[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvaFsWc_C6xVINjHU7IjT41ArX01OcGcAM0GPNk0JwZo":3,"$fzvAH_KUEYQxRC134J4SOlfrKzY5AXccsI2BWEq58nOM":141,"$fwqd8JN-oqnouSf8bsdpXestUTuLkxs86Mj0YMppCrgY":146},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":16,"download_link":23,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26,"discovery_status":27,"vulnerabilities":28,"developer":29,"crawl_stats":25,"alternatives":35,"analysis":25,"fingerprints":25},"geticed-failed-login-alerts","GetIced Failed Login Alerts","1.3","Nolan","https:\u002F\u002Fprofiles.wordpress.org\u002Fgeticed123\u002F","\u003Cp>GetIced Failed Login Alerts is a lightweight WordPress security plugin that monitors failed login attempts and notifies administrators instantly.\u003C\u002Fp>\n\u003Cp>Designed to be simple and safe, this plugin helps protect your website from brute-force attacks without the risk of locking you out.\u003C\u002Fp>\n\u003Cp>Features include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Email alerts for failed login attempts\u003C\u002Fli>\n\u003Cli>Track IP addresses and login attempts\u003C\u002Fli>\n\u003Cli>Optional IP blocking (disabled by default for safety)\u003C\u002Fli>\n\u003Cli>Temporary auto-unblock system\u003C\u002Fli>\n\u003Cli>Whitelist trusted IPs to prevent lockouts\u003C\u002Fli>\n\u003Cli>Clean admin interface to view and manage login activity\u003C\u002Fli>\n\u003Cli>Live Dashboard\u003C\u002Fli>\n\u003Cli>Rate limiting\u003C\u002Fli>\n\u003Cli>Bot Detection \u003C\u002Fli>\n\u003Cli>Username Protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Perfect for site owners who want essential login security without heavy, complex security plugins.\u003C\u002Fp>\n\u003Ch3>Short Description\u003C\u002Fh3>\n\u003Cp>Monitor failed login attempts and receive instant email alerts with optional IP blocking and whitelist protection.\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>The plugin automatically tracks failed login attempts.\u003C\u002Fli>\n\u003Cli>Email alerts are sent to the admin email when suspicious activity occurs.\u003C\u002Fli>\n\u003Cli>IP blocking is OFF by default to prevent accidental lockouts.\u003C\u002Fli>\n\u003Cli>You can enable blocking manually in settings if needed.\u003C\u002Fli>\n\u003Cli>Add your IP address to the whitelist to ensure you are never blocked.\u003C\u002Fli>\n\u003Cli>View and manage tracked IPs from the settings page.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GPLv2 or later.\u003C\u002Fp>\n","GetIced Failed Login Alerts is a lightweight WordPress security plugin that monitors failed login attempts and notifies administrators instantly.",0,306,"2026-05-07T20:27:00.000Z","6.9.5","6.0","",[18,19,20,21,22],"alerts","brute-force","failed-login","login","security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgeticed-failed-login-alerts.1.3.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":30,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":24,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},"geticed123",1,30,94,"2026-09-22T13:06:21.807Z",[36,54,76,98,119],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":24,"num_ratings":31,"last_updated":46,"tested_up_to":47,"requires_at_least":48,"requires_php":16,"tags":49,"homepage":51,"download_link":52,"security_score":53,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"email-login-attempts","Email Login Attempts","1.1.1","tildemark","https:\u002F\u002Fprofiles.wordpress.org\u002Ftildemark\u002F","\u003Cp>This plugin will send an email whenever a someone tries to login via the WordPress login page.\u003C\u002Fp>\n\u003Ch4>Todos\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Add admin page\u003C\u002Fli>\n\u003Cli>Specify recipient email addresses\u003C\u002Fli>\n\u003Cli>determine if failed or success login attempt\u003C\u002Fli>\n\u003Cli>Limit login attempts before sending email\u003C\u002Fli>\n\u003Cli>Do not send email on Whitelisted ip addresses\u003C\u002Fli>\n\u003Cli>Ability provide or change the default sender address\u003C\u002Fli>\n\u003Cli>Ability to block IP addresses\u003C\u002Fli>\n\u003Cli>Determine the location where the IP is coming from\u003C\u002Fli>\n\u003Cli>open to suggestions\u003C\u002Fli>\n\u003C\u002Ful>\n","This plugin will send an email whenever a someone tries to login via the WordPress login page.",10,2224,"2015-05-19T01:28:00.000Z","4.2.39","3.0.1",[18,19,50,21,22],"email","http:\u002F\u002Fcazimiweb.com\u002Fplugin\u002Femail-login-attempts","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Femail-login-attempts.1.1.1.zip",85,{"slug":55,"name":56,"version":57,"author":58,"author_profile":59,"description":60,"short_description":61,"active_installs":62,"downloaded":63,"rating":64,"num_ratings":65,"last_updated":66,"tested_up_to":67,"requires_at_least":68,"requires_php":16,"tags":69,"homepage":16,"download_link":73,"security_score":64,"vuln_count":74,"unpatched_count":11,"last_vuln_date":75,"fetched_at":26},"limit-login-attempts-reloaded","Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention","3.3.4","WPChef","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpchefgadget\u002F","\u003Cp>Protect your WordPress website against brute force attacks, bot attacks, and unauthorized login attempts with one of the most trusted login security plugins for WordPress.