BetterShield
Login protectionLockoutsSign-in

Limit login attempts in WordPress without locking yourself out

BetterShield team · · 9 min read

Out of the box, WordPress lets anyone keep trying passwords at your sign-in form for as long as they like, and a script can keep going far longer than any person would. The usual answer is to limit login attempts in WordPress: after a few wrong passwords, stop listening for a while.

Done carelessly, that limit can lock the real owner out or, behind a proxy, put every visitor under one lockout. BetterShield pauses the connection that keeps failing, never the account, acts only on addresses it can verify, and leaves you a way back in. It starts at activation, so on most sites the job is checking it, not building it.

Quick summary

  • By default, 5 wrong passwords in 15 minutes pause sign-in from that connection for 15 minutes, doubling for each repeat within a day, up to a day.
  • The account is never locked. When the attempts named a real account, its owner is emailed an unlock link.
  • Only a verified address is ever locked out. Behind a proxy, name it under Trusted proxies; Cloudflare needs no entry.
  • Comments, password resets and sign-ups have their own limits, counted apart from sign-in.
  • Keep your recovery link and printed codes off the site, and put fixed office addresses on Always allowed.

Why repeated wrong passwords are a problem

Guessing passwords is cheap: without a limit, nothing makes the hundredth guess slower than the first. A strong password is still what keeps people out; a limit adds to it by making each round of guesses wait. That is the core of WordPress brute force protection.

You can lock the account after a few failures, or pause the connection the failures came from. Locking the account sounds stricter, but it lets anyone who knows your username keep you out of your own site. BetterShield pauses the connection, so the account keeps working from everywhere else.

What a sensible limit looks like

  • Room for honest typos. People mistype, and password managers fill in old passwords. Failures allowed cannot go below 3, because below three, a mistyped password becomes a lockout.
  • A short window and a short pause. The default counts 5 failures within 15 minutes, then pauses for 15 minutes, so someone who mistyped waits a quarter of an hour at most.
  • Longer pauses for whoever keeps coming back. With the defaults, a repeat within a day waits 30 minutes, then an hour, then two, up to a full day.
  • A way out for the real owner. Every pause ends on its own, and the owner can end it sooner from an email.

How to limit login attempts in WordPress with BetterShield

  1. Open BetterShield › Protect › Login & Access.
  2. Look at Connections in the summary at the top. Verified means lockouts can run. Not verified means they are paused; see the proxy section below.
  3. Under Sign-in protection, check that Pause sign-in after repeated failures is on.
  4. Adjust Failures allowed (3 to 100), Counted within (minutes) and Pause lasts (minutes) (both 1 to 1440) if you need to.
  5. Press Save in the bar that appears, or Discard to drop your edits.

What a WordPress login lockout looks like here

  • The sign-in form tells that connection there have been too many failed sign-ins and asks it to wait.
  • The pause appears under Lockouts, listed by network (such as 203.0.113.0/24), running ones first. Release now ends one early.
  • If the attempts named a real account, its owner receives “[site name] Sign-in temporarily locked”, whose link leads to Clear the lockout. A pause released either way starts the doubling over.
  • Wrong two-factor codes and wrong application passwords count toward the limit too.

The hidden bot check

Refuse obviously automated submissions is on by default. It adds an invisible field and a clock to the sign-in, registration, comment and store account forms, and refuses a script that fills in every field or submits within two seconds. People see nothing. By the screen’s own account, it cuts bot noise rather than stopping a determined person.

A small puzzle after failed sign-ins

Slow down repeated failed sign-ins is off by default. After two wrong passwords from one connection, the next attempt pauses for a moment while the browser solves a small puzzle, a little harder after each further failure. It needs JavaScript, and HTTPS or localhost. An unsolved puzzle never counts toward a lockout, the puzzle lifts once the counting window passes, and addresses on Always allowed never see it.

A notice for sign-ins from a new network

Tell an account holder about a sign-in from a new network is off by default. When on, the person whose account it is (not your alert list) is emailed the first time the account signs in from a new network, at most once a day. Nothing is blocked.

Proxies and Cloudflare: telling visitors apart

A limit only works if the site can tell who is signing in. Behind a reverse proxy, a load balancer or a CDN, every request can arrive from the proxy’s address. Counting that address would put every visitor under one lockout, you included; believing any forwarding header would let anyone choose the address they appear to come from.

So only a verified address is ever locked out; anything else is recorded, never locked. An unnamed proxy turns lockouts off rather than locking everyone behind it, and Findings shows “Sign-in lockouts are not running” until it is fixed.

How this site sees you, under Who is at the door, reads your own request and stores nothing. It says either that automatic lockouts are active or why they are not running yet. Press Check again after any change.

  • Cloudflare is recognized by its published address ranges and needs no entry under Trusted proxies. If the screen asks, press Yes, this site is behind Cloudflare so each lockout follows the visitor; until then, a lockout counts the Cloudflare address and the visitor’s together. Turn that off withdraws that trust.
  • Another proxy goes under Trusted proxies, in One address or range per comma. The visitor address it forwards in its X-Forwarded-For header is then believed. If it is named and lockouts still are not running, set it to send that header.

Allow and block lists

Both lists are under Allowed and refused.

  • Always allowed holds addresses that are never locked out, never held by form limits and never given the puzzle. Addresses only, because a user agent is a claim anyone can make. An office or agency on fixed addresses puts them here.
  • Never allowed to sign in refuses sign-in, never browsing. An entry is an IP address or CIDR range, a username or a user-agent fragment of four characters or more, with an optional Note.

A username on its own is refused from anywhere, even an allowed address, with the answer a wrong password gets. A range applies only to verified connections, and your own username cannot be added.

Public forms have their own limits

Under Request protection, comments, password reset requests and sign-ups are counted separately from sign-ins, so a busy form never locks you out of your dashboard. Each has Allowed before it closes (3 to 100), Counted within (minutes) and Closed for (minutes).

OptionPast the limitDefault
Hold a burst of comments for moderationFurther comments wait in moderation. Nothing is discarded; moderators are never held.On: 10 in 10 minutes, closed 30 minutes
Slow repeated password reset requestsFurther requests get the answer a successful one gets, so no account is revealed.On: 8 in 15 minutes, closed 15 minutes
Slow repeated sign-upsFurther sign-ups are refused until later. Only where registration is open.On: 8 in 1 hour, closed 1 hour

Before you save, new numbers are replayed against the last two days of attempts, so you see what they would have held or refused.

How to avoid locking yourself out

  1. Keep your way back in off the site. The recovery link emailed at activation works once, lasts 90 days, and turns on safe mode for an hour, which pauses everything on Login & Access. On Protect › Recovery, Issue recovery codes gives you eight printed codes for the day email fails.
  2. Allow your own fixed addresses. If your office address does not change, add it to Always allowed.
  3. Check a range before you block it. A blocked range that includes your own network refuses you too.

If it happens anyway, Locked out of WordPress? covers every way back in.

Common mistakes

  • Assuming lockouts run behind a proxy. If Connections reads Not verified, name the proxy under Trusted proxies first.
  • Two plugins limiting sign-in. Quick Setup asks which plugin keeps Login attempt limits, because two limits lock a person out twice. If you later remove the other one, Findings shows “Nothing is limiting sign-in attempts” until you switch Pause sign-in after repeated failures back on.
  • Caching the sign-in page. A cached copy can show one visitor’s lockout answer to the next. If Findings shows “The sign-in page is served from a page cache”, exclude the sign-in address from caching.

Frequently asked questions

How many login attempts should WordPress allow?

BetterShield’s default is 5 wrong passwords within 15 minutes, then a 15-minute pause that doubles for a connection paused again within a day. You can allow 3 to 100; below three, a mistyped password becomes a lockout.

I see too many failed login attempts. What now?

Your connection has reached the limit. Wait for the pause to end (15 minutes by default), or open the unlock link sent to your account’s email address and press Clear the lockout. Another administrator can also press Release now.

Does login protection work behind Cloudflare?

Yes. Cloudflare is recognized by its published ranges and needs no Trusted proxies entry. When How this site sees you asks, press Yes, this site is behind Cloudflare so each lockout follows the visitor.

Is BetterShield’s brute-force protection free?

Yes. Everything in this guide is in the free BetterShield plugin on WordPress.org, with no account needed.

Conclusion

To limit login attempts in WordPress well, pause the connection rather than the account, make sure the site can tell visitors apart, and keep your own way back in. BetterShield starts with sensible numbers, so on most sites the one thing to confirm is that Connections reads Verified.

Then save your recovery link somewhere off the site. The full reference is the Login & Access guide.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield