BetterShield

Set up sign-in protection on Login & Access

5 min read

Set BetterShield’s login attempt limits, hidden bot check, public form limits, allow and block lists, trusted proxies and session limits.

Login & Access controls who may try to sign in, how often, and how long sessions last. It is on BetterShield › Protect › Login & Access. Edits wait in a bar with Save and Discard.

How this site sees you, and lockouts

How this site sees you reads your own request (nothing is stored) and says whether visitors can be told apart.

  • If lockouts are not running, it says why. Usually the fix is naming your proxy under Trusted proxies.
  • If your request came through Cloudflare unannounced, press Yes, this site is behind Cloudflare. Turn that off withdraws that trust.

Lockouts lists recent pauses from sign-in and the public forms, running ones first, by network (such as 203.0.113.0/24). Release now ends a running one.

Note: Only a verified address is ever locked out. Others are recorded, never locked.

Sign-in protection

OptionWhat it doesWhy it mattersDefault
Pause sign-in after repeated failuresAfter Failures allowed (3 to 100) wrong passwords from one connection within Counted within (minutes), sign-in from it pauses for Pause lasts (minutes) (both 1 to 1440).Stops brute-force password guessing without locking the account.On: 5 in 15 minutes, paused 15 minutes
Refuse obviously automated submissionsThe hidden bot check: an invisible field and a clock on the sign-in, registration, comment and store account forms. Refuses scripts that fill every field or submit within two seconds.Cuts bot noise; people see nothing.On
Slow down repeated failed sign-insAfter two wrong passwords from one connection, the browser solves a small puzzle before the next try. Needs JavaScript, and HTTPS or localhost.Guessing below the limit costs time; an unsolved puzzle never counts.Off
Tell an account holder about a sign-in from a new networkEmails the account’s own address the first time it signs in from a new network, at most once a day. Blocks nothing.The person who knows is told.Off

A connection paused again within a day is paused twice as long each time, up to a day; releasing one resets the doubling. Wrong two-factor codes and wrong application passwords also count. If the attempts named a real account, its owner is emailed an unlock link (see Locked out).

On multisite, each site keeps its own counts, lockouts and lists.

Signing in

Six sign-in fixes, all off by default, described in Hardening.

  • Change the sign-in address: moves sign-in to an address you choose.
  • Refuse application passwords: for site managers, or everyone.
  • Refuse passwords found in known breaches: checks new passwords against Pwned Passwords.
  • Keep low-privilege accounts out of the dashboard: sends a chosen role from wp-admin to the front page.
  • Hide the dashboard from visitors: signed-out visitors get a 404 at /wp-admin/.
  • Strengthen and rotate the sign-in keys: adds a secret to session keys.

Request protection

Counted apart from sign-ins, so a form never locks you out of your dashboard. Each form has Allowed before it closes (3 to 100), Counted within (minutes) and Closed for (minutes) (both 1 to 1440).

OptionPast the limitDefault
Hold a burst of comments for moderationFurther comments from that connection wait in moderation. Nothing is discarded; moderators are never held.On: 10 in 10 minutes, closed 30 minutes
Slow repeated password reset requestsFurther requests get the answer a successful one gets, so no account is revealed. Accounts are never affected.On: 8 in 15 minutes, closed 15 minutes
Slow repeated sign-upsFurther sign-ups are refused until later. Only where registration is open.On: 8 in 1 hour, closed 1 hour

Before you save, new numbers are replayed against the last two days of attempts.

Allowed and refused

ListWhat it doesDefault
Always allowedAddresses never locked out, held by form limits or given the puzzle. Addresses only.Empty
Never allowed to sign inRefuses sign-in, never browsing. Each entry names an address or range, a username, a user-agent fragment, or a mix, with an optional note.Empty
Trusted proxiesOne address or range per comma for a reverse proxy in front of the site, so the visitor address it forwards (X-Forwarded-For) is believed. Cloudflare needs no entry.Empty

A Never allowed to sign in entry has these fields, plus an optional Note:

  • IP address or CIDR range: matches verified connections only.
  • Or a username: on its own, refused from anywhere, even an allowed address, with the answer a wrong password gets. Beside a range or user agent, refused only from there. Your own username cannot be added.
  • Or a user-agent fragment: four characters or more. On its own, it applies to every connection.

Ranges can be no wider than /8 (IPv4) or /32 (IPv6). Each list holds up to 500 entries.

Sessions

OptionWhat it doesDefault
Sign out after idle (minutes)Signs a session out after this long without activity, yours included.0 (no timeout)
Sessions per accountWhen an account signs in past the cap, its oldest session signs out.0 (no cap)

Note: The idle timeout is 0 (off) or 5 to 1440 minutes (one day). The session cap (0 to 100) is unavailable where another plugin replaced WordPress’s session storage.

Who is signed in lists each session’s start, last activity and network. Sign out all their sessions signs one account out everywhere. Sign out everyone you can ends every session you may end, yours included. Both ask Yes, do it first.

Good to know

  • Minimum password lengths are under Settings › General. See General settings.
  • With Ask for my password before an action that removes a protection on, loosening a setting, releasing a lockout or signing people out asks for your password.
  • Safe mode, from your recovery link, pauses everything on this screen.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield