{"id":367859,"date":"2026-09-16T03:07:49","date_gmt":"2026-09-16T03:07:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/dadsfam-login-security\/"},"modified":"2026-09-28T14:57:22","modified_gmt":"2026-09-28T14:57:22","slug":"dadsfam-login-security","status":"publish","type":"plugin","link":"https:\/\/gax.wordpress.org\/plugins\/dadsfam-login-security\/","author":23486748,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.0.0","stable_tag":"2.0.0","tested":"7.1.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"DadsFam Login Security","header_author":"DadsFam","header_description":"Hardens your WordPress login against brute-force attacks, bots and username scanning. Smart lockouts, IP allow\/deny lists, a full login activity log, email alerts and built-in hardening \u2014 all free, no forced upsells.","assets_banners_color":"bbcbdf","last_updated":"2026-09-28 14:57:22","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/plugins.dadsfam.co.za\/dadsfam-login-security-free-and-pro\/","header_author_uri":"https:\/\/plugins.dadsfam.co.za\/","rating":0,"author_block_rating":0,"active_installs":20,"downloads":141,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.7.1":{"tag":"1.7.1","author":"dadsfam","date":"2026-09-16 03:07:16","revision":3697870},"2.0.0":{"tag":"2.0.0","author":"dadsfam","date":"2026-09-28 14:57:22","revision":3717419}},"upgrade_notice":{"2.0.0":"<p>Important fix: simply opening the sign-in page no longer counts as a wrong password. Adds the self-learning Brain, Autopilot, unlock by email and self-repair. Everything stays on your site.<\/p>","1.7.1":"<p>Review fixes: no DadsFam branding in the emails your users receive, and the plugin homepage link is fixed.<\/p>","1.7.0":"<p>Find any setting with the new search box, and a save bar that shows when something has changed.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3697870,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3697870,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3697870,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3697870,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.7.1","2.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3717419,"resolution":"1","location":"assets","locale":"","width":1280,"height":1600},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3717419,"resolution":"2","location":"assets","locale":"","width":1280,"height":1600},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3717419,"resolution":"3","location":"assets","locale":"","width":1280,"height":1200},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3717419,"resolution":"4","location":"assets","locale":"","width":1280,"height":800}},"screenshots":{"1":"The dashboard: whether your sign-in page is safe, in one sentence, with the Brain on duty.","2":"The Brain: what it decided and why, the clues it weighs, the Autopilot and self-repair.","3":"The activity log with the Brain's verdict on every attempt.","4":"Settings, with the Brain's switches and plain-English explanations."}},"plugin_section":[262246],"plugin_tags":[2439,9374,13868,602,600],"plugin_category":[38,54],"plugin_contributors":[274194],"plugin_business_model":[],"class_list":["post-367859","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-brute-force","plugin_tags-limit-login-attempts","plugin_tags-lockout","plugin_tags-login","plugin_tags-security","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-dadsfam","plugin_committers-dadsfam"],"banners":{"banner":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/banner-772x250.png?rev=3697870","banner_2x":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/banner-1544x500.png?rev=3697870","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/icon-128x128.png?rev=3697870","icon_2x":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/icon-256x256.png?rev=3697870","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-1.png?rev=3717419","caption":"The dashboard: whether your sign-in page is safe, in one sentence, with the Brain on duty."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-2.png?rev=3717419","caption":"The Brain: what it decided and why, the clues it weighs, the Autopilot and self-repair."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-3.png?rev=3717419","caption":"The activity log with the Brain's verdict on every attempt."},{"src":"https:\/\/ps.w.org\/dadsfam-login-security\/assets\/screenshot-4.png?rev=3717419","caption":"Settings, with the Brain's switches and plain-English explanations."}],"raw_content":"<!--section=description-->\n<p><strong>DadsFam Login Security<\/strong> protects the most-attacked part of your WordPress site \u2014 the login form \u2014 without making you read a manual or fiddle with servers.<\/p>\n\n<p>Most login plugins count wrong passwords and lock out whoever hits the number. That works on bots, and it also locks out your customer who mistyped twice on the same office connection a bot happens to be using. Version 2.0 gives the plugin its own Brain, running entirely on your site, so it can tell the two apart.