain understands far more everyday questions, including &quot;did someone get into my account?&quot;, and its typo-fixer no longer misreads real words.<\/p>","2.4.0":"<p>Security release: closes six ways attackers could get extra guesses, flood reset emails or find out which accounts exist. Update straight away.<\/p>","2.3.0":"<p>The Brain answers in Afrikaans when you ask in Afrikaans, every chat action can be undone, and everything fits a phone screen.<\/p>","2.2.0":"<p>Ask the Brain everywhere: on your dashboards, typo-proof, English and Afrikaans, with memory, numbers and charts. Plus a heat-map, a diary and an optional weekly letter.<\/p>","2.1.0":"<p>Ask the Brain in plain English, a Brain that checks its own work and learns bot usernames by itself, and bots stopped by a CAPTCHA now shown. Everything stays on your site.<\/p>","2.0.0":"<p>Important fix: simply opening the sign-in page no longer counts as a wrong password. Adds the self-learning Brain, Autopilot, unlock by email and self-repair. Everything stays on your site.<\/p>","1.7.1":"<p>Review fixes: no DadsFam branding in the emails your users receive, and the plugin homepage link is fixed.<\/p>","1.7.0":"<p>Find any setting with the new search box, and a save bar that shows when something has changed.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3697870,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3697870,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3697870,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3697870,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.7.1","2.0.0","2.2.0","2.6.1","2.6.2","2.8.0","2.9.0","3.0.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3726216,"resolution":"1","location":"assets","locale":"","width":1280,"height":1600},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3726216,"resolution":"2","location":"assets","locale":"","width":1280,"height":1600},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3726216,"resolution":"3","location":"assets","locale":"","width":1280,"height":1200},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3726216,"resolution":"4","location":"assets","locale":"","width":1280,"height":800},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3726216,"resolution":"5","location":"assets","locale":"","width":1072,"height":1253},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3726216,"resolution":"6","location":"assets","locale":"","width":834,"height":861},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3726216,"resolution":"7","location":"assets","locale":"","width":1072,"height":1253}},"screenshots":{"1":"The dashboard: whether your sign-in page is safe, in one sentence, with the Brain on duty.","2":"The Brain: what it decided and why, the clues it weighs, the Autopilot and self-repair.","3":"The activity log with the Brain's verdict on every attempt.","4":"Settings, with the Brain's switches and plain-English explanations.","5":"Ask the Brain: plain-English questions, answered from your own site with numbers, a chart and the fix as one button.","6":"The Brain on the WordPress dashboard: ask a question without leaving it.","7":"Ask the Brain in Afrikaans \u2014 how many attacks this month, why an account is locked out, unlock it \u2014 and it answers in Afrikaans, with the numbers and the fix."}},"plugin_section":[262246],"plugin_tags":[2439,9374,13868,602,600],"plugin_category":[38,54],"plugin_contributors":[274194],"plugin_business_model":[],"class_list":["post-367859","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-brute-force","plugin_tags-limit-login-attempts","plugin_tags-lockout","plugin_tags-login","plugin_tags-security","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-dadsfam","plugin_committers-dadsfam"],"banners":{"banner":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/banner-772x250.png?rev=3697870","banner_2x":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/banner-1544x500.png?rev=3697870","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/icon-128x128.png?rev=3697870","icon_2x":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/icon-256x256.png?rev=3697870","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-1.png?rev=3726216","caption":"The dashboard: whether your sign-in page is safe, in one sentence, with the Brain on duty."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-2.png?rev=3726216","caption":"The Brain: what it decided and why, the clues it weighs, the Autopilot and self-repair."