WordPress Brute Force Protection – Stop Brute Force Attacks

WordPress Brute Force Protection – Stop Brute Force Attacks

Wordpress plugin

Install on Wordpress

App Details

The only plugin with 100% brute force protection that doesn’t lock out genuine users.

Brute Force Protection

This security plugin implements an approach used by large websites such as Facebook, Google etc.

When a genuine user makes a successful login to their account using their mobile phone, tablet, or computer GuardGiant starts treating their device as Trusted.

  • Failed login attempts from trusted devices are directed towards ‘Lost Password’ forms rather than being subject to account lockouts or additional counter measures.
  • Users receive an alert when anyone logs into their account from an unrecognized device or browser.

Stop Hackers

GuardGiant uses a range of strong counter-measures to limit login attempts from unrecognized devices. The default behaviour is:

  • After 3 failed login attempts from the same unrecognized device, a Google ReCaptcha field is added to the login page. ReCaptcha is a strong counter-measure that is very hard for an automated process to solve.
  • After 10 failed login attempts a temporary block of 2 minutes is applied to the device/IP address. No login attempts can be made during this time.
  • Each further failed login attempt increases the block time by another minute. This slows down attacks to the point where they quickly become unviable.

All behavior is fully customizable to achieve the level of brute force protection that you require.

Login History

A fully featured security log gives you visibility to login attempts on your site.

  • Provides geographic location, device type, IP address and more for each login attempt.
  • Filter login attempts by Trusted or Unrecognized devices.
  • Search by IP address or username.
  • Filter by successful or failed attempts.
  • Easy to display successful logins from unrecognized devices that could indicate a hacked account.

This login history log should form an essential part of your brute force login protection plan. GDPR compliant.

Other Login Security Improvements

This security plugin implements various improvements recommended by the Open Web Application Security Project® (OWASP) to keep your site safe:

  • Obfuscates login errors to stop hackers detecting valid account names.
  • Option to disable XMLRPC.
  • And much, much more.

This security plugin is exceptionally easy to use no matter what your level of technical expertise.

The default settings are highly optimized, designed to prevent brute force attacks whilst not disturbing genuine users from logging in. Advanced users can fully customize the behavior of this plugin to suit their own environment.

Login Security Plugin – Background Information

The most common threat that WordPress site owners face is a password guessing attack known as a brute force attack.
A brute force attack is where an attacker uses a brute force tool (or script) to discover your password by systematically trying every possible combination of letters, numbers, and symbols until the correct password is found. A brute force attack will always work eventually, but the problem for the brute force attacker is that it may take many years to do it.

Brute force prevention techniques focus on slowing down these attacks to the point where they become unviable.

Using long and complex passwords (that are not dictionary words) is a good brute force attack prevention method to start with. This greatly increases the time an attacker will need.

A common way to stop brute force attacks is to lock out the WordPress account after a defined number of failed authorization attempts (there are various brute force plugins that do this).
The problem with this approach is that the site administrator ends up with unhappy users who have been locked out, often needing manual intervention to regain access. This is not sustainable or desirable for sites of any size.

The modern approach to brute force prevention is to track the devices that genuine users use to log in, ensuring they are always treated kindly if they forget their password. Unrecognized devices face a progressive but temporary timed lockout.

Stop Brute Force Attacks

Periodic monitoring of your security audit log can help you stop brute force attacks.

Here are patterns that indicate a brute force attack or some other account abuse:

  • Failed login attempts using alphabetically sequential usernames or passwords
  • Multiple different usernames being used by the same IP address
  • Logins for a single account coming from many different IP addresses
  • Failed logins at a specific period e.g. every 5 minutes

Pricing

Starting from $0 per month.

Check Out the Restaurant Menu List Widget

By Common Ninja

Restaurant Menu ListTry For Free!

App Info

Rating

Reviewers

4 reviews

Tags

Brute Force
brute force protection
limit login
login protection
login security

Developed By

GuardGiant brute force protection

Quick & Easy

Find the Best Wordpress plugins for you

Common Ninja has a large selection of powerful Wordpress plugins that are easy to use, fully customizable, mobile-friendly and rich with features — so be sure to check them out!

Testimonial

Testimonial plugins for Wordpress

Galleries

Galleries plugins for Wordpress

SEO

SEO plugins for Wordpress

Contact Form

Contact Form plugins for Wordpress

Forms

Forms plugins for Wordpress

Social Feeds

Social Feeds plugins for Wordpress

Social Sharing

Social Sharing plugins for Wordpress

Events Calendar

Events Calendar plugins for Wordpress

Sliders

Sliders plugins for Wordpress

Analytics

Analytics plugins for Wordpress

Reviews

Reviews plugins for Wordpress

Comments

Comments plugins for Wordpress

Portfolio

Portfolio plugins for Wordpress

Maps

Maps plugins for Wordpress

Security

Security plugins for Wordpress

Translation

Translation plugins for Wordpress

Ads

Ads plugins for Wordpress

Video Player

Video Player plugins for Wordpress

Music Player

Music Player plugins for Wordpress

Backup

Backup plugins for Wordpress

Privacy

Privacy plugins for Wordpress

Optimize

Optimize plugins for Wordpress

Chat

Chat plugins for Wordpress

Countdown

Countdown plugins for Wordpress

Email Marketing

Email Marketing plugins for Wordpress

Tabs

Tabs plugins for Wordpress

Membership

Membership plugins for Wordpress

popup

popup plugins for Wordpress

SiteMap

SiteMap plugins for Wordpress

Payment

Payment plugins for Wordpress

Coming Soon

Coming Soon plugins for Wordpress

Ecommerce

Ecommerce plugins for Wordpress

Customer Support

Customer Support plugins for Wordpress

Inventory

Inventory plugins for Wordpress

Video Player

Video Player plugins for Wordpress

Testimonials

Testimonials plugins for Wordpress

Tabs

Tabs plugins for Wordpress

Social Sharing

Social Sharing plugins for Wordpress

Social Feeds

Social Feeds plugins for Wordpress

Slider

Slider plugins for Wordpress

Reviews

Reviews plugins for Wordpress

Portfolio

Portfolio plugins for Wordpress

Membership

Membership plugins for Wordpress

Forms

Forms plugins for Wordpress

Events Calendar

Events Calendar plugins for Wordpress

Contact

Contact plugins for Wordpress

Comments

Comments plugins for Wordpress

Analytics

Analytics plugins for Wordpress

More plugins

plugins You Might Like

Discover Apps By Platform

Discover the best apps for your website

WordPress
Wix
Shopify
Weebly
Webflow
Joomla
PrestaShop
Shift4Shop
WebsiteX5
MODX
Opencart
NopCommerce

Common Ninja Search Engine

The Common Ninja Search Engine platform helps website builders find the best site widgets, apps, plugins, tools, add-ons, and extensions! Compatible with all major website building platforms - big or small - and updated regularly, our Search Engine tool provides you with the business tools your site needs!

Multiple platforms