<\/p>\n\n<h4>The Brain (free, and it never phones home)<\/h4>\n\n<ul>\n<li><strong>It learns your real people.<\/strong> Every correct password teaches it what a real sign-in on your site looks like. Every attempt on a username that does not exist teaches it what a bot looks like. It only learns from facts, never from its own guesses.<\/li>\n<li><strong>A browser that has signed in before is never locked out by its address.<\/strong> Its typos do not count, even on a shared connection that is being attacked. (After a generous number of misses the normal rules apply again, in case a laptop is stolen.)<\/li>\n<li><strong>Obvious bots are locked out on the first try<\/strong> \u2014 but only when it is almost certain and two hard clues agree, like a script with no browser posting straight at the form. A real browser cannot trip it.<\/li>\n<li><strong>Every attempt is explained in plain words:<\/strong> \"97% bot: posted straight at the sign-in form without opening it, no language setting.\"<\/li>\n<li><strong>Autopilot.<\/strong> During an attack it raises the shields (strangers get half the tries and a longer time-out), keeps whole attacking networks away for a day, then three, then a week \u2014 and lowers everything again once it is quiet. Networks your people use are never touched.<\/li>\n<li><strong>Unlock by email.<\/strong> A locked-out person can email themselves a one-time unlock link. It only ever goes to the account's own email address.<\/li>\n<li><strong>Self-repair.<\/strong> Every day and after every update it checks its own setup and fixes what is safe to fix \u2014 like the Cloudflare setting that lets one bot lock everybody out \u2014 then tells you what it did.<\/li>\n<li><strong>Remote control.<\/strong> On WordPress 6.9+ every action is available as a WordPress Ability, so an assistant you trust can check your login security or let someone back in.<\/li>\n<\/ul>\n\n<h4>Everything else you get (free)<\/h4>\n\n<ul>\n<li><strong>Smart lockouts<\/strong> \u2014 after too many wrong passwords an address is paused, and repeat offenders get a much longer time-out. Choose Relaxed, Balanced or Strict with one click.<\/li>\n<li><strong>Instant lockout for bot usernames<\/strong> \u2014 \"admin\", \"root\" and friends lock a bot out on the first try, unless someone on your site really uses that name.<\/li>\n<li><strong>Never lock me out<\/strong> \u2014 one click adds your own address to the allow list.<\/li>\n<li><strong>Allow and deny lists<\/strong> \u2014 single addresses, ranges and wildcards.<\/li>\n<li><strong>Activity log<\/strong> \u2014 every sign-in, wrong password, lockout and block, with the Brain's verdict, search, filters and CSV export.<\/li>\n<li><strong>Invisible bot trap and generic error messages<\/strong> \u2014 bots cannot tell whether a username exists.<\/li>\n<li><strong>Hardening<\/strong> \u2014 block username discovery, switch off XML-RPC and pingbacks.<\/li>\n<li><strong>Email alerts<\/strong> \u2014 when someone is locked out, and (optionally) when a person signs in from a browser and network they have never used.<\/li>\n<li><strong>Cloudflare and proxy support<\/strong> \u2014 reads the real visitor address, safely.<\/li>\n<li><strong>A recovery switch<\/strong> \u2014 add DFLS_DISABLE_LOCKOUTS to wp-config.php and nobody is locked out until you remove it.<\/li>\n<\/ul>\n\n<h4>Privacy<\/h4>\n\n<p>Everything the Brain knows stays in your WordPress database. Nothing is sent to DadsFam, to an AI company or to any other service \u2014 the free plugin makes no outside requests at all.<\/p>\n\n<p>It stores, per person, the browsers they have signed in with (as a random token matched by a scrambled fingerprint) and the networks they use (as one-way fingerprints that cannot be turned back into addresses). A recognised browser gets one first-party cookie, <code>dfls_tb<\/code>, which only your site can read. The activity log keeps the address, username and browser name of each attempt for 30 days by default. Uninstalling the plugin removes all of it.<\/p>\n\n<h4>Pro features (DadsFam Login Security Pro add-on)<\/h4>\n\n<p>Two-factor codes, a smart sign-in check that asks for an email code when a sign-in looks unusual to the Brain, a CAPTCHA, a hidden login address, breached-password checks, country blocking, sessions control and a full audit trail.<\/p>\n\n<h4>A word about PRO<\/h4>\n\n<p>Right, let me be straight with you, because I hate being sold to as much as you do.<\/p>\n\n<p>Everything above is free and it stays free. The lockouts, the allow and deny lists, the activity log, the live dashboard, the email alerts, the bot traps and the hardening \u2014 none of those are premium features. Those are the things a login-security plugin should just do, and if I put them behind a paywall I would be taking the mickey.