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-3.png?rev=3726216","caption":"The activity log with the Brain's verdict on every attempt."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-4.png?rev=3726216","caption":"Settings, with the Brain's switches and plain-English explanations."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-5.png?rev=3726216","caption":"Ask the Brain: plain-English questions, answered from your own site with numbers, a chart and the fix as one button."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-6.png?rev=3726216","caption":"The Brain on the WordPress dashboard: ask a question without leaving it."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-7.png?rev=3726216","caption":"Ask the Brain in Afrikaans \u2014 how many attacks this month, why an account is locked out, unlock it \u2014 and it answers in Afrikaans, with the numbers and the fix."}],"raw_content":"<!--section=description-->\n<p><strong>DadsFam Login Security<\/strong> protects the most-attacked part of your WordPress site \u2014 the login form \u2014 without making you read a manual or fiddle with servers.<\/p>\n\n<p>Most login plugins count wrong passwords and lock out whoever hits the number. That works on bots, and it also locks out your customer who mistyped twice on the same office connection a bot happens to be using. Version 2.0 gives the plugin its own Brain, running entirely on your site, so it can tell the two apart.<\/p>\n\n<h4>The Brain (free, and it never phones home)<\/h4>\n\n<ul>\n<li><strong>Ask the Brain.<\/strong> Type a question the way you would ask a person \u2014 \"is my site safe?\", \"why can't Sarah sign in?\", then \"unlock her\"; \"how many attacks this month?\", then \"and last month?\" \u2014 and it answers from your own site's data with the numbers, a small chart and the fix as one button. It forgives typos, answers in Afrikaans when you ask in Afrikaans, explains every feature, and lives on your dashboard and the WordPress dashboard. Its own language engine runs on your site; nothing is sent to an AI service.<\/li>\n<li><strong>Lost phone? One sentence.<\/strong> \"Who is signed in right now?\" or \"sign Sarah out of every device\".<\/li>\n<li><strong>A heat-map of when attacks come<\/strong>, and a diary of everything the Brain did by itself.<\/li>\n<li><strong>The Brain's weekly letter<\/strong> (optional): its plain-English story of the week, emailed every Monday.<\/li>\n<li><strong>It learns your real people.<\/strong> Every correct password teaches it what a real sign-in on your site looks like. Every attempt on a username that does not exist teaches it what a bot looks like. It only learns from facts, never from its own guesses.<\/li>\n<li><strong>It checks its own work.<\/strong> When a real person it had doubted signs in, it notes the mistake; twice in a month and it demands more certainty before it acts.<\/li>\n<li><strong>It learns which usernames only bots use.<\/strong> Once several different addresses try a name nobody on your site has, one try is enough to lock them out \u2014 never on a network your people use.<\/li>\n<li><strong>It learns from DadsFam AntiSpam.<\/strong> An address caught spamming your forms is treated with suspicion if it then tries to sign in.<\/li>\n<li><strong>It shows which real accounts are being guessed<\/strong>, and tells the week's story in plain English.<\/li>\n<li><strong>A browser that has signed in before is never locked out by its address.<\/strong> Its typos do not count, even on a shared connection that is being attacked. (After a generous number of misses the normal rules apply again, in case a laptop is stolen.)<\/li>\n<li><strong>Obvious bots are locked out on the first try<\/strong> \u2014 but only when it is almost certain and two hard clues agree, like a script with no browser posting straight at the form. A real browser cannot trip it.<\/li>\n<li><strong>Every attempt is explained in plain words:<\/strong> \"97% bot: posted straight at the sign-in form without opening it, no language setting.\"<\/li>\n<li><strong>Autopilot.<\/strong> During an attack it raises the shields (strangers get half the tries and a longer time-out), keeps whole attacking networks away for a day, then three, then a week \u2014 and lowers everything again once it is quiet. Networks your people use are never touched.<\/li>\n<li><strong>Unlock by email.