Skip to content
WordPress.org

Afaan Oromoo

  • Themes
  • Plugins
  • About
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

DadsFam Login Security

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

DadsFam Login Security

By dadsfam
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

DadsFam Login Security protects the most-attacked part of your WordPress site — the login form — without making you read a manual or fiddle with servers.

Most login plugins count wrong passwords and lock out whoever hits the number. That works on bots, and it also locks out your customer who mistyped twice on the same office connection a bot happens to be using. Version 2.0 gives the plugin its own Brain, running entirely on your site, so it can tell the two apart.

The Brain (free, and it never phones home)

  • It learns your real people. Every correct password teaches it what a real sign-in on your site looks like. Every attempt on a username that does not exist teaches it what a bot looks like. It only learns from facts, never from its own guesses.
  • A browser that has signed in before is never locked out by its address. Its typos do not count, even on a shared connection that is being attacked. (After a generous number of misses the normal rules apply again, in case a laptop is stolen.)
  • Obvious bots are locked out on the first try — but only when it is almost certain and two hard clues agree, like a script with no browser posting straight at the form. A real browser cannot trip it.
  • Every attempt is explained in plain words: “97% bot: posted straight at the sign-in form without opening it, no language setting.”
  • Autopilot. During an attack it raises the shields (strangers get half the tries and a longer time-out), keeps whole attacking networks away for a day, then three, then a week — and lowers everything again once it is quiet. Networks your people use are never touched.
  • Unlock by email. A locked-out person can email themselves a one-time unlock link. It only ever goes to the account’s own email address.
  • Self-repair. Every day and after every update it checks its own setup and fixes what is safe to fix — like the Cloudflare setting that lets one bot lock everybody out — then tells you what it did.
  • Remote control. On WordPress 6.9+ every action is available as a WordPress Ability, so an assistant you trust can check your login security or let someone back in.

Everything else you get (free)

  • Smart lockouts — after too many wrong passwords an address is paused, and repeat offenders get a much longer time-out. Choose Relaxed, Balanced or Strict with one click.
  • Instant lockout for bot usernames — “admin”, “root” and friends lock a bot out on the first try, unless someone on your site really uses that name.
  • Never lock me out — one click adds your own address to the allow list.
  • Allow and deny lists — single addresses, ranges and wildcards.
  • Activity log — every sign-in, wrong password, lockout and block, with the Brain’s verdict, search, filters and CSV export.
  • Invisible bot trap and generic error messages — bots cannot tell whether a username exists.
  • Hardening — block username discovery, switch off XML-RPC and pingbacks.
  • Email alerts — when someone is locked out, and (optionally) when a person signs in from a browser and network they have never used.
  • Cloudflare and proxy support — reads the real visitor address, safely.
  • A recovery switch — add DFLS_DISABLE_LOCKOUTS to wp-config.php and nobody is locked out until you remove it.

Privacy

Everything the Brain knows stays in your WordPress database. Nothing is sent to DadsFam, to an AI company or to any other service — the free plugin makes no outside requests at all.

It stores, per person, the browsers they have signed in with (as a random token matched by a scrambled fingerprint) and the networks they use (as one-way fingerprints that cannot be turned back into addresses). A recognised browser gets one first-party cookie, dfls_tb, which only your site can read. The activity log keeps the address, username and browser name of each attempt for 30 days by default. Uninstalling the plugin removes all of it.

Pro features (DadsFam Login Security Pro add-on)

Two-factor codes, a smart sign-in check that asks for an email code when a sign-in looks unusual to the Brain, a CAPTCHA, a hidden login address, breached-password checks, country blocking, sessions control and a full audit trail.

A word about PRO

Right, let me be straight with you, because I hate being sold to as much as you do.

Everything above is free and it stays free. The lockouts, the allow and deny lists, the activity log, the live dashboard, the email alerts, the bot traps and the hardening — none of those are premium features. Those are the things a login-security plugin should just do, and if I put them behind a paywall I would be taking the mickey.

There is a PRO add-on. It exists because I am a dad in Cape Town, and this is one of the things that puts food on the table at my house. That is the honest reason. Not “unlock your potential”, not “supercharge your workflow”. Just: if this plugin kept the bots off your login page and you can spare it, PRO helps me keep building.

What PRO adds is the second layer you reach for once the door is already locked — two-factor codes, a CAPTCHA, a hidden login address, breached-password checks, country blocking. That is extra security and convenience. It is not the plugin working properly, because the plugin already works properly.

So if the free one does everything you need, brilliant. Genuinely. Use it, and I hope your activity log stays boring. If you get to the point where a second factor or a hidden login would let you sleep better, PRO is at plugins.dadsfam.co.za.

Either way, thanks for using something I built. — Zak, DadsFam

Screenshots

The dashboard: whether your sign-in page is safe, in one sentence, with the Brain on duty.
The dashboard: whether your sign-in page is safe, in one sentence, with the Brain on duty.
The Brain: what it decided and why, the clues it weighs, the Autopilot and self-repair.
The Brain: what it decided and why, the clues it weighs, the Autopilot and self-repair.
The activity log with the Brain's verdict on every attempt.
The activity log with the Brain’s verdict on every attempt.
Settings, with the Brain's switches and plain-English explanations.
Settings, with the Brain’s switches and plain-English explanations.

Installation

  1. Upload the plugin through Plugins → Add New → Upload Plugin, or search for “DadsFam Login Security”.
  2. Activate it. Protection starts straight away with safe defaults, and the Brain starts learning from your next sign-in (it also reads your existing activity log if you are updating).
  3. Open Login Security in the admin menu and click Never lock me out.

FAQ

Does the Brain send my data to an AI company?

No. It is not a connection to ChatGPT, Claude or anything else. It is a small learning engine written into the plugin, and it runs on your own server. Nothing leaves your site.

Will this lock me out of my own site?

It is built not to. Add yourself to the allow list with the Never lock me out button, and once you have signed in once your browser is recognised and cannot be locked out by its address. If you are ever stuck, use the “Email me an unlock link” link on the lockout message, or add define( 'DFLS_DISABLE_LOCKOUTS', true ); to wp-config.php, sign in, and remove the line again.

Can the Brain lock out a real person by mistake?

It is designed so it cannot. It only acts alone when it is almost certain and at least two hard clues agree — things a real browser in a person’s hands does not do, like having no browser name at all. Recognised browsers and the networks your people use are excluded from that entirely.

Does it work behind Cloudflare or a load balancer?

Yes. Choose Cloudflare or Another proxy or load balancer under Settings → Where visitors’ addresses come from, and it reads the real visitor address — only when the request really came through your proxy, so the header cannot be faked. Self-repair switches Cloudflare on for you when it detects Cloudflare.

Is it compatible with WooCommerce login forms?

Yes. The shop’s account page is protected the same way as wp-login.php.

Will disabling XML-RPC break anything?

Only apps that still use XML-RPC, such as the old WordPress mobile app or some remote publishing tools. It is off by default.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“DadsFam Login Security” is open source software. The following people have contributed to this plugin.

Contributors
  • dadsfam

Translate “DadsFam Login Security” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

2.0.0

  • New: the Brain. The plugin learns, on your site only, who your real people are and how bots behave, and explains every attempt in plain words.
  • New: browsers that have signed in before are never locked out by their address, and their typos do not count.
  • New: obvious bots are locked out on the first try when the Brain is almost certain and two hard clues agree.
  • New: Autopilot raises the shields during attacks and blocks attacking networks for a while, never your people’s networks.
  • New: unlock by email, self-repair, smarter new-sign-in alerts, WordPress Abilities, and Support and What’s new tabs.
  • Fix: opening the sign-in page was counted as a wrong password (with “Don’t say which part was wrong” on, the default), which could lock real people out. Fixed, the false records are removed on update, and anyone who had signed in successfully before is let back in.

1.7.1

  • Removed the small “Powered by DadsFam” line from the bottom of the lockout and new-login emails. Those emails go to your users, and nothing of ours belongs in them unless you have asked for it.
  • Corrected the plugin’s homepage link in its header, which pointed at a page that no longer exists.

1.7.0

  • New: find any setting. A search box above the Settings cards filters every switch and field by a word in its label or description, opens the “actual numbers” section when a match is inside it, and says plainly when nothing matches.
  • New: the save bar tells you. It lights up the moment something on the page changes and the browser warns before you leave with unsaved changes.
  • Readme: added the standing “A word about PRO” note — what stays free, why the optional add-on exists, and what it actually adds — and the line that nothing in the free plugin is disabled, blurred out, time-limited or reduced. Tested up to WordPress 7.1.

1.6.1

  • Fixed: cleared every WordPress.org Plugin Check violation — six request values read without sanitising, a discouraged text-domain call, and a set of table-name and nonce false positives now carry the justification the checker needs. Zero violations.
  • Fixed: a CAPTCHA refusal raised by another plugin was counted as a failed password. A visitor turned away by a bot check a few times was then locked out here as well — two plugins compounding one problem. Any error whose code mentions a CAPTCHA is now ignored when counting failed attempts, whichever plugin raised it. Wrong passwords still count exactly as before.

1.6.0

  • New: the whole admin screen has been rebuilt in the DadsFam house style — one calm, tabbed screen (Dashboard · Activity · Settings) that leads with what is true right now and what to do about it, in plain English. Protection status at a glance, a “finish locking things down” checklist that disappears once you’re done, big tap-tiles, and an “if something goes wrong” panel with the fix written right there.
  • New: “Never lock me out” — one click puts your own address on the allow list, from the dashboard or the checklist.
  • New: instant lockout for bot usernames. Anyone trying “admin”, “root”, “test” and friends when no such account exists is a bot; they’re locked out on the first try instead of the fifth. Real accounts with those names are never affected. The list is editable.
  • New: protection levels. Pick Relaxed, Balanced (recommended) or Strict instead of juggling five numbers — the numbers are still there for people who want them.
  • New: Cloudflare and proxy support. Behind Cloudflare, every visitor used to look like the same address, so one bot could lock out your whole site. Choose “Cloudflare” or “Another proxy” under Settings → Where visitors’ addresses come from; forwarded headers are only ever trusted when the request genuinely came from the proxy, so nobody can fake their address. The dashboard warns you if it spots Cloudflare and the setting is still on “plain hosting”.
  • New: a recovery valve for the free plugin. Add define( 'DFLS_DISABLE_LOCKOUTS', true ); to wp-config.php and every lockout is switched off until you remove it. The dashboard shows a red warning while it is in place.
  • New: “Let everyone back in” clears every active lockout at once; “Block for good” on any row moves an address to the deny list.
  • New: the activity log shows “Chrome on Windows” instead of a 200-character user agent, filters with pills, and lets you block an attacker straight from the row.
  • Improved: locked-out addresses hammering a real account no longer cost a password-hash check per attempt — the lockout is now applied before the (deliberately slow) password comparison.
  • Improved: dashboard statistics come from one query instead of five, and are memoised per request.
  • Improved: the live dashboard pauses when the tab is hidden and refreshes the moment you come back.
  • Changed: minimum WordPress version is now 6.0. Tested up to 7.0.

Older versions are listed in changelog.txt.

Meta

  • Version 2.0.0
  • Last updated 13 hours ago
  • Active installations 20+
  • WordPress version 6.0 or higher
  • Tested up to 7.1.2
  • PHP version 7.4 or higher
  • Language
    English (US)
  • Tags
    Brute Forcelimit login attemptslockoutloginsecurity
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • dadsfam

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Support
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Afaan Oromoo

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry.
The WordPress® trademark is the intellectual property of the WordPress Foundation.