login lockdown plugin. WordPress Login LockDown Security Plugin – Hack Protection

Good afternoon, dear readers! Today we will increase security in wordpress. WordPress is already well protected, but additional security will not hurt us.

First, let's close access to unnecessary files. Type in the browser address, for example, your_blog/wp-content and if you see a white screen, then everything is fine:

If you have a list of files, then you need to do the following (even if there is a white screen, it is better to do the following):

Security in WordPress with the Login LockDown Plugin

Also, your blog can be hacked by guessing your blog password. If you set a very light password, then hackers can easily “penetrate” your blog using special scripts.

Configuring the Login LockDown Security Plugin

To get to the plugin settings, you need to go to WordPress Admin –> Settings –> Login LockDown:

1. Max Login Retries– maximum number of password attempts.

2. Retry Time Period Restriction (minutes)– the number of minutes for which the maximum number of password attempts is counted.

3. Lockout Length (minutes) blocking time.

That is, if the numbers remain the same as in the picture above, then this means the following: if in 5 minutes the password is entered incorrectly 3 times in a row, then the WordPress admin area is blocked for 60 minutes.

I left the Login LockDown plugin settings by default, did not touch anything, since they completely suit me.

Perhaps, for today, everything is about security in WordPress (Wordpress). See you in the next lessons!

Hello, dear readers of the blog site! Topic of today's article: protecting your WordPress blog from hacking by selecting a password to enter the admin panel. This method is called . This problem is very relevant, since cases of unauthorized access to the holy of holies of the blog, namely the WordPress control panel, unfortunately, are not at all rare.

In general, the WordPress security topic is very extensive and is not limited only to the ones that I already wrote about earlier. Much more unfortunate consequences (I don’t even want to imagine) can occur if attackers gain access to the blog admin panel. Our task is to do everything possible to prevent this from happening. And today I will talk about only one of the ways to strengthen the protection of the blog. Meet the WordPress Security Plugin Login LockDown.

Protecting the WordPress Admin from Hacking with the Login LockDown Plugin

The easiest way to hack a site is to pick up a username and password to enter the control panel. I must say that many bloggers themselves make it 50% easier for a hacker, leaving the default login. And then it remains only to guess the password.

Have you changed your username or do you still have the name admin? If not, then do it immediately. My article ““ may help you with this.

Be sure, immediately after installing the engine, change the password to a more secure one (we make about 20 characters using upper and lower case letters, numbers and special characters). This can be done directly from the admin panel by going to the menu “Users" - "Your profile". Enter the new password twice and save the changes by clicking the “ Update Profile“. Change your password periodically and do not use it on other sites.

With such simple actions, we will already complicate the task for crackers. But, let's say they turned out to be stubborn and do not leave attempts, using special programs for guessing a password. This is where the WordPress Login LockDown security plugin comes to the rescue.

How the Login LockDown Plugin Works

The plugin captures the exact time and IP address from which an unsuccessful login attempt was made to the blog admin. When a certain number of unsuccessful attempts are made within a certain period of time, the plugin blocks access to the site for a specified time. A message is displayed:

“Error: Sorry, but this IP range has been blocked due to too many failed login attempts. Please try again later.”

In addition, you will have a list of all blocked IP addresses and the ability to unblock them in the plugin settings. Let's consider them in more detail.

Installing and configuring the Login LockDown security plugin

Install and activate the plugin. I described in detail the installation of this plugin, as an example, in the article ““. Therefore, without further ado, let's move on to the settings.

Go to the menu “ Options" - " Login LockDown".

The illustration shows the default settings. You can change them to your liking. Below I will describe what each of the points means and give my comments:

  • 1. Max Login Retries- the maximum number of attempts to enter the blog admin panel. I don't think it makes sense to put more than three.
  • 2. Retry Time Period Restriction (minutes)– time period in minutes to retry. Five minutes is enough to even run to the Canadian border, let alone enter the password.
  • 3. Lockout Length (minutes)- time in minutes for which access to the WordPress admin panel is blocked. You can leave 60 minutes, or you can set more.
  • 4. Lockout Invalid Usernames– take into account incorrect login input? We mark this item and the plugin, in addition to the password, will also take into account the incorrectly written name. Extra protection of the blog is never superfluous.
  • 5. Mask Login Errors– masking errors of entering incorrect data. We note, and then the cracker will not know that his actions are under control (something did not notice any difference).
  • 6. Currently Locked Out- here you can see a list of currently blocked IP addresses and the time until unblocking. More on this below.

After the Login LockDown security plugin has been configured, click the “Update Settings“ button for the changes to take effect.

For clarity, I will decipher what happens when you try to hack a blog if the settings are, for example, by default, as in the figure above. If the password is entered incorrectly more than 3 times with an interval of 5 minutes, then access to the admin panel is blocked for 60 minutes.

Now back to the list of IP addresses. I don't know when this might be needed, but you have the ability to unblock an IP address that has fallen out of favor. To do this, check this item and click "Release Selected". This probably makes sense if you are not the only one with access to the blog. For example, several authors or a freelancer needs to tweak something.

One more detail. If you notice, then in the first screenshot you can see that a warning about protection by the Login LockDown plugin is displayed under the login form in the admin panel. It should appear if you installed the plugin correctly and it works. But in this case, the meaning of paragraph 5 is lost, because the attacker will be warned about the protection in advance. Let's remove this label.

Go to the menu " Plugins"-" Editor". Select our security plugin from the drop-down list at the top right and click “Select“. Finding in a file login-lockdown/loginlockdown.php this line (see the picture below) and remove everything between the quotes. Click "Update file" and go to the login page. The inscription should disappear.

Pay attention to the warning on the edit page. Before making any changes, deactivate the plugin and then re-enable it. I hope that before any editing of files, it is necessary to make copies of them, there is no need to remind.

Now WordPress Login LockDown security plugin will not allow an attacker to get into the admin panel by guessing a password. Of course, this does not guarantee 100% WordPress protection from hacks and other troubles. But every type of blog protection will build a wall in front of the enemy brick by brick. The higher this wall, the more peacefully you will sleep at night.

You need to remember well that you need to pay attention to blog security issues no less than writing unique content and promotion in search engines. In future articles, I will return to this topic more than once. Subscribe to blog updates to always be in the know. See you soon!