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\" rel=\"nofollow ugc\">Limit Login Attempts Security\u003C\u002Fa> strengthens your WordPress login security by limiting failed login attempts, blocking malicious IPs, securing wp-login.php, protecting XML-RPC, and adding powerful firewall and 2FA protection without slowing down your website.\u003C\u002Fp>\n\u003Cp>Trusted by 2 million WordPress websites, Limit Login Attempts Security is designed specifically to protect the most targeted part of your website: the login page.\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FS3nf8Zpbcfs?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>Why Use Limit Login Attempts Security?\u003C\u002Fh4>\n\u003Cp>By default, WordPress allows unlimited login attempts. This creates a major security vulnerability where bots and attackers can repeatedly guess usernames and passwords until they gain access. This is especially important in the age of AI, where attackers now have access to faster and more sophisticated tools than ever before.\u003C\u002Fp>\n\u003Cp>Limit Login Attempts Security helps stop:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Brute force attacks\u003C\u002Fli>\n\u003Cli>Bot login attacks\u003C\u002Fli>\n\u003Cli>Credential stuffing attacks\u003C\u002Fli>\n\u003Cli>XML-RPC attacks\u003C\u002Fli>\n\u003Cli>Unauthorized login attempts\u003C\u002Fli>\n\u003Cli>WooCommerce login abuse\u003C\u002Fli>\n\u003Cli>Malicious IP access attempts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin automatically blocks excessive login attempts and locks out suspicious IP addresses and usernames before attackers can gain access.\u003C\u002Fp>\n\u003Ch4>Features Included in the Free Version\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Login Security & Brute Force Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Limit login attempts by IP address and username\u003C\u002Fli>\n\u003Cli>Automatically lock out suspicious login activity\u003C\u002Fli>\n\u003Cli>Adjustable lockout duration and retry limits\u003C\u002Fli>\n\u003Cli>Protect wp-login.php from automated attacks\u003C\u002Fli>\n\u003Cli>Prevent brute force login attacks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>2FA \u002F Multi-Factor Authentication (MFA)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Built-in two-factor authentication (2FA)\u003C\u002Fli>\n\u003Cli>Add an additional layer of login protection\u003C\u002Fli>\n\u003Cli>Improve WordPress account security\u003C\u002Fli>\n\u003Cli>Secure administrator and user logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Firewall & Bot Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Block malicious login requests\u003C\u002Fli>\n\u003Cli>Detect suspicious login behavior\u003C\u002Fli>\n\u003Cli>Reduce bot-based login attacks\u003C\u002Fli>\n\u003Cli>Lightweight firewall-focused login protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>WooCommerce & Plugin Compatibility\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Protects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WooCommerce login pages\u003C\u002Fli>\n\u003Cli>XML-RPC login requests\u003C\u002Fli>\n\u003Cli>Custom login pages\u003C\u002Fli>\n\u003Cli>WordPress multisite installations\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Compatible With:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Wordfence\u003C\u002Fli>\n\u003Cli>Sucuri\u003C\u002Fli>\n\u003Cli>Ultimate Member\u003C\u002Fli>\n\u003Cli>MemberPress\u003C\u002Fli>\n\u003Cli>WPS Hide Login\u003C\u002Fli>\n\u003Cli>Cloudflare and reverse proxy setups\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Login Monitoring & Notifications\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Failed login attempt logs\u003C\u002Fli>\n\u003Cli>Lockout email notifications\u003C\u002Fli>\n\u003Cli>Denied attempt tracking\u003C\u002Fli>\n\u003Cli>Login retry visibility for users\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Access Controls\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>IP safelist and denylist support\u003C\u002Fli>\n\u003Cli>Username safelist and denylist support\u003C\u002Fli>\n\u003Cli>IPv6 range support\u003C\u002Fli>\n\u003Cli>Custom IP origin configuration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Premium Features (Start Your Free 14 Day Trial)\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fplans\u002F\" rel=\"nofollow ugc\">Upgrade to Limit Login Attempts Security Premium\u003C\u002Fa> to extend protection with cloud-based login security and advanced attack prevention.