<\/strong> A locked-out person can email themselves a one-time unlock link. It only ever goes to the account's own email address.<\/li>\n<li><strong>Self-repair.<\/strong> Every day and after every update it checks its own setup and fixes what is safe to fix \u2014 like the Cloudflare setting that lets one bot lock everybody out \u2014 then tells you what it did.<\/li>\n<li><strong>Remote control.<\/strong> On WordPress 6.9+ every action is available as a WordPress Ability, so an assistant you trust can check your login security or let someone back in.<\/li>\n<\/ul>\n\n<h4>Everything else you get (free)<\/h4>\n\n<ul>\n<li><strong>Smart lockouts<\/strong> \u2014 after too many wrong passwords an address is paused, and repeat offenders get a much longer time-out. Choose Relaxed, Balanced or Strict with one click.<\/li>\n<li><strong>Instant lockout for bot usernames<\/strong> \u2014 \"admin\", \"root\" and friends lock a bot out on the first try, unless someone on your site really uses that name.<\/li>\n<li><strong>Never lock me out<\/strong> \u2014 one click adds your own address to the allow list.<\/li>\n<li><strong>Allow and deny lists<\/strong> \u2014 single addresses, ranges and wildcards.<\/li>\n<li><strong>Activity log<\/strong> \u2014 every sign-in, wrong password, lockout and block, with the Brain's verdict, search, filters and CSV export.<\/li>\n<li><strong>Invisible bot trap and generic error messages<\/strong> \u2014 bots cannot tell whether a username exists.<\/li>\n<li><strong>Hardening<\/strong> \u2014 block username discovery, switch off XML-RPC and pingbacks.<\/li>\n<li><strong>Email alerts<\/strong> \u2014 when someone is locked out, and (optionally) when a person signs in from a browser and network they have never used.<\/li>\n<li><strong>Cloudflare and proxy support<\/strong> \u2014 reads the real visitor address, safely.<\/li>\n<li><strong>A recovery switch<\/strong> \u2014 add DFLS_DISABLE_LOCKOUTS to wp-config.php and nobody is locked out until you remove it.<\/li>\n<\/ul>\n\n<h4>Privacy<\/h4>\n\n<p>Everything the Brain knows stays in your WordPress database. Nothing is sent to DadsFam, to an AI company or to any other service \u2014 the free plugin makes no outside requests at all.<\/p>\n\n<p>It stores, per person, the browsers they have signed in with (as a random token matched by a scrambled fingerprint) and the networks they use (as one-way fingerprints that cannot be turned back into addresses). A recognised browser gets one first-party cookie, <code>dfls_tb<\/code>, which only your site can read. The activity log keeps the address, username and browser name of each attempt for 30 days by default. Uninstalling the plugin removes all of it.<\/p>\n\n<h4>Pro features (DadsFam Login Security Pro add-on)<\/h4>\n\n<p>Two-factor codes, a smart sign-in check that asks for an email code when a sign-in looks unusual to the Brain, a CAPTCHA, a hidden login address, breached-password checks, country blocking, sessions control and a full audit trail.<\/p>\n\n<h4>A word about PRO<\/h4>\n\n<p>Right, let me be straight with you, because I hate being sold to as much as you do.<\/p>\n\n<p>Everything above is free and it stays free. The lockouts, the allow and deny lists, the activity log, the live dashboard, the email alerts, the bot traps and the hardening \u2014 none of those are premium features. Those are the things a login-security plugin should just do, and if I put them behind a paywall I would be taking the mickey.<\/p>\n\n<p>There is a PRO add-on. It exists because I am a dad in Cape Town, and this is one of the things that puts food on the table at my house. That is the honest reason. Not \"unlock your potential\", not \"supercharge your workflow\". Just: if this plugin kept the bots off your login page and you can spare it, PRO helps me keep building.<\/p>\n\n<p>What PRO adds is the second layer you reach for once the door is already locked \u2014 two-factor codes, a CAPTCHA, a hidden login address, breached-password checks, country blocking. That is extra security and convenience. It is not the plugin working properly, because the plugin already works properly.<\/p>\n\n<p>So if the free one does everything you need, brilliant. Genuinely. Use it, and I hope your activity log stays boring. If you get to the point where a second factor or a hidden login would let you sleep better, PRO is at plugins.dadsfam.co.za.