# Welcome to Limit Login Attempts Reloaded

Welcome to the LLAR software documentation. Whether you're a beginner or an experienced user, this documentation is designed to provide you with all the information you need to harness the full power of our plugin and take your login security to new heights.

Within this documentation, you'll find detailed guides, step-by-step tutorials, and in-depth explanations of the various features and capabilities offered by Limit Login Attempts Reloaded. We've worked hard to ensure that this documentation serves as a valuable resource, addressing common questions and providing solutions to help you make the most of our plugin.

We understand your time is valuable, and that's why we've organized this documentation in a user-friendly manner, making it easy for you to navigate and locate the information you need. Whether you're looking to integrate our plugin into your existing project, customize its functionality, or troubleshoot any issues you may encounter, you'll find the answers you're seeking right here.

We value your feedback and strive to continuously improve our plugin and its documentation. If you have any suggestions, questions, or concerns, please don't hesitate to reach out to our support team or join our vibrant community forum, where fellow users and our team members are always ready to lend a helping hand.

## Popular Links

{% content-ref url="/pages/DKGpxWd38RFqbpxgV11g" %}
[Installing The Plugin](/installation-and-setup/installing-the-plugin)
{% endcontent-ref %}

{% content-ref url="/pages/M9Xh1JyqKAQ81JhYMhXp" %}
[Activating The Plugin](/installation-and-setup/activating-the-plugin)
{% endcontent-ref %}

{% content-ref url="/pages/jxOvT88pgVp6pZgYats4" %}
[General Settings](/plugin-settings/general-settings)
{% endcontent-ref %}

{% content-ref url="/pages/vqSfVbFg9UC7F1CGgoE7" %}
[Safelist & Denylist](/plugin-settings/advanced-settings/safelist-and-denylist)
{% endcontent-ref %}

{% content-ref url="/pages/kXiE0J2v8anCaRgOCc8y" %}
[IP Logs](/plugin-settings/advanced-settings/ip-logs)
{% endcontent-ref %}

{% content-ref url="/pages/iJJR2ztwVV2ripRUg3Qa" %}
[Common Issues & Resolutions](/troubleshooting-and-support/common-issues-and-resolutions)
{% endcontent-ref %}

{% content-ref url="/pages/ql9Y8QcR6f1n3JjWkJbx" %}
[Frequently Asked Questions (FAQ)](/troubleshooting-and-support/frequently-asked-questions-faq)
{% endcontent-ref %}

{% content-ref url="/pages/Uh4u6keabYxBFljgDI3N" %}
[Contacting Support For Assistance](/troubleshooting-and-support/contacting-support-for-assistance)
{% endcontent-ref %}


# Overview

Limit Login Attempts Reloaded is a WordPress plugin designed to enhance the security of your WordPress website by limiting the number of login attempts a user can make. It helps prevent and neutralize brute-force attacks, where an attacker tries to gain unauthorized access to your website by repeatedly guessing usernames and passwords. With over 2.5 million active users, Limit Login Attempts Reloaded is the one of the top security plugins used in WordPress, and top 25 plugins overall.&#x20;

{% embed url="<https://www.youtube.com/watch?v=IsotthPWCPA>" %}


# Importance of Preventing Brute Force Attacks

Preventing brute force attacks is of utmost importance for several reasons

**1. Security:** Brute force attacks involve automated attempts to guess usernames and passwords, systematically trying various combinations until they find the correct credentials. By implementing countermeasures against such attacks, you significantly enhance the security of your website or system, protecting sensitive data and preventing unauthorized access.

**2. Data Protection:** Brute force attacks can lead to unauthorized access to user accounts, compromising personal information, financial data, or other sensitive data. By preventing these attacks, you safeguard your users' data, maintaining their trust and confidence in your platform.

**3. Resource Conservation:** Brute force attacks can put a strain on your system's resources by repeatedly sending login requests. These attacks can cause server overload, slow down website performance, and consume bandwidth. Implementing preventive measures helps conserve system resources and ensures the smooth functioning of your website.

**4. User Experience:** Brute force attacks can result in successful unauthorized logins, leading to account lockouts, compromised profiles, or even website defacement. By mitigating such attacks, you protect your users from inconvenience, frustration, and potential damage to their online presence.

**5. Reputation and Trust:** A security breach caused by a successful brute force attack can have severe consequences for your organization's reputation and customer trust. Proactively preventing these attacks demonstrates your commitment to user safety and reinforces your credibility as a reliable and secure platform.

> Preventing brute force attacks is vital for maintaining the security and integrity of your system, protecting user data, optimizing resource utilization, providing a seamless user experience, and upholding your organization's reputation.

{% embed url="<https://www.youtube.com/watch?v=wzmPXu55zLU>" %}


# System Requirements

To ensure smooth installation and optimal performance of the Limit Login Attempts Reloaded plugin, please ensure that your system meets the following requirements:

**1. WordPress Version:** The plugin is compatible with WordPress 4.0 or higher. It is recommended to use the latest stable version of WordPress for compatibility and security reasons.

**2. PHP Version:** The plugin requires PHP 5.6 or higher. We recommend using the latest stable version of PHP to ensure compatibility and take advantage of performance improvements and security patches.

**3. MySQL Version:** The plugin is designed to work with MySQL 5.6 or higher. It is important to have a compatible MySQL version for seamless integration and reliable database operations.

**4. Web Server:** The plugin is compatible with popular web servers such as Apache, Nginx,  Microsoft IIS, LightSpeed or any other web server capable of running PHP. Ensure that your web server meets the minimum requirements for hosting WordPress web sites.

**5. Browser Compatibility:** The plugin is designed to be compatible with modern web browsers such as Chrome, Firefox, Safari, Opera, Brave and Edge. Ensure that you are using an up-to-date browser version for the best user experience.


# Installing The Plugin

To install the "Limit Login Attempts Reloaded" plugin and enhance the security of your WordPress website, follow these simple steps:

**1. Log in to your WordPress Admin Dashboard:** Enter your website's URL followed by "/wp-admin" (e.g., [www.yourwebsite.com/wp-admin](http://www.yourwebsite.com/wp-admin)) in your web browser. Provide your login credentials to access the WordPress admin area.

**2. Navigate to the "Plugins" section:** On the left-hand side of the admin dashboard, find the "Plugins" tab and click on it. This will take you to the plugins management page.

**3. Click on "Add New":** Once you're on the plugins page, click on the "Add New" button located at the top of the screen. This will take you to the plugin installation page.

**4. Search for "Limit Login Attempts Reloaded":** In the search field on the top right, type "Limit Login Attempts Reloaded" and press Enter. The plugin should appear in the search results.

**5. Click on "Install Now":** Locate the "Limit Login Attempts Reloaded" plugin from the search results and click on the "Install Now" button next to it. WordPress will automatically download and install the plugin on your website.&#x20;

{% hint style="info" %}
In some cases, the Limit Login Attempts Reloaded plugin might be automatically installed when your web hosting provider sets up your WordPress web site. In these situations you might need your web hosting provider’s assistance updating it to the latest version.
{% endhint %}


# Activating The Plugin

**1. Navigate to the "Plugins" section:** On the left-hand side of the admin dashboard, find the "Plugins" tab and click on it. This will take you to the plugins management page.

**2. Click on “Installed Plugins”:** Use the search bar on the top-right to locate “Limit Login Attempts Reloaded”. Once found, click on the "Activate" link that appears under the plugin title. This will activate the "Limit Login Attempts Reloaded" plugin on your WordPress website.

**3.  Access Plugin Settings:** Once activated, you can access the plugin's settings by clicking on "Settings" in the left-hand menu and selecting "Limit Login Attempts". From there, you can configure the plugin according to your preferences to effectively prevent brute force attacks.

{% hint style="info" %}
The premium version of Limit Login Attempts Reloaded is activated with a special setup code that is sent via email once the subscription is paid for. This is good for one domain or a subdomain, or multiple sites if an Agency plan is used.
{% endhint %}

### How to Activate The Premium Version

{% embed url="<https://www.youtube.com/watch?v=JbGrIYn8RwA>" %}


# Configuration Options

The optimal settings are configured by default. However, users are free to make changes as necessary.&#x20;

{% hint style="info" %}
Please consult a web developer or security professional before making advanced changes to your settings. This could result in admin lockouts and degraded performance.
{% endhint %}

{% content-ref url="/pages/jxOvT88pgVp6pZgYats4" %}
[General Settings](/plugin-settings/general-settings)
{% endcontent-ref %}

{% content-ref url="/pages/9G5Uj6No1OYKMO18Kgyc" %}
[Advanced Settings](/plugin-settings/advanced-settings)
{% endcontent-ref %}


# General Settings

## General Settings

{% content-ref url="/pages/ETHbbG1LvTqQ6wo3h17O" %}
[Enabling/Disabling Plugin](/plugin-settings/general-settings/enabling-disabling-plugin)
{% endcontent-ref %}

{% content-ref url="/pages/JxpiE9YE9p10W9RrKuQ5" %}
[Setting Max Login Attempts](/plugin-settings/general-settings/setting-max-login-attempts)
{% endcontent-ref %}

{% content-ref url="/pages/XYeXnIgWdXoAG3xnLXvg" %}
[Setting The Active App](/plugin-settings/general-settings/setting-the-active-app)
{% endcontent-ref %}

{% content-ref url="/pages/ECZwNLS4h1XEZlFoT3vM" %}
[Setting Lockout Email Notifications](/plugin-settings/general-settings/setting-lockout-email-notifications)
{% endcontent-ref %}

{% content-ref url="/pages/BWEBs2lxRTdjIioIKQBW" %}
[Setting Display Options Within WP Dashboard](/plugin-settings/general-settings/setting-display-options-within-wp-dashboard)
{% endcontent-ref %}

{% content-ref url="/pages/XmcwB8gpgL2tazTiOU8K" %}
[GDPR Compliance](/plugin-settings/general-settings/gdpr-compliance)
{% endcontent-ref %}

{% content-ref url="/pages/b1LiAzIyJdGScV9yM6Fz" %}
[Two-Factor Authentication](/plugin-settings/general-settings/two-factor-authentication)
{% endcontent-ref %}

{% content-ref url="/pages/3kXuzHuZlBEP5o24HwD5" %}
[Successful Login Logs](/plugin-settings/general-settings/successful-login-logs)
{% endcontent-ref %}


# Enabling/Disabling Plugin

Enabling and disabling the "Limit Login Attempts Reloaded" plugin is a straightforward process. Follow the steps below to enable or disable the plugin as needed:

## Enabling The Plugin

**1. Log in to your WordPress Admin Dashboard:** Enter your website's URL followed by "/wp-admin" (e.g., [www.yourwebsite.com/wp-admin](http://www.yourwebsite.com/wp-admin)) in your web browser. Provide your login credentials to access the WordPress admin area.

**2. Navigate to the "Plugins" section:** On the left-hand side of the admin dashboard, find the "Plugins" tab and click on it. This will take you to the plugins management page.

**3. Locate the "Limit Login Attempts Reloaded" Plugin:** Look for the "Limit Login Attempts Reloaded" plugin in the list of installed plugins. It should be listed alphabetically. If you have trouble finding it, you can use the search bar at the top-right to search for the plugin by name.

**4. Click on "Activate":** Once you locate the "Limit Login Attempts Reloaded" plugin, click on the "Activate" button below it. This will enable the plugin, and start protecting your WordPress website against brute force attacks.

## Disabling The Plugin

**1. Log in to your WordPress Admin Dashboard.**

**2. Navigate to the "Plugins" section.**

**3. Locate the "Limit Login Attempts Reloaded" Plugin.**

**4. Click on "Deactivate":** If the "Limit Login Attempts Reloaded" plugin is currently active, you will see a "Deactivate" button below it. Click on this button to disable the plugin.

{% hint style="info" %}
Disabling the plugin will temporarily stop its functionality, but it will not remove any configured settings or data associated with the plugin. If you wish to completely remove the plugin, you can choose to uninstall it instead. If you are a premium account holder, removing the plugin will not cancel your subscription. Please [login to your billing account](https://my.limitloginattempts.com/) to make updates.
{% endhint %}


# Setting Max Login Attempts

In the plugin dashboard, navigate to the **“Settings”** tab. Scroll down to the **“App Settings”**. If you are a free user, you will use the **“Local App”** section. If you are a premium user, you will use the **“Limit Login Attempts Reloaded Cloud App”** section. Look for **“Lockout”** and the field for **“allowed retries”**. This setting will allow you to set how many times an IP address (bot or human) can attempt a login before they get locked out.\
\
By default, the **allowed retries** setting is set to 4. You are free to increase or decrease this. Please be aware that fewer attempts may increase the likelihood of legitimate admins and users to be locked out more frequently. However, if the amount of attempts is set too high, it might increase your brute force activity.

{% hint style="info" %}
We suggest keeping the default setting unless suggested by your web host or a security professional.&#x20;
{% endhint %}


# Setting The Active App

There are two types of app settings for the plugin. The **“Local”** app is defaulted for free users, and will handle all IP handling on the local server. The **“Limit Login Attempts Reloaded Cloud”** app will activate automatically when you upgrade to premium. This means that IP handling will be managed by the cloud app, which will offload the brute force activity from your local server. In the event you exceed the amount of resources in your premium plan, the app will downgrade to **“Local”** until the following month. You may contact support to upgrade, or wait until the new month when requests are reset. Also, in the event your premium subscription is canceled, you’ll be downgraded to the **“Local”** app. We will notify you before we terminate your premium account via email.\
\
When in the plugin dashboard, navigate to the **“Settings”** tab. In the **“General Settings”**, you’ll find the field for **“Active App”** about half way down the page.&#x20;


# Setting Lockout Email Notifications

In the plugin dashboard, navigate to the **“Settings”** tab. In the **“General Settings”**, scroll to **“Notify on lockout”**. By default, the system will notify you after 3 IP lockouts and send to the email you specify in this field. By default, the email is set to your WordPress admin email. If you lower this number, you will likely receive more notifications, but also have more awareness of failed logins on your website. You may also disable this feature altogether by unchecking the box, which we do not recommend unless you are signed up for premium. Otherwise, you will be unaware of elevated attacks.

{% hint style="info" %}
We suggest keeping the default setting unless suggested by your web host or a security professional.&#x20;
{% endhint %}


# Two-Factor Authentication

Two-Factor Authentication (2FA) adds an extra layer of security to your WordPress login by requiring a one-time verification code in addition to your password. With Limit Login Attempts Reloaded version 3.0 and above, 2FA is simple to enable and available to both free and premium users. Passwords alone are no longer enough to protect your site, as they can be compromised through data breaches, phishing attacks, or reuse across multiple platforms. By enabling 2FA, you ensure that even if someone gains access to your password, they will not be able to log in without the additional verification code sent to your email.

To enable 2FA, navigate to your WordPress dashboard and go to **Limit Login Attempts → 2FA Settings**. From there, check the option to enable multi-factor authentication and select the user roles that should be required to use 2FA. It is highly recommended to enable this feature for administrators first, as these accounts have the highest level of access and are the most important to protect. Once you have selected the appropriate roles, click Save Settings to continue.

<figure><img src="/files/QV10B8FFsM0IfYjAXAz9" alt=""><figcaption></figcaption></figure>

Before fully activating 2FA, you will be prompted to **download your rescue links**. These are one-time use backup links that allow you to regain access to your account if you are unable to receive the verification email or lose access to your email address. It is important to store these links in a secure location, such as a password manager, printed copy, or encrypted file. You can copy them to your clipboard, print them, or download them as a PDF. After saving them, confirm that you have stored your rescue links and proceed by clicking Activate 2FA and Save Settings. Each rescue link can only be used once, so they should be treated as sensitive security credentials.

Once 2FA is enabled, your login process will include an additional verification step. After entering your username and password, you will receive a six-digit verification code sent to your registered email address. Enter this code on the verification screen to complete your login. These codes expire quickly, typically within a few minutes, to ensure maximum security.

<figure><img src="/files/aVse3gJhl9oLN84naOuj" alt=""><figcaption></figcaption></figure>

The verification email will also include helpful information about the login attempt, such as the IP address, location, browser, and device used. This allows you to quickly identify whether the login attempt was legitimate. If you do not recognize the attempt, you should immediately change your WordPress password and review your site’s security settings.

If you are unable to access your email and cannot receive the verification code, you can use one of your rescue links to regain access to your site. When a rescue link is used, 2FA will be temporarily disabled for a short period, allowing you to log in and update your settings. Because each link can only be used once, it is important to keep them safe and generate new ones if needed.

This email-based 2FA system is designed to be both secure and easy to use, requiring no additional apps or complicated setup. It works alongside Limit Login Attempts Reloaded’s existing protections, including brute force protection, IP intelligence, and login monitoring, to create a layered security approach. By enabling 2FA, you significantly reduce the risk of unauthorized access and strengthen the overall security of your WordPress site.

\ <br>

<br>


# IP Data Handling

We save IPs locally (meaning where the WordPress website lives) in the free version and send them to our cloud in the paid version. We don’t install any cookies, except for the two in the dashboard “llar\_enable\_notify\_notice\_shown” and “llar\_review\_notice\_shown”. This fixes AJAX-related issues for some customers with misconfigured sites. Those cookies don’t track anything.&#x20;


# Displaying Privacy Terms

In the plugin dashboard, navigate to the **“Settings”** tab. Right under the **“General Settings”** on the top you’ll see **“GDPR Compliance”**. Check the box next to it to display privacy terms. Underneath you’ll see the **“GDPR message”** which can be modified. You can use a shortcode here to insert links, for example, a link to your Privacy Policy page. The shortcode is: \[llar-link url="<https://example.com>" text="Privacy Policy"]


# Setting Display Options Within WP Dashboard

You have the option of hiding certain elements of the plugin within the WordPress admin dashboard. In the plugin dashboard, navigate to the **“Settings”** tab. In the **“General Settings”**, you’ll find the following items:

{% content-ref url="/pages/GizQCHC90qmGgtJMYbzN" %}
[Displaying Left Menu Item](/plugin-settings/general-settings/setting-display-options-within-wp-dashboard/displaying-left-menu-item)
{% endcontent-ref %}

{% content-ref url="/pages/ZH0GsChEgnl4jsJcTil5" %}
[Hide Dashboard Widget](/plugin-settings/general-settings/setting-display-options-within-wp-dashboard/hide-dashboard-widget)
{% endcontent-ref %}

{% content-ref url="/pages/dAaSLRG7YU1ojXvFEMUP" %}
[Showing Warning Badge](/plugin-settings/general-settings/setting-display-options-within-wp-dashboard/showing-warning-badge)
{% endcontent-ref %}

{% content-ref url="/pages/oy4Mf3SCNYZp3dyBjGQK" %}
[Displaying Top Menu Item](/plugin-settings/general-settings/setting-display-options-within-wp-dashboard/displaying-top-menu-item)
{% endcontent-ref %}


# Displaying Left Menu Item

This option will show the LLAR logo icon in your left-hand menu within your WordPress admin dashboard. By default, this option is checked for new installs. If you uncheck this option, you may only access LLAR by clicking on **"Settings"** in the left-hand menu and selecting **"Limit Login Attempts"**.


# Hide Dashboard Widget

This option allows you to hide the report widget that is found on the WordPress Admin Dashboard Home Screen. By unchecking this option, this widget will be removed from the Home screen.


# Showing Warning Badge

This option allows you to hide the warning icon that displays next to the LLAR logo icon in your left-hand menu within your WordPress admin dashboard. By unchecking this option, this warning icon will be removed


# Displaying Top Menu Item

This option will show the LLAR logo icon in your top horizontal menu within your WordPress admin dashboard. By default, this option is checked for new installs. If you uncheck this option, it will remove the menu item.&#x20;


# GDPR Compliance

Both free and paid versions of our plugin are GDPR compliant. The compliance is achieved by displaying a security message on the login screen of your website. This message can be turned on and off from the Settings page of the plugin.\
\
GDPR does not make consent a mandatory requirement for all processing of personal data. Consent ([Article 6 (1)a](https://gdpr-info.eu/art-6-gdpr/)) is indeed one of conditions that can be used to comply with the GDPR requirement that processing must be lawful, but it is not the only condition available to the controller to ensure lawful processing – there are alternatives (before the list of conditions it says that “at least one of the following” must be satisfied).