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Cloud Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Real-time malicious IP intelligence\u003C\u002Fli>\n\u003Cli>Global denylist protection\u003C\u002Fli>\n\u003Cli>Synchronized lockouts across websites\u003C\u002Fli>\n\u003Cli>Auto IP denylist generation\u003C\u002Fli>\n\u003Cli>Cloud-based login attack mitigation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Enhanced Performance Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Offload excessive failed login requests from your server\u003C\u002Fli>\n\u003Cli>Reduce server strain during attacks\u003C\u002Fli>\n\u003Cli>Improve stability under heavy attack conditions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced Security Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Country-based login blocking\u003C\u002Fli>\n\u003Cli>Enhanced throttling and lockout escalation\u003C\u002Fli>\n\u003Cli>Registration page protection\u003C\u002Fli>\n\u003Cli>Successful login tracking\u003C\u002Fli>\n\u003Cli>Enhanced lockout analytics and geolocation data\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Multi-Site & Team Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Shared safelist and denylist syncing\u003C\u002Fli>\n\u003Cli>Shared lockout protection between domains\u003C\u002Fli>\n\u003Cli>Cloud backups of IP security data\u003C\u002Fli>\n\u003Cli>CSV exports of login and IP activity\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Premium Support\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Access to security-focused support specialists\u003C\u002Fli>\n\u003Cli>Faster troubleshooting and assistance\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Lightweight Security Built for WordPress\u003C\u002Fh4>\n\u003Cp>Unlike many large security suites, Limit Login Attempts Security focuses specifically on login security and brute force protection.\u003C\u002Fp>\n\u003Cp>This means:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Faster performance\u003C\u002Fli>\n\u003Cli>Less server overhead\u003C\u002Fli>\n\u003Cli>Easier configuration\u003C\u002Fli>\n\u003Cli>Strong protection without unnecessary bloat\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Protect More Than Just wp-login.php\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Security secures:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>wp-login.php\u003C\u002Fli>\n\u003Cli>XML-RPC\u003C\u002Fli>\n\u003Cli>WooCommerce logins\u003C\u002Fli>\n\u003Cli>Custom login forms\u003C\u002Fli>\n\u003Cli>Registration pages\u003C\u002Fli>\n\u003Cli>Multisite logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Trusted by Millions of WordPress Websites\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Security is one of the most widely used WordPress login security plugins and has helped protect millions of websites from brute force attacks and malicious login activity.\u003C\u002Fp>\n\u003Cp>Whether you run:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>A personal blog\u003C\u002Fli>\n\u003Cli>WooCommerce store\u003C\u002Fli>\n\u003Cli>Membership website\u003C\u002Fli>\n\u003Cli>Agency\u003C\u002Fli>\n\u003Cli>Business website\u003C\u002Fli>\n\u003Cli>Enterprise WordPress network\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Limit Login Attempts Security helps secure your login experience with modern WordPress login protection.\u003C\u002Fp>\n\u003Ch4>Upgrading from the Original Limit Login Attempts Plugin?\u003C\u002Fh4>\n\u003Cp>Switching is easy:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Remove the old Limit Login Attempts plugin\u003C\u002Fli>\n\u003Cli>Install Limit Login Attempts Security\u003C\u002Fli>\n\u003Cli>Your settings will remain intact\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Translation Support\u003C\u002Fh4>\n\u003Cp>Currently translated into multiple languages including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Dutch\u003C\u002Fli>\n\u003Cli>Turkish\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Romanian\u003C\u002Fli>\n\u003Cli>Chinese (Traditional)\u003C\u002Fli>\n\u003Cli>Brazilian Portuguese\u003C\u002Fli>\n\u003Cli>And more\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Secure Your WordPress Login Today\u003C\u002Fh4>\n\u003Cp>Install Limit Login Attempts Security and protect your WordPress website with:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Login security\u003C\u002Fli>\n\u003Cli>Two-Factor Authentication (2FA)\u003C\u002Fli>\n\u003Cli>Brute force protection\u003C\u002Fli>\n\u003Cli>Firewall security\u003C\u002Fli>\n\u003Cli>Bot protection\u003C\u002Fli>\n\u003Cli>XML-RPC protection\u003C\u002Fli>\n\u003Cli>WooCommerce login protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Without slowing down your website.