<\/p>\n\n<p>Either way, thanks for using something I built. \u2014 Zak, DadsFam<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin through <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>, or search for \"DadsFam Login Security\".<\/li>\n<li>Activate it. Protection starts straight away with safe defaults, and the Brain starts learning from your next sign-in (it also reads your existing activity log if you are updating).<\/li>\n<li>Open <strong>Login Security<\/strong> in the admin menu and click <strong>Never lock me out<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20does%20the%20brain%20understand%20what%20i%20mean%3F\"><h3>How does the Brain understand what I mean?<\/h3><\/dt>\n<dd><p>It listens for ideas, not just exact words. It has a small thesaurus (\"burglars\", \"culprits\" and \"baddies\" all mean attackers), example questions for every topic, and a table of word meanings worked out from GloVe word vectors (Stanford NLP, public domain). All three are plain text files in the plugin's data folder, and it all runs on your site - nothing is sent anywhere. Understanding by meaning only ever picks what to show you; anything that changes something still needs exact words and your click.<\/p><\/dd>\n<dt id=\"does%20the%20brain%20send%20my%20data%20to%20an%20ai%20company%3F\"><h3>Does the Brain send my data to an AI company?<\/h3><\/dt>\n<dd><p>No. It is not a connection to ChatGPT, Claude or anything else. It is a small learning engine written into the plugin, and it runs on your own server. Ask the Brain works the same way: it understands your question with its own language engine and answers from your site's data. Nothing leaves your site.<\/p><\/dd>\n<dt id=\"will%20this%20lock%20me%20out%20of%20my%20own%20site%3F\"><h3>Will this lock me out of my own site?<\/h3><\/dt>\n<dd><p>It is built not to. Add yourself to the allow list with the <strong>Never lock me out<\/strong> button, and once you have signed in once your browser is recognised and cannot be locked out by its address. If you are ever stuck, use the \"Email me an unlock link\" link on the lockout message, or add <code>define( 'DFLS_DISABLE_LOCKOUTS', true );<\/code> to wp-config.php, sign in, and remove the line again.<\/p><\/dd>\n<dt id=\"can%20the%20brain%20lock%20out%20a%20real%20person%20by%20mistake%3F\"><h3>Can the Brain lock out a real person by mistake?<\/h3><\/dt>\n<dd><p>It is designed so it cannot. It only acts alone when it is almost certain and at least two hard clues agree \u2014 things a real browser in a person's hands does not do, like having no browser name at all. Recognised browsers and the networks your people use are excluded from that entirely.<\/p><\/dd>\n<dt id=\"does%20it%20work%20behind%20cloudflare%20or%20a%20load%20balancer%3F\"><h3>Does it work behind Cloudflare or a load balancer?<\/h3><\/dt>\n<dd><p>Yes. Choose <strong>Cloudflare<\/strong> or <strong>Another proxy or load balancer<\/strong> under Settings \u2192 Where visitors' addresses come from, and it reads the real visitor address \u2014 only when the request really came through your proxy, so the header cannot be faked. Self-repair switches Cloudflare on for you when it detects Cloudflare.<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20woocommerce%20login%20forms%3F\"><h3>Is it compatible with WooCommerce login forms?<\/h3><\/dt>\n<dd><p>Yes. The shop's account page is protected the same way as wp-login.php.<\/p><\/dd>\n<dt id=\"will%20disabling%20xml-rpc%20break%20anything%3F\"><h3>Will disabling XML-RPC break anything?<\/h3><\/dt>\n<dd><p>Only apps that still use XML-RPC, such as the old WordPress mobile app or some remote publishing tools. It is off by default.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>3.0.1<\/h4>\n\n<p>Found on a live site: the Brain must never mistake an attacker for the account's owner.\n* Fixed: wrong passwords from many rotating addresses (a VPN working through one account) were counted as the owner's own when the Brain had not seen the owner sign in lately, so it said their password was \"not working\" and offered a reset link. It now needs evidence - an address or browser the person really used - and says plainly that strangers are guessing, with a button to block their network.\n* Fixed: \"device trusted\" and \"passkey added\" now count as proof of the person's own address.\n* Fixed: slow guessing that the Brain could not score is now blocked by itself too, but only when it is spread over six hours or more; tries that look like a person never count.\n* Fixed: no more \"their own An unknown browser\".<\/p>\n\n<h4>3.0.0<\/h4>\n\n<p>The self-learning Brain.\n* New: the Brain learns your words. When it does not understand you, it says what it thinks you mean; when you rephrase it or pick one of its guesses, it remembers and understands that wording next time (\"Got it\"). Ask \"What have you learned?\" to see it all, and forget it with one tap.\n* New: it defends by itself against slow guessing - a network working through a real account's password a few tries a day, too slowly for the usual rules - and tells you what it did, with an Undo button.\n* New: ask \"How accurate are you?\" or \"Can I trust you?\" for its own track record.<\/p>\n\n<h4>2.9.0<\/h4>\n\n<p>The Brain notices things.\n* New: the Brain opens with what it noticed by itself - a real account whose password is being worked through slowly (with a one-tap block when the tries come from one network), people who joined this week and cannot get in, help you gave that has not worked yet.\n* New: ask \"What have you noticed?\" or \"Anything I should know?\" any time.\n* New: after an answer about a person, ask \"How do you know?\" and the Brain shows its evidence - their sign-ins, which wrong passwords came from them and which from strangers, lock-outs, the two-factor side and your help - and the conclusion it reached.<\/p>\n\n<h4>2.8.0<\/h4>\n\n<p>The Brain closes the loop.\n* New: when you help someone from the Brain - a link to choose a new password, letting them back in, clearing a waiting sign-in - it remembers, and tells you how it went: \"Sorted: you sent them a link 2 hours ago, and Rene signed in 10 minutes later\", or that they have not tried since.\n* New: a \"Needs a hand\" card on the Dashboard shows anyone stuck signing in right now, with the reason, before they have to phone you - and who got sorted since you helped.\n* New: \"Ask the Brain\" buttons open the Brain with the question already answered.<\/p>\n\n<h4>2.7.0<\/h4>\n\n<p>The Brain helps one person sign in.\n* New: ask \"Why can't Rene sign in?\" and the Brain looks at that one person and says, in one plain sentence, what is really going on - locked out, password not working, someone else guessing, account never used, or simply fine - and offers the fix. With Pro it also sees the two-factor side.\n* New: it finds people the way you ask - first name, surname, username or part of their email. When two people fit, it asks which one.\n* New: a button that emails someone a link to choose a new password, straight from the answer.\n* New: ask \"Who is having trouble signing in?\" for everyone stuck right now, with the reason for each. Bots guessing passwords are left out.\n* New: the Sign in button can't be pressed twice - after the first tap it says \"Signing you in\u2026\".<\/p>\n\n<h4>2.6.2<\/h4>\n\n<p>Usernames stay hidden.\n* Fixed: on sites with normal web addresses, WordPress's own redirect ran before \"Hide the list of usernames\", so \/?author=1 led straight to the admin's author page and showed their username. The protection now runs first.\n* Author pages (their address is the username) now send visitors - and signed-in customers or members who can't write posts - to the home page. Made-up author addresses do the same, so nothing confirms that a username exists. Authors, editors and admins still see author pages.\n* The user sitemap, which listed every author page, is left out, and comments by registered users no longer carry the username as a hidden label.\n* All of it is part of \"Hide the list of usernames\" and switches off with it.<\/p>\n\n<h4>2.6.1<\/h4>\n\n<ul>\n<li>Fixed: when something happened exactly once, the Brain and the screens said \"1 addresses in 1 networks\", \"signed in 1 times from 1 recognised browsers\", \"1 real sign-ins\" and \"1 lockouts\". Every count now uses the singular for one - including the Dashboard tiles as their numbers update live, and the lockout page when the time-out is set to one minute.<\/li>\n<\/ul>\n\n<h4>2.6.0<\/h4>\n\n<p>The Brain understands what you mean, not just the words it was taught.\n* New: questions are understood by their meaning - \"who are the burglars?\", \"anyone in the penalty box?\", \"give me the rundown\" - using a thesaurus of the ideas it listens for, example questions for every topic, and a table of word meanings.\n* New: when it is not sure, it asks \"Is it one of these?\" and shows the likely questions as buttons.\n* Safe by design: understanding by meaning only ever chooses what to show you. Blocking, unlocking or changing a setting still needs the exact words and your click, and questions about something else entirely (the weather, a joke) still get \"I did not quite catch that\".\n* Private: it all runs on your site. The three small word files ship inside the plugin as plain text, and nothing is sent anywhere.\n* Fixed: \"who is ...?\" and \"what did ...?\" questions with no address or name were answered with the lockout list.\n* Fixed: \"who is on the ...?\" and \"who is in ...?\" questions were taken to mean \"who is online\".<\/p>\n\n<h4>2.5.0<\/h4>\n\n<p>The Brain, attacked on purpose: every change below came from throwing everyday, odd and hostile questions at it until it answered them all.\n* New: the Brain understands far more everyday questions \u2014 \"has anyone tried breaking in?\", \"show me the baddies\", \"something feels wrong\".\n* New: \"I think someone got into my account\" gets a real answer \u2014 everyone who actually signed in over the last 14 days, and a button that signs you out of your other devices.\n* New: ask \"do you send my data to OpenAI?\", \"what are you?\", \"what version is this?\" or \"what is new?\" and it answers plainly.\n* New: type \"undo\" to take back your last settings change; \"forget Sarah's browsers\" works after a lost phone.\n* Fixed: the typo-fixer rewrote real words \u2014 \"strong\" was read as \"strict\", \"offline\" as \"online\", \"ever\" as \"never\". Checked against the 10,000 most common English words, it now leaves real words alone.\n* Fixed: questions about two-factor, CAPTCHA, country blocking and password strength get the right answer about what Pro adds; \"change my password\" shows where WordPress does that.\n* Hardened: questions are trimmed to 500 characters, so a huge paste can never slow the Brain down.\n* Hardened: tested against \"ignore previous instructions\", SQL and script text \u2014 the Brain never obeys them, and a question never changes anything by itself; every change still needs your click.<\/p>\n\n<h4>2.4.0<\/h4>\n\n<p>Security release \u2014 every fix below was proven with a real attack against a test site.\n* Security: strikes are counted inside the database in one step, so many guesses fired at the same moment can no longer slip past the limit.\n* Security: IPv6 lockouts cover the whole \/64 block, so an attacker cannot hop to a fresh IPv6 address after each lockout.\n* Security: when strangers from several addresses guess one real account's password, every further stranger is locked out on the first wrong try. Recognised browsers and your own people's networks are never affected.\n* Security: \"Lost your password?\" is rate-limited (5 requests per connection per 30 minutes, 3 emails per account per hour) and never reveals whether an account exists \u2014 on the WordPress and WooCommerce forms.\n* Security: wrong application passwords over the REST API count toward lockouts, locked-out addresses cannot use them, and the error no longer reveals whether a username exists.\n* Security: the Activity CSV export can no longer carry spreadsheet formulas typed in as usernames.<\/p>\n\n<h4>2.3.0<\/h4>\n\n<ul>\n<li>New: ask the Brain in Afrikaans and it answers in Afrikaans \u2014 the answers, the buttons, the numbers and the times. Switch language mid-conversation and it follows you.<\/li>\n<li>New: an Undo button after blocking or trusting an address, changing the protection level or flipping a switch from the chat.<\/li>\n<li>Improved: the Dashboard and Ask the Brain now fit a phone screen (no sideways scrolling, full-width answers).<\/li>\n<li>Fix: the lost-phone answer for your own account said \"Forget my\u2019s browsers\".<\/li>\n<\/ul>\n\n<h4>2.2.0<\/h4>\n\n<ul>\n<li>New: Ask the Brain is on your Login Security dashboard and on the WordPress dashboard too.<\/li>\n<li>New: it holds a real conversation \u2014 forgives typos, understands Afrikaans, remembers what you were talking about (\"unlock her\", \"and last month?\").<\/li>\n<li>New: answers with numbers, the trend and a small chart; the last attack, when attacks come, which usernames bots try, your own IP; plain-English explanations of every feature and how-tos with a button.<\/li>\n<li>New: \"who is signed in right now?\" and \"sign Sarah out of every device\" for lost or stolen phones.