All the conditions for lawfulness of processing are spelled out in Article 6 of the GDPR. One of alternatives is Article 6 (1)f. It says it is legal to process personal data if Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.\
\
Logging IP addresses for the purpose of security is an extremely widespread practice. It is a legitimate interest to comply with standard security practices. It is the default, and most websites do this. It is legal to do this without a consent.

{% content-ref url="/pages/QjYWaG5qKYRobguF4v0v" %}
[IP Data Handling](/plugin-settings/general-settings/gdpr-compliance/ip-data-handling)
{% endcontent-ref %}

{% content-ref url="/pages/5O3vd5RTbdsL4jpkoHa3" %}
[Displaying Privacy Terms](/plugin-settings/general-settings/gdpr-compliance/displaying-privacy-terms)
{% endcontent-ref %}

\ <br>

<br>


# IP Data Handling

We save IPs locally (meaning where the WordPress website lives) in the free version and send them to our cloud in the paid version. We don’t install any cookies, except for the two in the dashboard “llar\_enable\_notify\_notice\_shown” and “llar\_review\_notice\_shown”. This fixes AJAX-related issues for some customers with misconfigured sites. Those cookies don’t track anything.&#x20;


# Displaying Privacy Terms

In the plugin dashboard, navigate to the **“Settings”** tab. Right under the **“General Settings”** on the top you’ll see **“GDPR Compliance”**. Check the box next to it to display privacy terms. Underneath you’ll see the **“GDPR message”** which can be modified. You can use a shortcode here to insert links, for example, a link to your Privacy Policy page. The shortcode is: \[llar-link url="<https://example.com>" text="Privacy Policy"]


# Successful Login Logs

The Successful Login Logs feature helps you monitor legitimate logins to your WordPress site. This gives administrators better visibility into who is accessing the site, when they logged in, what IP address was used, and what user role was involved.

This premium feature is especially helpful for spotting unusual login activity. For example, if an administrator account logs in from an unfamiliar location, unknown IP address, or unexpected internet provider, you can investigate quickly and take action if needed.

<figure><img src="/files/dWlw0s9c7JEW90Jkqtar" alt=""><figcaption></figcaption></figure>

In the Successful Login Attempts section, you will see a list of recent successful logins. Each entry includes the login time, username, IP address, and user role. You can click the dropdown arrow on a login entry to expand it and view additional location details connected to the IP address.

Expanded login details may include the continent, country, state or province, district, city, zip code, latitude and longitude, timezone, and internet provider. A map may also appear to show the approximate location of the login based on the IP address.

Please note that IP-based location details are approximate and may not always reflect the user’s exact physical location. VPNs, corporate networks, mobile carriers, and internet providers can affect the location shown.

To review successful login logs, go to the Limit Login Attempts Reloaded dashboard and find the Successful Login Attempts panel on the dashboard. Review the list regularly and look for anything unusual, such as admin logins from unexpected regions, repeated logins from unfamiliar IP addresses, or users accessing the site at unusual times.

If you notice suspicious activity, we recommend changing the affected user’s password, enabling [Two-Factor Authentication](/plugin-settings/general-settings/two-factor-authentication), reviewing admin users, and checking your site for any unauthorized changes.


# Advanced Settings

## Advanced Settings

{% content-ref url="/pages/vqSfVbFg9UC7F1CGgoE7" %}
[Safelist & Denylist](/plugin-settings/advanced-settings/safelist-and-denylist)
{% endcontent-ref %}

{% content-ref url="/pages/jJWCN4MkyESD9YrOTFdd" %}
[Trusted IP Origins](/plugin-settings/advanced-settings/trusted-ip-origins)
{% endcontent-ref %}

{% content-ref url="/pages/kXiE0J2v8anCaRgOCc8y" %}
[IP Logs](/plugin-settings/advanced-settings/ip-logs)
{% endcontent-ref %}


# Safelist & Denylist

The Safelist and Denylist give admins the ability to always allow or deny IPs or IP ranges from logging in. There are two different ways to manage your Safelist and Blocklist.

## Free Version

When in the plugin dashboard, navigate to the **“Logs”** tab. Right under **“Statistics”** you’ll see boxes for **“Safelist”** and **“Denylist”**. In the first box, you can add/remove one IP or IP range (1.2.3.4-5.6.7.8) per line. In the second box, you can add/remove your login usernames. Make sure to save when finished.

## Premium Version

If you’re a premium user, the safelist and blocklist have a slightly different interface. They are called **“IP Access Rules”** and **“Login Access Rules”**. You may enter values here similar to the free version. For a more detailed explanation, please view IP Log Management.&#x20;

{% hint style="info" %}
Premium users receive advanced IP intelligence, which detects, counters, and neutralizes malicious login attempts. This requires virtually no manual actions from the user to manage the safelist and denylist.&#x20;
{% endhint %}

{% content-ref url="/pages/vm9I8FAKhh5RogvltZAJ" %}
[Block By Country](/plugin-settings/advanced-settings/safelist-and-denylist/block-by-country)
{% endcontent-ref %}

<br>


# Block By Country

**You must be a premium user to use this feature.**&#x20;

When in the plugin dashboard, navigate to the **“Logs”** tab. Right under **“Country Access Rules”** you’ll see boxes where you can deny or allow specified countries.&#x20;


# Trusted IP Origins

A Trusted Origin allows you to specify a server variable name that your website uses to retrieve the visitor's correct IP address when the server cannot determine it reliably.

## Free Version

In the free version of the plugin, you can specify the origins you trust in order of priority, separated by commas. When in the plugin dashboard, navigate to the “settings” tab. In the “App Settings”, you’ll find the section for “Local App”. Here you can modify the “Trusted IP Origins”. We strongly recommend that you do not use anything other than REMOTE\_ADDR since other origins can be easily faked. Examples: HTTP\_X\_FORWARDED\_FOR, HTTP\_CF\_CONNECTING\_IP, HTTP\_X\_SUCURI\_CLIENTIP.

## Premium Version

This is managed within the cloud automatically.&#x20;

<br>


# IP Logs

There are a few different tables with statuses and various actions that can be performed.

To Access the **“Event Logs”**, go to the **“Logs”** tab in the LLAR dashboard inside the plugin dashboard.&#x20;

{% content-ref url="/pages/WF6vjzs7c5gxYpRjQ7cn" %}
[Active Lockouts Log](/plugin-settings/advanced-settings/ip-logs/active-lockouts-log)
{% endcontent-ref %}

<br>


# Active Lockouts Log

The active Lockout table provides a list of all lockouts that are currently active and enabled. It contains the IP address, login name, how many attempts were made (Count), and when the lockout will expire (Expires in minutes).

## **Event Logs**

This is a log of all login attempts for your website.

### Table Definitions

**Time:** the time the attempt was recorded (using the time configured on your site).

**IP:** IP address associated with the attempt.

**Gateway:** The URL that was used by the attack.

**Login:** Username that was used in the attack.

**Rule:** The rule that was triggered. It’s either allow or deny.

**Reason:** There are quite a few different statuses available here:

* **ip\_acl\_temp\_local\_deny** – IP blocked temporary for this site only
* **ip\_acl\_temp\_network\_deny** – IP blocked temporary for the group of sites this site belongs to
* **ip\_acl\_local\_deny** – IP blocked by allow/deny rules for this site only
* **ip\_acl\_network\_deny** – IP blocked by allow/deny rules for the group of sites this site belongs to
* **ip\_lockout\_allow\_expired** – IP allowed b/c its lockout period has expired
* **ip\_lockout\_allow\_below\_limit** – IP allowed b/c the number of attempts is below limit
* **ip\_lockout\_deny** – IP is locked out b/c the number of attempts is above limit
* **ip\_acl\_xmlrpc\_deny** – IP is locked out b/c the XML-RPC gateway is closed
* **login\_acl\_local\_pass** – attempt allowed b/c of a local login pass rule
* **ip\_acl\_local\_pass** – attempt allowed b/c of a local ip pass rule
* **all\_acl\_none** – there were no allow/deny rules matching the request
* **country\_acl\_local\_allow** – the country is allowed for this site
* **country\_acl\_local\_deny** – the country is denied for this site
* **ip\_acl\_temp\_none** – IP is not blocked temporary
* **all\_acl\_local\_allow** – both IP and login are allowed by allow rules for this site only
* **all\_acl\_network\_allow** – both IP and login are allowed by allow/deny rules for the group of sites this site belongs too
* **login\_acl\_network\_deny** – login is blocked by a deny rule for the group of sites this site belongs too
* **login\_acl\_local\_deny** – login is blocked by a deny rule for this site only

**Pattern:** A username that you listed, an IP or range of IPs, a country. This is an entity based on which the decision was made to allow or deny an attempt.

**Attempts Left:** How many attempts are left for the IP at the time the attempt happened.

**Lockout Duration:** How many minutes are left before the IP is unlocked automatically, at the time the attempt happened.

**Actions:** You can add or remove IPs and logins to/from your allow/deny lists.

### **Icons definitions for actions:**

**Open Red Lock** – Unlock IP (release an active automatic lockout)

**Red Plus Sign** – Add IP Or Login To Deny Rules

**Red Minus Sign** – Remove IP Or Login From Deny Rules

**Green Plus Sign** – Add IP Or Login To Allow Rules

<br>


# Accessing List of Denied/Allowed Usernames & IPs

When in the plugin dashboard, navigate to the **“Logs”** tab. Right under **“Statistics”** you’ll see boxes for **“Safelist”** and **“Blocklist”**. In the first box, you can add one IP or IP range (1.2.3.4-5.6.7.8) per line. In the second box, you can add your login usernames. Make sure to save when finished.

If you’re a premium user, the safelist and blocklist have a slightly different interface. They are called **“IP Access Rules”** and **“Login Access Rules”**. You may enter values here similar to the free version.&#x20;

For a more detailed explanation, please view **"IP Logs".**

{% content-ref url="/pages/kXiE0J2v8anCaRgOCc8y" %}
[IP Logs](/plugin-settings/advanced-settings/ip-logs)
{% endcontent-ref %}


# Viewing Details of Denied Attempts

To view the details of denied attempts, please go to **"IP Logs"** for more information.

{% content-ref url="/pages/kXiE0J2v8anCaRgOCc8y" %}
[IP Logs](/plugin-settings/advanced-settings/ip-logs)
{% endcontent-ref %}


# Allowing Usernames & IPs

Many users will want to add their admin usernames and local IPs to the safelist in order to prevent the possibility of a lockout.&#x20;

**Please see "Safelist and Denylist" for more information on allowing and denying users and IPs.**

{% content-ref url="/pages/vqSfVbFg9UC7F1CGgoE7" %}
[Safelist & Denylist](/plugin-settings/advanced-settings/safelist-and-denylist)
{% endcontent-ref %}

{% hint style="info" %}
Premium users may also login to their [billing account](https://my.limitloginattempts.com) to manage their safelist and denylist. They can also unblock their admins here too.&#x20;
{% endhint %}


# Receiving Email Notifications

In **“General Settings”**, you have the option of receiving email notifications when an IP reaches a certain amount of lockouts. By default, this is set at 3. The email will be sent to your admin email by default, but this can be changed to any email you prefer. You may also turn off this notification.\
\
It’s possible to receive several emails in a short period of time when you’re under brute force attack. This is normal behavior and can help you gauge the seriousness of the attack.\
\
Premium users will receive a monthly digest email with stats from failed login attempts from the previous month. Free users who subscribe to our email list will also receive occasional updates on new features and security updates.

{% content-ref url="/pages/ECZwNLS4h1XEZlFoT3vM" %}
[Setting Lockout Email Notifications](/plugin-settings/general-settings/setting-lockout-email-notifications)
{% endcontent-ref %}


# Analyzing Login Attempts & Statistics

{% content-ref url="/pages/HMHbKTHD5e8iOPlS5zvm" %}
[Dashboard Statistics](/notifications-and-reporting/analyzing-login-attempts-and-statistics/dashboard-statistics)
{% endcontent-ref %}

{% content-ref url="/pages/YsjREemajrZg7GcPZOFt" %}
[Reviewing IP Logs](/notifications-and-reporting/analyzing-login-attempts-and-statistics/reviewing-ip-logs)
{% endcontent-ref %}

<br>


# Dashboard Statistics

For both free and premium versions of the plugin, there are charts and statistics on the LLAR main plugin dashboard.

## Failed Login Attempts (Past 24 Hours)

On the top left of the dashboard, you’ll find the amount of failed login attempts from the past 24 hours. If you are a premium user, these failed login attempts have been processed in the cloud, and do not pose a threat to your website.

## Failed Login Attempts (Chart)

On the top right of the dashboard, you’ll find a chart showing the past 14 days of failed login attempts.

## Failed Login Attempts By Country (Global Network)

On the bottom left, you’ll find a table for failed login attempts by country. The purpose of this table is to provide a high level view of where the attacks are originating from in our network.&#x20;

{% hint style="info" %}
Please note this is data collected from the premium network, which consists of thousands of websites.&#x20;
{% endhint %}

## Failed Login Attempts (Chart - Global Network)

On the bottom right, you’ll find a chart for failed login attempts for the past 14 days. The purpose of this chart is to provide a high level view of the velocity of attacks over the past 14 day period.&#x20;

{% hint style="info" %}
Please note this is data collected from the premium network, which consists of thousands of websites.
{% endhint %}


# Reviewing IP Logs

Review the IP logs for detailed information on login attempts.

In order to review the IP logs, go to the **"logs"** tab inside the plugin dashboard. The "Active Lockouts" log will share important information about the IPs that have attempted logins. \
\
**You can learn more about logs including definitions here:**&#x20;

{% content-ref url="/pages/WF6vjzs7c5gxYpRjQ7cn" %}
[Active Lockouts Log](/plugin-settings/advanced-settings/ip-logs/active-lockouts-log)
{% endcontent-ref %}


# Exporting IP Data

For premium users, they have the option to download their IP data.[ Login to your billing dashboard](https://my.limitloginattempts.com/user/login) and go to **“Domains”** on the left-hand menu. All of your domains will be listed here, and under the **“Logs”** column you can export a CSV file of the data.


# Common Issues & Resolutions

Here you'll find a list of common issues and resolutions.&#x20;

{% content-ref url="/pages/7o4KX1T32jBYRYCQupLh" %}
[Unlocking An Admin That Gets Locked Out](/troubleshooting-and-support/common-issues-and-resolutions/unlocking-an-admin-that-gets-locked-out)
{% endcontent-ref %}

{% content-ref url="/pages/mODVcQkAJh3H8a1AxRYl" %}
[Seeing Login Attempts After an IP Address Has Been Denied by IP Access Rules](/troubleshooting-and-support/common-issues-and-resolutions/seeing-login-attempts-after-an-ip-address-has-been-denied-by-ip-access-rules)
{% endcontent-ref %}


# Unlocking An Admin That Gets Locked Out

Open the site from another IP address. Users can do this from a mobile device phone, or use Opera browser and enable free VPN. Try turning off the router for a few minutes and then see if it assigns a different IP address. These will work if the website hosting server is configured correctly.\
\
If that doesn’t work, connect to the site using FTP or the hosting control panel file manager. Navigate to “wp-content/plugins/” and rename the limit-login-attempts-reloaded folder. Login to the site then rename that folder back to the original, and safelist your IP through **IP access rules**.&#x20;

{% hint style="info" %}
By upgrading to our[ premium app](https://www.limitloginattempts.com/services/technical-questions/#llar-checkout), users will have the unlocking functionality right from the cloud so they'll never have to deal with this issue.&#x20;
{% endhint %}

{% content-ref url="/pages/axul0LE36PNKv3y4jM5o" %}
[Allowing Usernames & IPs](/managing-denied-allowed-users/allowing-usernames-and-ips)
{% endcontent-ref %}

{% content-ref url="/pages/vqSfVbFg9UC7F1CGgoE7" %}
[Safelist & Denylist](/plugin-settings/advanced-settings/safelist-and-denylist)
{% endcontent-ref %}

<br>


# Seeing Login Attempts After an IP Address Has Been Denied by IP Access Rules

It’s common to see blocked IP’s making login attempts. They are not a threat, and will fail.&#x20;

To stop a malicious login attempt completely, users would need to filter all traffic that goes to their website before it hits the WordPress installation. This is only possible when users have an extra level of software called **“reverse proxy”**.

With reverse proxy, all requests to a website including login attempts first hit that proxy, and if the proxy is smart enough, it will deny the bad requests and allow the good ones. Then the good requests will hit the website.

**There are 2 main problems with reverse proxies:**

1. **They are usually not easy to implement and hiring a web developer is required.** Users will have to give the developer access to their domain management console and/or their hosting account console. Also users will have to install additional WordPress plugins that will make their site compatible with the proxies.
2. **The most popular proxies are generic.** They are not dedicated to WordPress exclusively, instead they try to cover all websites. Hence they have much less information to decide whether a request is bad or not, compared to more focused solutions like Limit Login Attempts Reloaded.

A typical WordPress installation doesn’t use a proxy and all requests will reach the website. At this point, the Limit Login Attempts Plugin comes into play. The plugin decides if a request is legit enough to at least let it try to log in, and if it’s not, it stops the attempt right away.

Since all requests get to the site, users see the login attempts in their log even after they denied the related IPs, usernames or countries. **All of them will get denied**.

There is no comprehensive way to stop the attempts completely without using an extra piece of software called “reverse proxy”, but using the Limit Login Attempts Reloaded plugin will deny the malicious attempts. <br>


# Frequently Asked Questions (FAQ)

{% hint style="info" %}
For a more comprehensive list of FAQs, please [visit our our help center](https://www.limitloginattempts.com/resources/).&#x20;
{% endhint %}

{% content-ref url="/pages/rymGZwk4fsRnJPUQcjlc" %}
[How do I know if I'm under attack?](/troubleshooting-and-support/frequently-asked-questions-faq/how-do-i-know-if-im-under-attack)
{% endcontent-ref %}

{% content-ref url="/pages/8DdLsPDEVcnhtjUWZc1s" %}
[How can I tell that the premium plugin is working?](/troubleshooting-and-support/frequently-asked-questions-faq/how-can-i-tell-that-the-premium-plugin-is-working)
{% endcontent-ref %}

{% content-ref url="/pages/dEdfmA9sVYSl3Vg9J26w" %}
[Could these failed login attempts be fake?](/troubleshooting-and-support/frequently-asked-questions-faq/could-these-failed-login-attempts-be-fake)
{% endcontent-ref %}

{% content-ref url="/pages/0saoghr0Bp3pcE1RimQt" %}
[What happens if my site exceeds the request limits in the plan?](/troubleshooting-and-support/frequently-asked-questions-faq/what-happens-if-my-site-exceeds-the-request-limits-in-the-plan)
{% endcontent-ref %}

{% content-ref url="/pages/FU89HRea2v3EVE1rSgPZ" %}
[What do I do if all users get blocked?](/troubleshooting-and-support/frequently-asked-questions-faq/what-do-i-do-if-all-users-get-blocked)
{% endcontent-ref %}

{% content-ref url="/pages/1L4K4m2Kh7TKLyUYJO71" %}
[What URLs are being attacked and protected?](/troubleshooting-and-support/frequently-asked-questions-faq/what-urls-are-being-attacked-and-protected)
{% endcontent-ref %}

{% content-ref url="/pages/agPZSiNtSYNsFHL8Dtks" %}
[What do I do when an admin gets blocked?](/troubleshooting-and-support/frequently-asked-questions-faq/what-do-i-do-when-an-admin-gets-blocked)
{% endcontent-ref %}

{% content-ref url="/pages/JWFm2Od7rwUhF6KBijPb" %}
[How is LLAR better than other brute-force protection plugins?](/troubleshooting-and-support/frequently-asked-questions-faq/how-is-llar-better-than-other-brute-force-protection-plugins)
{% endcontent-ref %}


# How do I know if I'm under attack?

An easy way to check if the attack is legitimate is to copy the IP address from the lockout notification, and go to <https://whatismyipaddress.com/ip-lookup>. Enter in the IP address to see if you recognize the location. If the location is not somewhere you recognize and you have received several failed login attempts, then you are likely being attacked. You might notice dozens or hundreds of IPs each day.

