Li

Limit Login Attempts Reloaded

by WPChef

Blocks brute force attempts by limiting retries per IP, with optional cloud reputation data.

4.81,483 WordPress.org reviewsSecurityFreemium

This link may earn us a commission. It never changes our rating.

What Limit Login Attempts Reloaded does

Blocks brute force attempts by limiting retries per IP, with optional cloud reputation data.

It sits in the security part of a WordPress stack and is sold by WPChef on a freemium basis. We recommend it in our security guides because it does that one job well without asking you to rebuild the rest of the site around it.

Every plugin adds work to a page request, so treat this as a decision with a cost. Record a speed test before you install it and run the same test afterwards, on the same page, so you know exactly what it charged you.

Real user ratings

Score

4.8/5

Reviews

1,483

Active installs

1,000,000+

Downloads

95.0M

Latest version

3.3.8

Last updated

2026-09-10

These figures come straight from the public WordPress.org plugin directory API for version 3.3.8, not from us. Check them yourself on the WordPress.org listing. Our own editorial score is 4.8/5.

Where Limit Login Attempts Reloaded ranks elsewhere

Limit Login Attempts Reloaded does not appear in the published "best of" lists we track from WPBeginner, TechRadar, Kinsta, Themeisle and similar sites. That is not a mark against it - those roundups are short and skew towards the biggest names.

What changed in the latest version

v3.3.8Latest release
  • Added Personal and Business plans to the premium comparison table and made the displayed plans adapt to the currently installed plan.
  • Aligned dashicons across the logs, premium, ACL and help admin pages for WordPress 7 compatibility.
  • Fixed the failed-login page script being blocked under a nonce-based Content Security Policy by printing it with wp_get_inline_script_tag(). Thanks to Oskar Schöldström (@oxyc) for the pull request.
  • Fixed the denylist matching the account email when only the username was listed; now the submitted login is matched literally (case-insensitive), while explicit email entries still apply.
v3.3.7
  • Fixed PHP warnings when a cloud app custom setting is missing the label, description, or value field.
  • Added the SameSite=Lax attribute to the login flow cookie for better CSRF protection.
  • Fixed dashicons line-height on all admin pages and dashboard widgets for WordPress 7 compatibility.
  • Fixed the cloud app setup so it verifies the setup code was saved before activating the custom app, preventing an inconsistent state on storage errors.
  • Fixed the review admin notice buttons not working because its inline script was being stripped by output sanitization.
  • Fixed the Micro Cloud setup so it surfaces the actual server error message to admins and handles an incomplete app configuration gracefully instead of failing silently.
v3.3.6
  • Refactored the core plugin class into smaller services.

Release notes are the developer's own words, published on WordPress.org. Read the full changelog

Pros and cons

  • Big protection for almost no overhead
  • A free tier you can trial before paying
  • Actively maintained and used on production sites we test
  • Only covers login guessing
  • The features most sites need sit in the paid tier

How to use it

  1. 1Take a full backup before enabling any blocking feature.
  2. 2Turn on login protection and two-factor for administrator accounts first.
  3. 3Schedule scans outside peak hours to protect response times.
  4. 4Set alerts to a monitored inbox, not the default admin address.
  5. 5Re-run the speed test so you know what the protection costs you.

How it compares

Other security plugins we recommend, with their rating and pricing model.

PluginOur ratingWordPress.orgPricingBest for
Limit Login Attempts Reloaded4.84.8 (1,483)FreemiumBig protection for almost no overhead
Akismet4.74.7 (1,186)FreemiumCatches almost all comment spam with no tuning
Antispam Bee4.84.8 (226)FreePrivacy friendly spam filtering with no account
Duo4.24 (1)FreemiumCentral policy control for teams
Jetpack Protect4.34.6 (123)FreemiumFree vulnerability alerts
Loggedin4.44.9 (111)FreeStops shared account credentials

Guides that cover Limit Login Attempts Reloaded