<\/li>\n<li>New: a heat-map of when attacks come, the Brain's diary, and an optional weekly letter by email.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>New: Ask the Brain. Ask in plain English and it answers from your site's own data, with the fix as one button. It runs on your site; nothing is sent to an AI service.<\/li>\n<li>New: it checks its own work and demands more certainty after doubting a real person, easing back after a clean month.<\/li>\n<li>New: it learns which usernames only bots use and locks them out on the first try (never on your people's networks).<\/li>\n<li>New: it learns from DadsFam AntiSpam, shows which accounts are being guessed, and tells the week's story in plain English.<\/li>\n<li>Fix: bots stopped by a CAPTCHA were never shown, so an attacked site could look quiet. They are now counted, never as a strike.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>New: the Brain. The plugin learns, on your site only, who your real people are and how bots behave, and explains every attempt in plain words.<\/li>\n<li>New: browsers that have signed in before are never locked out by their address, and their typos do not count.<\/li>\n<li>New: obvious bots are locked out on the first try when the Brain is almost certain and two hard clues agree.<\/li>\n<li>New: Autopilot raises the shields during attacks and blocks attacking networks for a while, never your people's networks.<\/li>\n<li>New: unlock by email, self-repair, smarter new-sign-in alerts, WordPress Abilities, and Support and What's new tabs.<\/li>\n<li>Fix: opening the sign-in page was counted as a wrong password (with \"Don't say which part was wrong\" on, the default), which could lock real people out. Fixed, the false records are removed on update, and anyone who had signed in successfully before is let back in.<\/li>\n<\/ul>\n\n<h4>1.7.1<\/h4>\n\n<ul>\n<li>Removed the small \"Powered by DadsFam\" line from the bottom of the lockout and new-login emails. Those emails go to your users, and nothing of ours belongs in them unless you have asked for it.<\/li>\n<li>Corrected the plugin's homepage link in its header, which pointed at a page that no longer exists.<\/li>\n<\/ul>\n\n<h4>1.7.0<\/h4>\n\n<ul>\n<li>New: find any setting. A search box above the Settings cards filters every switch and field by a word in its label or description, opens the \"actual numbers\" section when a match is inside it, and says plainly when nothing matches.<\/li>\n<li>New: the save bar tells you. It lights up the moment something on the page changes and the browser warns before you leave with unsaved changes.<\/li>\n<li>Readme: added the standing \"A word about PRO\" note \u2014 what stays free, why the optional add-on exists, and what it actually adds \u2014 and the line that nothing in the free plugin is disabled, blurred out, time-limited or reduced. Tested up to WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.6.1<\/h4>\n\n<ul>\n<li>Fixed: cleared every WordPress.org Plugin Check violation \u2014 six request values read without sanitising, a discouraged text-domain call, and a set of table-name and nonce false positives now carry the justification the checker needs. Zero violations.<\/li>\n<li>Fixed: a CAPTCHA refusal raised by another plugin was counted as a failed password. A visitor turned away by a bot check a few times was then locked out here as well \u2014 two plugins compounding one problem. Any error whose code mentions a CAPTCHA is now ignored when counting failed attempts, whichever plugin raised it. Wrong passwords still count exactly as before.<\/li>\n<\/ul>\n\n<p>Older versions are listed in changelog.txt.<\/p>","raw_excerpt":"Stops brute-force attacks with its own self-learning Brain that knows your real people, locks bots out fast and fixes its own setup.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/367859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=367859"}],"author":[{"embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dadsfam"}],"wp:attachment":[{"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=367859"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=367859"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=367859"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=367859"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=367859"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=367859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}