{% hint style="info" %}
In the premium version, users have access to enhanced logs which will show the country of origin without having to conduct additional research.&#x20;
{% endhint %}


# How can I tell that the premium plugin is working?

After you upgrade to our premium version, you will see a new dashboard in your WordPress admin that shows all attacks that will now relay through our cloud service.\
\
You will still see the attacks because they will never stop regardless if you upgrade, but now our cloud service will safely process and neutralize them without taking resources from your site. This is very important and positively impacts your site’s stability and performance.\
\
In some cases, you may notice an increase in speed and efficiency with your website. Also, a reduction in lockout notifications via email.&#x20;

<br>


# Could these failed login attempts be fake?

Some users feel that it’s impossible to receive so many failed login attempts, especially since they’re site was just created or they have minimal human traffic. Let us be clear that these failed login attempts are NOT generated by the plugin. New websites are often hosted on a shared IP address, which makes it very easy for hackers to find. Also, new domain names are often crawled once they are created, so as soon as a WordPress website is built on it, it’s vulnerable to attacks. New websites are often the best target since security is not top of mind for site owners.

<br>


# What happens if my site exceeds the request limits in the plan?

The premium plan’s resource limits start from 100,000 requests per month, which should accept almost any heavy brute-force attack. We monitor all of our sites and will alert the user if it appears they are going over their limits. If limits are reached, we will suggest upgrading to the next plan. If you are using the free version, the load caused by brute force attacks will be absorbed by your current hosting bandwidth, which might require more server bandwidth resulting in increased hosting costs.

<br>


# What do I do if all users get blocked?

If you are using contemporary hosting, it’s likely your site uses a proxy domain service like CloudFlare, Sucuri, Nginx, etc. They replace your user’s IP address with their own. If your server is not configured properly, all users will get the same IP address. This also applies to bots and hackers. Therefore, locking one user will lead to locking everybody else out. In the free version of the plugin, this can be adjusted using the **Trusted IP Origin setting**. In the premium version, the cloud service intelligently recognizes the non-standard IP origins and handles them correctly, even if your hosting provider does not.

{% content-ref url="/pages/jJWCN4MkyESD9YrOTFdd" %}
[Trusted IP Origins](/plugin-settings/advanced-settings/trusted-ip-origins)
{% endcontent-ref %}

<br>


# What URLs are being attacked and protected?

The URLs being protected are your login page (wp-login.php, wp-admin), xmlrpc.php, WooCommerce login page, and any custom login page you have that uses regular WordPress login hooks.<br>


# How is LLAR better than other brute-force protection plugins?

Our main focus is protecting your site from brute-force attacks. This allows our plugin to be very lean and effective. It doesn’t require a lot of your web hosting resources and keeps your site well-protected. More importantly, it does all of this automatically as our service learns on its own about each IP it encounters. In contrast, a firewall would require manual addition or removal of IPs. We’ve published an article about it [here](https://www.limitloginattempts.com/should-i-block-ip-addresses/).

<br>


# What do I do when an admin gets blocked?

Open the site from another IP. You can do this from your cell phone, or using Opera browser and enabling free VPN there. You can also try turning off your router for a few minutes and then see if you get a different IP address. These will work if your hosting server is configured correctly. If that doesn’t work, connect to the site using FTP or  your hosting control panel file manager. Navigate to wp-content/plugins/ and rename the limit-login-attempts-reloaded folder. Log in to the site then rename that folder back and whitelist your IP.

{% hint style="info" %}
By upgrading to our[ premium app](https://www.limitloginattempts.com/services/technical-questions/#llar-checkout), you will have the unlocking functionality right from the cloud so you’ll never have to deal with this issue.
{% endhint %}

{% content-ref url="/pages/7o4KX1T32jBYRYCQupLh" %}
[Unlocking An Admin That Gets Locked Out](/troubleshooting-and-support/common-issues-and-resolutions/unlocking-an-admin-that-gets-locked-out)
{% endcontent-ref %}

{% content-ref url="/pages/vqSfVbFg9UC7F1CGgoE7" %}
[Safelist & Denylist](/plugin-settings/advanced-settings/safelist-and-denylist)
{% endcontent-ref %}

<br>


# Debug Info

In some cases, you’ll have to provide info from the plugin to help our technical support team diagnose potential issues. While in the plugin, navigate to the **“Debug”** tab and you’ll see a field for **“Debug Info”**. Please copy the contents of this field and send to support if requested.&#x20;

<br>

<br>

<br>


# Software Version

While in the plugin, navigate to the **“Debug”** tab and you’ll see a field for **“Version”** towards the bottom.&#x20;


# Contacting Support For Assistance

To contact our support, we offer different options based on your usage of the software. If you are a free user, you can utilize the [community forum on WordPress.org](https://wordpress.org/support/plugin/limit-login-attempts-reloaded/) for assistance. Many common questions have already been addressed by other users, and our community is active in providing support. While we strive to answer questions within 7 days, we may not answer it at all if your query has already been answered.&#x20;

For our Premium users, we provide dedicated technical support via email. Our support team is available from 9am to 5pm EST (US) daily to address your inquiries and provide personalized assistance. Typically we reply in an hour, but there are times it might take longer. To reach our Premium support, you can send an email to **<support@limitloginattempts.com>**. Our team will promptly attend to your concerns and ensure that you receive the support you need.

We value your satisfaction and are committed to providing quality support to all our users. Whether you are a free user relying on the community forum or a Premium user with access to email support, we are here to assist you and help you make the most of our software.

<br>


# Using Strong Passwords

When it comes to using strong passwords in WordPress, following these best practices will significantly enhance the security of your website:

&#x31;**. Length and Complexity:** Use passwords that are at least 12 characters long. Include a combination of uppercase and lowercase letters, numbers, and special characters (!, @, #, $, etc.). Avoid using common dictionary words or easily guessable information like your name, birthdate, or "password."

**2. Unique Passwords:** Ensure that each user account on your WordPress website has a unique password. Avoid reusing passwords across multiple accounts, as compromising one account could potentially lead to unauthorized access to others.

**3. Password Managers:** Consider using a trusted password manager tool to generate, store, and manage your passwords securely. These tools can generate complex passwords for you and remember them, so you don't have to rely on memory or write them down.

**5. Regular Password Updates:** Encourage users, including yourself, to change their passwords periodically. Set a password change policy that specifies the frequency of password updates, such as every 90 days, to minimize the risk of long-term compromises.

**6. Secure Password Recovery:** Ensure that your password recovery options, such as security questions or email verification, are properly set up and not easily guessable or prone to social engineering attacks. Choose strong security questions or use alternative methods for account recovery.

**7. Limit User Access and Privileges:** Grant administrative privileges and access only to trusted individuals who require them. Restrict user roles and permissions to limit potential damage if an account is compromised.\
\
**8. Educate Users:** Provide guidance and training to your WordPress users on the importance of using strong passwords and adhering to password security practices. Encourage them to create unique, complex passwords and reinforce the significance of maintaining good password hygiene.<br>


# Implementing Additional Security Measures

In addition to keeping plugins updated and following best practices, here are some additional security measures for WordPress users:

**1. Website Firewall:** Consider using a website firewall service or plugin that helps detect and block malicious traffic, such as distributed denial-of-service (DDoS) attacks, SQL injections, and cross-site scripting (XSS) attempts.

**2. Two-Factor Authentication:** Two-factor authentication (2FA) adds a critical second layer of protection by requiring a one-time code in addition to your password, making it much harder for attackers to access your account. Even if your password is compromised, 2FA helps prevent unauthorized logins and keeps your site secure.

**3. SSL/TLS Encryption:** Enable SSL/TLS encryption for your website to secure data transmission between your visitors and your server. This is especially important for websites that handle sensitive information like login credentials or financial transactions.

**4. File Permissions:** Set proper file permissions for your WordPress installation to restrict unauthorized access. Limit write permissions to essential directories and files, preventing malicious code injection or unauthorized modifications.

**5. Regular Website Backups:** Perform regular backups of your entire WordPress website, including its database, files, and plugins. Store backups securely offsite or in a separate server to ensure you can restore your website in case of a security incident or data loss.

**6. Security Audits:** Periodically conduct security audits of your WordPress website. Use security scanning tools or hire professionals to identify vulnerabilities, weak points, or outdated software that may pose a risk. Regular audits help you stay proactive in addressing potential security issues.

**7. User Awareness and Training:** Educate your website users, including administrators and contributors, about security best practices. Encourage them to use strong passwords, update their devices and plugins, and be cautious of phishing attempts and suspicious links.

**8. Secure Hosting Environment:** Choose a reputable and secure hosting provider that follows robust security practices. Ensure that they regularly update server software, monitor for security vulnerabilities, and offer features like firewalls and intrusion detection systems.

By implementing these additional security measures, you enhance the overall security posture of your WordPress website, reducing the likelihood of successful attacks and safeguarding your data and user privacy.

<br>

<br>


# Regularly Updating WordPress and Plugins

To keep WordPress plugins updated and minimize the risk of your website being compromised, follow these essential practices:

**1. Regularly Update Plugins:** Stay vigilant about updating your plugins to the latest available versions. Developers often release updates to address security vulnerabilities and improve overall functionality. Enable automatic updates for plugins whenever possible, or manually check for updates frequently.

**2. Enable Automatic Updates for WordPress Core:** Keep your WordPress core software up to date by enabling automatic updates. This ensures that you have the latest security patches and bug fixes, reducing the chances of exploitation.

**3. Use Trusted and Well-Maintained Plugins:** Select plugins from reputable sources, such as the official WordPress Plugin Directory or reputable third-party marketplaces. Verify the plugin's rating, reviews, and the developer's track record to ensure its reliability and ongoing maintenance.

**4. Remove Unnecessary Plugins:** Regularly review your installed plugins and remove any that are no longer necessary. Unused or outdated plugins can become security liabilities if they are not maintained or updated regularly. Reduce the potential attack surface by keeping your plugin list lean and efficient.

**5. Enable Plugin Auto-Updates:** Whenever possible, enable automatic updates for plugins. Many popular plugins offer this feature, allowing you to receive security patches and new features without manual intervention. However, ensure that auto-updates won't conflict with your website's stability or specific plugin configurations.

**6. Monitor Plugin Vulnerabilities:** Stay informed about plugin vulnerabilities and security advisories. Subscribe to plugin update notifications, security mailing lists, or use security monitoring services to receive alerts about known vulnerabilities. This helps you stay proactive in identifying and addressing potential security risks.

**7. Maintain Regular Website Backups:** Regularly backup your WordPress website, including its plugins and database. In the event of a security breach or plugin-related issues, having recent backups allows you to restore your website to a known secure state.

**8. Keep WordPress User Accounts Secure:** Ensure that all user accounts on your WordPress site have strong, unique passwords and implement two-factor authentication (2FA) whenever possible. Strong user account security adds an extra layer of protection against unauthorized access.

<br>


# Recap of The Benefits of "Limit Login Attempts Reloaded"

Using the "Limit Login Attempts Reloaded" plugin offers numerous benefits that greatly enhance the security of your WordPress website. This powerful plugin effectively prevents brute force attacks by limiting the number of login attempts, thwarting malicious users or bots trying to gain unauthorized access. You can easily customize lockout settings, such as the maximum number of login attempts and lockout duration, to suit your specific security needs. Additionally, the plugin provides the option to receive email notifications whenever a user is locked out due to excessive login attempts, keeping you informed about potential threats and enabling prompt action. By whitelisting trusted IP addresses, you can ensure convenient access for authorized users or systems while maintaining stringent security measures.

Installation and setup are straightforward, and the user-friendly interface simplifies configuration. The plugin is compatible with most WordPress installations and themes, ensuring optimal performance without compromising website speed. With continuous development and regular updates, you can rest assured that your website remains protected against emerging security threats. By using the "Limit Login Attempts Reloaded" plugin, you contribute to a more secure WordPress community, making it a valuable tool for safeguarding your website and enhancing overall resilience against hacking attempts.

<br>

<br>


# Encouragement To Provide Feedback and Reviews

We encourage you to actively participate by providing feedback, suggesting new features, reporting any security issues, or writing a review of the software. Your input plays a crucial role in shaping the future of our product and ensuring that it meets your evolving needs. You can participate by adding your comments and ideas to our [roadmap](https://limitloginattempts.hellonext.co/roadmap) and then voting on the priorities.\
\
To submit feedback or a feature request, [create a post in our roadmap](https://limitloginattempts.hellonext.co/). Security issues can be sent directly to <support@limitloginattempts.com>. We encourage you to[ leave a review directly with WordPress](https://wordpress.org/plugins/limit-login-attempts-reloaded/#reviews). We greatly appreciate your time and contribution in helping us deliver a better user experience and maintain a high level of security for all our users.

<br>

<br>