<\/p>\n\n<p>There is a PRO add-on. It exists because I am a dad in Cape Town, and this is one of the things that puts food on the table at my house. That is the honest reason. Not \"unlock your potential\", not \"supercharge your workflow\". Just: if this plugin kept the bots off your login page and you can spare it, PRO helps me keep building.<\/p>\n\n<p>What PRO adds is the second layer you reach for once the door is already locked \u2014 two-factor codes, a CAPTCHA, a hidden login address, breached-password checks, country blocking. That is extra security and convenience. It is not the plugin working properly, because the plugin already works properly.<\/p>\n\n<p>So if the free one does everything you need, brilliant. Genuinely. Use it, and I hope your activity log stays boring. If you get to the point where a second factor or a hidden login would let you sleep better, PRO is at plugins.dadsfam.co.za.<\/p>\n\n<p>Either way, thanks for using something I built. \u2014 Zak, DadsFam<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin through <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>, or search for \"DadsFam Login Security\".<\/li>\n<li>Activate it. Protection starts straight away with safe defaults, and the Brain starts learning from your next sign-in (it also reads your existing activity log if you are updating).<\/li>\n<li>Open <strong>Login Security<\/strong> in the admin menu and click <strong>Never lock me out<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20brain%20send%20my%20data%20to%20an%20ai%20company%3F\"><h3>Does the Brain send my data to an AI company?<\/h3><\/dt>\n<dd><p>No. It is not a connection to ChatGPT, Claude or anything else. It is a small learning engine written into the plugin, and it runs on your own server. Nothing leaves your site.<\/p><\/dd>\n<dt id=\"will%20this%20lock%20me%20out%20of%20my%20own%20site%3F\"><h3>Will this lock me out of my own site?<\/h3><\/dt>\n<dd><p>It is built not to. Add yourself to the allow list with the <strong>Never lock me out<\/strong> button, and once you have signed in once your browser is recognised and cannot be locked out by its address. If you are ever stuck, use the \"Email me an unlock link\" link on the lockout message, or add <code>define( 'DFLS_DISABLE_LOCKOUTS', true );<\/code> to wp-config.php, sign in, and remove the line again.<\/p><\/dd>\n<dt id=\"can%20the%20brain%20lock%20out%20a%20real%20person%20by%20mistake%3F\"><h3>Can the Brain lock out a real person by mistake?<\/h3><\/dt>\n<dd><p>It is designed so it cannot. It only acts alone when it is almost certain and at least two hard clues agree \u2014 things a real browser in a person's hands does not do, like having no browser name at all. Recognised browsers and the networks your people use are excluded from that entirely.<\/p><\/dd>\n<dt id=\"does%20it%20work%20behind%20cloudflare%20or%20a%20load%20balancer%3F\"><h3>Does it work behind Cloudflare or a load balancer?<\/h3><\/dt>\n<dd><p>Yes. Choose <strong>Cloudflare<\/strong> or <strong>Another proxy or load balancer<\/strong> under Settings \u2192 Where visitors' addresses come from, and it reads the real visitor address \u2014 only when the request really came through your proxy, so the header cannot be faked. Self-repair switches Cloudflare on for you when it detects Cloudflare.<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20woocommerce%20login%20forms%3F\"><h3>Is it compatible with WooCommerce login forms?<\/h3><\/dt>\n<dd><p>Yes. The shop's account page is protected the same way as wp-login.php.<\/p><\/dd>\n<dt id=\"will%20disabling%20xml-rpc%20break%20anything%3F\"><h3>Will disabling XML-RPC break anything?<\/h3><\/dt>\n<dd><p>Only apps that still use XML-RPC, such as the old WordPress mobile app or some remote publishing tools. It is off by default.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>New: the Brain. The plugin learns, on your site only, who your real people are and how bots behave, and explains every attempt in plain words.<\/li>\n<li>New: browsers that have signed in before are never locked out by their address, and their typos do not count.<\/li>\n<li>New: obvious bots are locked out on the first try when the Brain is almost certain and two hard clues agree.<\/li>\n<li>New: Autopilot raises the shields during attacks and blocks attacking networks for a while, never your people's networks.<\/li>\n<li>New: unlock by email, self-repair, smarter new-sign-in alerts, WordPress Abilities, and Support and What's new tabs.<\/li>\n<li>Fix: opening the sign-in page was counted as a wrong password (with \"Don't say which part was wrong\" on, the default), which could lock real people out. Fixed, the false records are removed on update, and anyone who had signed in successfully before is let back in.<\/li>\n<\/ul>\n\n<h4>1.7.1<\/h4>\n\n<ul>\n<li>Removed the small \"Powered by DadsFam\" line from the bottom of the lockout and new-login emails. Those emails go to your users, and nothing of ours belongs in them unless you have asked for it.<\/li>\n<li>Corrected the plugin's homepage link in its header, which pointed at a page that no longer exists.<\/li>\n<\/ul>\n\n<h4>1.7.0<\/h4>\n\n<ul>\n<li>New: find any setting. A search box above the Settings cards filters every switch and field by a word in its label or description, opens the \"actual numbers\" section when a match is inside it, and says plainly when nothing matches.<\/li>\n<li>New: the save bar tells you. It lights up the moment something on the page changes and the browser warns before you leave with unsaved changes.<\/li>\n<li>Readme: added the standing \"A word about PRO\" note \u2014 what stays free, why the optional add-on exists, and what it actually adds \u2014 and the line that nothing in the free plugin is disabled, blurred out, time-limited or reduced. Tested up to WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.6.1<\/h4>\n\n<ul>\n<li>Fixed: cleared every WordPress.org Plugin Check violation \u2014 six request values read without sanitising, a discouraged text-domain call, and a set of table-name and nonce false positives now carry the justification the checker needs. Zero violations.<\/li>\n<li>Fixed: a CAPTCHA refusal raised by another plugin was counted as a failed password. A visitor turned away by a bot check a few times was then locked out here as well \u2014 two plugins compounding one problem. Any error whose code mentions a CAPTCHA is now ignored when counting failed attempts, whichever plugin raised it. Wrong passwords still count exactly as before.<\/li>\n<\/ul>\n\n<h4>1.6.0<\/h4>\n\n<ul>\n<li>New: the whole admin screen has been rebuilt in the DadsFam house style \u2014 one calm, tabbed screen (Dashboard \u00b7 Activity \u00b7 Settings) that leads with what is true right now and what to do about it, in plain English. Protection status at a glance, a \u201cfinish locking things down\u201d checklist that disappears once you're done, big tap-tiles, and an \u201cif something goes wrong\u201d panel with the fix written right there.<\/li>\n<li>New: \u201cNever lock me out\u201d \u2014 one click puts your own address on the allow list, from the dashboard or the checklist.<\/li>\n<li>New: instant lockout for bot usernames. Anyone trying \u201cadmin\u201d, \u201croot\u201d, \u201ctest\u201d and friends when no such account exists is a bot; they're locked out on the first try instead of the fifth. Real accounts with those names are never affected. The list is editable.<\/li>\n<li>New: protection levels. Pick Relaxed, Balanced (recommended) or Strict instead of juggling five numbers \u2014 the numbers are still there for people who want them.<\/li>\n<li>New: Cloudflare and proxy support. Behind Cloudflare, every visitor used to look like the same address, so one bot could lock out your whole site. Choose \u201cCloudflare\u201d or \u201cAnother proxy\u201d under Settings \u2192 Where visitors' addresses come from; forwarded headers are only ever trusted when the request genuinely came from the proxy, so nobody can fake their address. The dashboard warns you if it spots Cloudflare and the setting is still on \u201cplain hosting\u201d.<\/li>\n<li>New: a recovery valve for the free plugin. Add <code>define( 'DFLS_DISABLE_LOCKOUTS', true );<\/code> to wp-config.php and every lockout is switched off until you remove it. The dashboard shows a red warning while it is in place.<\/li>\n<li>New: \u201cLet everyone back in\u201d clears every active lockout at once; \u201cBlock for good\u201d on any row moves an address to the deny list.<\/li>\n<li>New: the activity log shows \u201cChrome on Windows\u201d instead of a 200-character user agent, filters with pills, and lets you block an attacker straight from the row.<\/li>\n<li>Improved: locked-out addresses hammering a real account no longer cost a password-hash check per attempt \u2014 the lockout is now applied before the (deliberately slow) password comparison.<\/li>\n<li>Improved: dashboard statistics come from one query instead of five, and are memoised per request.<\/li>\n<li>Improved: the live dashboard pauses when the tab is hidden and refreshes the moment you come back.<\/li>\n<li>Changed: minimum WordPress version is now 6.0. Tested up to 7.0.<\/li>\n<\/ul>\n\n<p>Older versions are listed in changelog.txt.<\/p>","raw_excerpt":"Stops brute-force attacks with its own self-learning Brain that knows your real people, locks bots out fast and fixes its own setup.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/367859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=367859"}],"author":[{"embeddable":true,"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dadsfam"}],"wp:attachment":[{"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=367859"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=367859"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=367859"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=367859"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=367859"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/gax.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=367859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}