\u003C\u002Fp>\n","WordPress login security with brute force protection, Two-factor authentication (2FA\u002FMFA), firewall, IP\u002Fcountry blocking, and login monitoring",1000000,91831747,98,1468,"2026-07-08T11:06:00.000Z","7.0.2","5.0",[70,19,71,72,22],"2fa","firewall","login-security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flimit-login-attempts-reloaded.3.3.4.zip",4,"2023-12-20 00:00:00",{"slug":77,"name":78,"version":79,"author":80,"author_profile":81,"description":82,"short_description":83,"active_installs":84,"downloaded":85,"rating":24,"num_ratings":86,"last_updated":87,"tested_up_to":67,"requires_at_least":88,"requires_php":89,"tags":90,"homepage":94,"download_link":95,"security_score":96,"vuln_count":31,"unpatched_count":11,"last_vuln_date":97,"fetched_at":26},"cloudsecure-wp-security","CloudSecure WP Security","1.4.12","XServer","https:\u002F\u002Fprofiles.wordpress.org\u002Fxserverjp\u002F","\u003Cp>CloudSecure WP Securityは、管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。\u003Cbr \u002F>\n簡単な設定だけで、不正アクセスや不正ログインからWordPressを保護し、サイトのセキュリティを高めます。\u003Cbr \u002F>\n各機能は有効／無効を切り替えるだけで設定でき、必要な対策をわかりやすく管理できます。シンプルで扱いやすい設計のため、日々のサイト運用にも取り入れやすいプラグインです。\u003C\u002Fp>\n\u003Cp>※ 本プラグインは日本国内の利用者向けに提供しているものであり、EU居住者を対象とした提供は意図していません。\u003C\u002Fp>\n\u003Cp>ドキュメントやFAQなど、より詳細な情報は \u003Ca href=\"https:\u002F\u002Fwpplugin.cloudsecure.ne.jp\u002Fcloudsecure_wp_security\" rel=\"nofollow ugc\">こちら\u003C\u002Fa> でご覧いただけます。\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPressのマルチサイト機能には対応していません。\u003C\u002Fli>\n\u003Cli>WebサーバーはApache2.xでの動作を確認済みです。\u003C\u002Fli>\n\u003Cli>画像認証追加機能を利用するためには、PHPに拡張ライブラリ「gd」をインストールする必要があります。\u003C\u002Fli>\n\u003Cli>管理画面アクセス制限機能、ログインURL変更機能を利用するためには、Apacheに「mod_rewrite」を読み込む必要があります。\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>本プラグインの機能は以下のとおりです。\u003C\u002Fp>\n\u003Ch4>ログイン無効化\u003C\u002Fh4>\n\u003Cp>指定した期間内に指定した回数ログインに失敗した場合、指定した時間ログインを無効化（ブロック）します。\u003Cbr \u002F>\nブルートフォースアタックやパスワードリスト攻撃など、不正なログインを試みる攻撃を防ぐための機能です。\u003Cbr \u002F>\nとくに、自動化された攻撃に有効です。\u003C\u002Fp>\n\u003Ch4>ログインURL変更\u003C\u002Fh4>\n\u003Cp>ログインURL（wp-login.php）を変更します。\u003Cbr \u002F>\n半角英小文字、半角数字、ハイフン、アンダースコアのいずれかを使用し、4文字以上12文字以下でお好みの名前（文字列）に設定できます。\u003Cbr \u002F>\nブルートフォースアタックやパスワードリスト攻撃など、不正なログインを試みる攻撃を受けにくくするための機能です。\u003C\u002Fp>\n\u003Ch4>ログインエラーメッセージ統一\u003C\u002Fh4>\n\u003Cp>ログイン時、ユーザー名、パスワード、画像認証のどれを間違えても同一のメッセージを表示します。\u003Cbr \u002F>\nユーザー名の存在を調査する攻撃を受けにくくするための機能です。\u003C\u002Fp>\n\u003Ch4>2段階認証\u003C\u002Fh4>\n\u003Cp>ログイン時、ユーザー名とパスワードの入力に加え、別のコードで追加認証を行います。\u003Cbr \u002F>\n認証方法は\u003Ca href=\"https:\u002F\u002Fplay.google.com\u002Fstore\u002Fapps\u002Fdetails?id=com.google.android.apps.authenticator2\" rel=\"nofollow ugc\">Google Authenticator\u003C\u002Fa> またはメール認証のいずれかを選択できます。\u003Cbr \u002F>\n各認証方法で生成された6桁の認証コードをログイン画面で入力し、すべての情報が一致すればログインできます。\u003Cbr \u002F>\nユーザー名やパスワードを不正入手した第三者によるログインやなりすましを防止し、セキュリティを強化します。\u003C\u002Fp>\n\u003Ch4>画像認証追加\u003C\u002Fh4>\n\u003Cp>画像データ上にランダムに表示される文字の入力を求め、一致しなければ次の画面に進めないようにする機能です。\u003Cbr \u002F>\nログインフォーム、コメントフォーム、パスワードリセットフォーム、ユーザー登録フォームに設定できます。\u003Cbr \u002F>\nブルートフォースアタックやパスワードリスト攻撃などの不正なログインを試みる攻撃や、悪意のあるプログラムからの機械的な不正アクセスを防止する機能です。\u003C\u002Fp>\n\u003Ch4>ユーザー名漏えい防止\u003C\u002Fh4>\n\u003Cp>「?author=数字」アクセスによるユーザー名の漏えいを防止します。\u003C\u002Fp>\n\u003Ch4>XML-RPC無効化\u003C\u002Fh4>\n\u003Cp>XML-RPC機能、またはピンバック機能を無効化し、その乱用から管理画面を保護します。\u003C\u002Fp>\n\u003Ch4>REST API無効化\u003C\u002Fh4>\n\u003Cp>REST APIを無効化し、その悪用から管理画面を守ります。\u003C\u002Fp>\n\u003Ch4>管理画面アクセス制限\u003C\u002Fh4>\n\u003Cp>管理画面にログインしていない接続元IPアドレスから管理ページ（\u002Fwp-admin\u002F以降）にアクセスすると、404エラー（Not Found）を返します。\u003Cbr \u002F>\n24時間以上管理画面にログインしていない接続元IPアドレスが対象です。\u003Cbr \u002F>\nログインすると接続元IPアドレスが記録され、管理画面にアクセスできるようになります。\u003Cbr \u002F>\nこの機能を除外するページ（wp-admin以下）を指定できます。\u003C\u002Fp>\n\u003Ch4>設定ファイルアクセス防止\u003C\u002Fh4>\n\u003Cp>WordPressのシステムに関するファイルへの不正アクセスを遮断する機能です。\u003C\u002Fp>\n\u003Ch4>シンプルWAF\u003C\u002Fh4>\n\u003Cp>WordPressへの攻撃に対して、基本的な防御機能を備えたシンプルなWAF（Web Application Firewall）機能です。\u003Cbr \u002F>\nSQLインジェクションやクロスサイトスクリプティングなどの一般的な攻撃を遮断します。\u003C\u002Fp>\n\u003Ch4>ログイン通知\u003C\u002Fh4>\n\u003Cp>ログインがあったとき、ユーザーにメールで通知します。\u003Cbr \u002F>\n心当たりのないメールを受信した場合、不正なログインを疑ってください。\u003C\u002Fp>\n\u003Ch4>アップデート通知\u003C\u002Fh4>\n\u003Cp>WordPress、プラグイン、テーマの更新が必要になったとき、WordPressの管理者ユーザーにメールで通知します。\u003Cbr \u002F>\n更新の確認は24時間ごとに行われます。\u003Cbr \u002F>\n常に最新版を使用することが、セキュリティの基本です。\u003C\u002Fp>\n\u003Ch4>サーバーエラー通知\u003C\u002Fh4>\n\u003Cp>サーバーエラー「HTTPステータスコード500（Internal Server Error）」が発生したとき、エラーの履歴を記録し、WordPressの管理者ユーザーにメールで通知します。\u003Cbr \u002F>\n1時間以内に同じタイプのエラーが発生した場合、エラーの履歴は記録しますが、メールでの通知は行いません。\u003C\u002Fp>\n\u003Ch4>ログイン履歴\u003C\u002Fh4>\n\u003Cp>管理画面にログインした履歴を表示します。\u003Cbr \u002F>\nそれぞれの項目で絞り込んでの検索も可能です。\u003Cbr \u002F>\nログイン通知と同様、不正なログインの気づきを促す機能です。\u003C\u002Fp>\n","CloudSecure WP Securityは、管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。 簡単な設定だけで、不正アクセスや不正ログインからWordPressを保護し、サイトのセキュリティを高めます。",100000,890285,2,"2026-07-22T03:14:00.000Z","5.3.15","7.1",[91,19,92,22,93],"anti-spam","login-lock","waf","https:\u002F\u002Fwpplugin.cloudsecure.ne.jp\u002Fcloudsecure_wp_security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcloudsecure-wp-security.1.4.12.zip",99,"2026-05-28 00:00:00",{"slug":99,"name":100,"version":101,"author":102,"author_profile":103,"description":104,"short_description":105,"active_installs":106,"downloaded":107,"rating":108,"num_ratings":109,"last_updated":110,"tested_up_to":67,"requires_at_least":111,"requires_php":112,"tags":113,"homepage":114,"download_link":115,"security_score":116,"vuln_count":117,"unpatched_count":11,"last_vuln_date":118,"fetched_at":26},"hide-my-wp","WP Ghost (Hide My WP Ghost) – Security & Firewall","7.0.07","John Darrel","https:\u002F\u002Fprofiles.wordpress.org\u002Fjohndarrel\u002F","\u003Cp>\u003Cstrong>WP Ghost\u003C\u002Fstrong> (formerly known as \u003Cstrong>Hide My WP Ghost\u003C\u002Fstrong>) is a professional-grade, comprehensive \u003Cstrong>hack-prevention security solution for WordPress\u003C\u002Fstrong>. Built for speed and engineered for maximum defense, WP Ghost provides a multi-layered security architecture designed to block hacker bots, neutralize automated scanners, and stop the hack before the reconnaissance even begins.\u003C\u002Fp>\n\u003Cp>While traditional security tools focus on Detection (scanning for malware after a breach) or Signature-Filtering (blocking known exploits), \u003Cstrong>WP Ghost focuses on Architecture\u003C\u002Fstrong>. By implementing \u003Cstrong>Paths Security and Site Hardening\u003C\u002Fstrong>, we remove the digital footprints that make your site a target for automated botnets, providing a \u003Cstrong>proactive foundation that secures your site before it can even be identified as a target\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FQMdoSN8dk1c?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Cp>\u003Cstrong>WP Ghost Global Stats:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>10 Million+ Monthly Brute-Force Attempts Blocked\u003C\u002Fli>\n\u003Cli>100 Million+ Monthly Security Threats Prevented\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Official websites:\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwpghost.com\u002F\" rel=\"nofollow ugc\">WP Ghost (wpghost.com)\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fhidemywpghost.com\u002F\" rel=\"nofollow ugc\">Hide My WP Ghost (hidemywpghost.com)\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Stop Attacks with Paths Security & Architectural Hardening\u003C\u002Fh3>\n\u003Cp>Most WordPress attacks are automated. Bots scan millions of sites per hour looking for default paths like \u002Fwp-admin or \u002Fwp-login.php to confirm a site is running WordPress. Once confirmed, they launch targeted exploits against known plugin or theme vulnerabilities.\u003C\u002Fp>\n\u003Cp>WP Ghost breaks this cycle. By changing and securing common paths, you reduce your attack surface by up to 90%. This isn’t “obscurity”, it’s Site Hardening. We re-engineer the visible structure of your site so it is no longer a low-hanging fruit for global botnets.\u003C\u002Fp>\n\u003Ch3>Key Protections Included\u003C\u002Fh3>\n\u003Cp>WP Ghost is packed with advanced defensive mechanisms to protect your site against:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Brute Force Attacks\u003C\u002Fstrong>: Blocks automated password guessing at the source.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SQL Injection & XSS\u003C\u002Fstrong>: Neutralizes malicious query strings and script injections.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero-Day Exploits\u003C\u002Fstrong>: Secures paths for plugins before patches are even released.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC & REST API Attacks\u003C\u002Fstrong>: Shuts down common remote-access entry points.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bot Reconnaissance\u003C\u002Fstrong>: Prevents “fingerprinting” that hackers use to map your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Spam & Scrapers\u003C\u002Fstrong>: Filters malicious traffic, saving bandwidth and server load.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Over 115 Free Security Features Included\u003C\u002Fh3>\n\u003Cp>We believe professional security should be accessible to everyone. The free version of WP Ghost includes a massive suite of tools to harden your WordPress architecture.\u003C\u002Fp>\n\u003Ch4>1. Change and Secure Paths (Paths Security)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Change wp-admin & wp-login.php\u003C\u002Fstrong>: Move your login to a unique URL and show a 404 error to intruders.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Change Lost Password & Register URLs\u003C\u002Fstrong>: Secure all authentication entry points.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Change wp-content & wp-includes\u003C\u002Fstrong>: Secure your core system folders from direct access.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anonymize Plugins & Themes\u003C\u002Fstrong>: Change visible plugin\u002Ftheme paths so hackers can’t identify your software version.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure admin-ajax.php & REST API\u003C\u002Fstrong>: Change the \u002Fwp-json path to prevent data scraping.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Presets\u003C\u002Fstrong>: One-click activation with three preset levels — from minimal to full protection with Firewall, Brute Force, Logs, and 2FA.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Frontend Test\u003C\u002Fstrong>: Verify your site loads correctly after changing paths before confirming settings.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Redirects\u003C\u002Fstrong>: Set unique login\u002Flogout redirects based on user roles.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Page Designer\u003C\u002Fstrong>: Customize your secured login page with your logo, colors, background, and 10 color schemes.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>2. Next-Gen Firewall & Authentication\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>8G & 7G Firewall Filters\u003C\u002Fstrong>: High-speed, lightweight server-edge filtering to block bad bots.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Passkey Authentication (Passwordless 2FA)\u003C\u002Fstrong>: Use Face ID, Touch ID, or Windows Hello for un-phishable, device-based logins.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Standard 2FA (Code & Email)\u003C\u002Fstrong>: Add an extra verification layer to all user accounts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Headers\u003C\u002Fstrong>: Automatically implement CSP, HSTS, X-Frame-Options, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP & User Agent Blocking\u003C\u002Fstrong>: Manually blacklist suspicious traffic or referrers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Threats Log\u003C\u002Fstrong>: Track blocked attacks and malicious requests directly in your dashboard (limited view).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Events Log\u003C\u002Fstrong>: Monitor login activity, role changes, and user actions (limited view).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GEO Threats Map\u003C\u002Fstrong>: Visualize where attacks originate with an interactive world map showing the top 5 threat countries.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Optimization Score\u003C\u002Fstrong>: Real-time 0-100 score showing exactly how hardened your site is, with actionable recommendations.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Temporary Logins\u003C\u002Fstrong>: Create time-limited access links for developers and clients without sharing passwords.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>3. Deep Hiding & Footprint Removal\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Scrub Meta Tags\u003C\u002Fstrong>: Remove WordPress version numbers and generator tags.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean HTML Comments\u003C\u002Fstrong>: Strip identifiable comments that reveal your tech stack.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide Admin Toolbar\u003C\u002Fstrong>: Remove the toolbar for specific roles to hide backend indicators.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Emoticons & RSD\u003C\u002Fstrong>: Remove unnecessary header links that bloat code and reveal info.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>4. Advanced Disable Options\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable XML-RPC\u003C\u002Fstrong>: Shut down the most common vector for DDoS and brute force.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable REST API Access\u003C\u002Fstrong>: Restrict API access to authenticated users only.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Frontend Lockdown\u003C\u002Fstrong>: Disable right-click, “View Source,” and text selection to prevent manual reconnaissance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Directory Browsing\u003C\u002Fstrong>: Ensure your server folders are never visible to the public.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>5. Brute Force Protection\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Integrated ReCaptcha\u003C\u002Fstrong>: Supports Google V2, V3, Enterprise, and Math ReCaptcha.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Targeted Protection\u003C\u002Fstrong>: Enable brute force defense on Login, Signup, and WooCommerce pages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Throttling\u003C\u002Fstrong>: Define your own lockout times and attempt limits.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>6. Extra Tools & Integrations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Magic Links\u003C\u002Fstrong>: Log in securely without a password via a one-time email link.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Text & URL Mapping\u003C\u002Fstrong>: Change any class name or URL in your source code dynamically.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CDN & Cache Support\u003C\u002Fstrong>: Works perfectly with WP Rocket, Cloudflare, and Litespeed.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Premium Hack-Prevention Features\u003C\u002Fh4>\n\u003Cp>For agencies and high-traffic sites, WP Ghost Premium adds advanced features focused on Security Intelligence, Automated Response, and Copyright Protection.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Ghost Mode\u003C\u002Fstrong>: Maximum security preset, changes all paths, hides all file extensions, and enables all hiding options in one click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Block Automation\u003C\u002Fstrong>: Automatically block IP addresses that trigger repeated security threats.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI Copyright Protection\u003C\u002Fstrong>: Block 30+ AI training crawlers (GPTBot, ClaudeBot, PerplexityBot, and others) at the firewall level. List auto-updated with each release. Does not affect Google, Bing, or regular search visibility.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full Security Threats Log\u003C\u002Fstrong>: Unlimited entries with filters by threat type, status, country, and time range, full-text search, pagination, and CSV export.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full User Events Log\u003C\u002Fstrong>: Unlimited entries with filters, search, pagination, and CSV export.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloud Event Storage\u003C\u002Fstrong>: 30-day cloud retention for audits and incident reports.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-time Email Alerts\u003C\u002Fstrong>: Get notified instantly of brute-force attempts or suspicious activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geo-Security (Country Blocking)\u003C\u002Fstrong>: Block entire countries or specific paths by country.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced File Hardening\u003C\u002Fstrong>: Hide file extensions (PHP, CSS, JS, JSON), secure wp-config.php, php.ini, and debug.log.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database & Server Hardening\u003C\u002Fstrong>: Fix file permissions, change database prefix, regenerate SALT keys.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Priority Support\u003C\u002Fstrong>: Direct access to our security experts and founder-led assistance.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpghost.com\u002Ffeatures\u002F\" rel=\"nofollow ugc\">Hide My WP Premium Feature\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Technical Compatibility\u003C\u002Fh3>\n\u003Cp>WP Ghost is engineered for the modern WordPress ecosystem:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Hosting Support\u003C\u002Fstrong>: Optimized for WP Engine, Inmotion Hosting, Hostgator Hosting, Godaddy Hosting, Host1plus, Payperhost, Fastcomet, Dreamhost, Bitnami Apache, Bitnami Nginx, Google Cloud Hosting, Amazon AWS Lightsail, Litespeed Hosting, Flywheels Hosting, Kinsta Hosting, Ploi.io, CloudPanel, RunCloud, Rocket Domain, Yunohost.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Server Support\u003C\u002Fstrong>: Fully compatible with Nginx, Apache, LiteSpeed, and IIS.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin Support\u003C\u002Fstrong>: Seamless integration with Woocommerce, WPML, WPMUDEV, W3 Total Cache, Gravity, WP Super Cache, WP Fastest Cache, Hummingbird Cache, Cachify Cache, Litespeed Cache, SiteGround Optimizer, Nitropack, Cache Enabler, CDN Enabler, WOT Cache, Autoptimize, Jetpack by WordPress, Contact Form 7, bbPress, Manage WP, All In One SEO, Rank Math, Yoast SEO, Squirrly SEO, WP-Rocket, Minify HTML, Solid Security, Sucuri Security, Really Simple SSL, WordFence Security, WP Cerber Security, BBQ Firewall, Anti-Malware Security, Back-Up WordPress, Elementor Page Builder, Divi Builder, Weglot Translate, AddToAny Share Btn, Limit Login Attempts Reloaded, Loginizer, Shield Security, Asset CleanUp, WP Hide & Security Enhancer, and more.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Stop the hack before it starts\u003C\u002Fstrong>. Join over 100,000 users who trust WP Ghost to secure their digital presence.\u003C\u002Fp>\n","Hide and Secure WP paths with the complete WP security suite for Site Hardening. Includes 8G Firewall, Brute Force protection, and Passkeys.",80000,2693018,90,371,"2026-07-20T11:52:00.000Z","5.8","7.4",[19,71,99,21,22],"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fhide-my-wp\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhide-my-wp.7.0.07.zip",89,8,"2026-03-18 00:00:00",{"slug":120,"name":121,"version":122,"author":123,"author_profile":124,"description":125,"short_description":126,"active_installs":127,"downloaded":128,"rating":129,"num_ratings":130,"last_updated":131,"tested_up_to":132,"requires_at_least":133,"requires_php":112,"tags":134,"homepage":137,"download_link":138,"security_score":139,"vuln_count":31,"unpatched_count":11,"last_vuln_date":140,"fetched_at":26},"wp-fail2ban","WP fail2ban – Advanced Security","5.4.1","invisnet","https:\u002F\u002Fprofiles.wordpress.org\u002Finvisnet\u002F","\u003Cp>\u003Ca href=\"http:\u002F\u002Fwww.fail2ban.org\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=wp-fail2ban-premium-5.4.1\" rel=\"nofollow ugc\">fail2ban\u003C\u002Fa> is one of the simplest and most effective security measures you can implement to protect your WordPress site.\u003C\u002Fp>\n\u003Cp>\u003Cem>WP fail2ban\u003C\u002Fem> provides the link between WordPress and \u003Ccode>fail2ban\u003C\u002Fcode>:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>Oct 17 20:59:54 foobar wordpress(www.example.com)[1234]: Authentication failure for admin from 192.168.0.1\nOct 17 21:00:00 foobar wordpress(www.example.com)[2345]: Accepted password for admin from 192.168.0.1\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Cem>WPf2b\u003C\u002Fem> comes with three \u003Ccode>fail2ban\u003C\u002Fcode> filters: \u003Ccode>wordpress-hard.conf\u003C\u002Fcode>, \u003Ccode>wordpress-soft.conf\u003C\u002Fcode>, and \u003Ccode>wordpress-extra.conf\u003C\u002Fcode>. These are designed to allow a split between immediate banning (hard) and the traditional more graceful approach (soft), with extra rules for custom configurations.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Failed Login Attempts\u003C\u002Fstrong>\u003Cbr \u002F>\nThe very first feature of \u003Cem>WPf2b\u003C\u002Fem>: logging failed login attempts so the IP can be banned. Just as useful today as it was then.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Block User Enumeration\u003C\u002Fstrong>\u003Cbr \u002F>\nOne of the most common precursors to a password-guessing brute force attack is \u003Ca href=\"https:\u002F\u002Fwp-fail2ban.com\u002Ffeatures\u002Fblock-user-enumeration\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=wp-fail2ban-premium-5.4.1\" rel=\"nofollow ugc\">user enumeration\u003C\u002Fa>. \u003Cem>WPf2b\u003C\u002Fem> can block it, stopping the attack before it starts.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Block username logins\u003C\u002Fstrong>\u003Cbr \u002F>\nSometimes it’s not possible to block user enumeration (for example, if your theme provides Author profiles). \u003Cem>WPf2b\u003C\u002Fem> can require users to login with their email address instead of their username.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Blocking Users\u003C\u002Fstrong>\u003Cbr \u002F>\nAnther of the older \u003Cem>WPf2b\u003C\u002Fem> features: the login process can be aborted for specified usernames.\u003Cbr \u002F>\nSay a bot collected your site’s usernames before you blocked user enumeration. Once you’ve changed all the usernames, add the old ones to the list; anything using them will trigger a “hard” fail.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Empty Username Login Attempts\u003C\u002Fstrong>\u003Cbr \u002F>\nSome bots will try to login without a username; harmless, but annoying. These attempts are logged as a “soft” fail so the more persistent bots will be banned.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Spam\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>WPf2b\u003C\u002Fem> will log a spammer’s IP address as a “hard” fail when their comment is marked as spam; the Premium version will also log the IP when Akismet discards “obvious” spam.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Attempted Comments\u003C\u002Fstrong>\u003Cbr \u002F>\nSome spam bots try to comment on everything, even things that aren’t there. \u003Cem>WPf2b\u003C\u002Fem> detects these and logs them as a “hard” fail.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Pingbacks\u003C\u002Fstrong>\u003Cbr \u002F>\nPingbacks are a great feature, but they can be abused to attack the rest of the WWW. Rather than disable them completely, \u003Cem>WPf2b\u003C\u002Fem> effectively rate-limits potential attackers by logging the IP address as a “soft” fail.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Block XML‑RPC Requests\u003C\u002Fstrong> [Premium]\u003Cbr \u002F>\nThe only reason most sites need XML‑RPC (other than Pingbacks) is for Jetpack; \u003Cem>WPf2b\u003C\u002Fem> Premium can block XML‑RPC while allowing Jetpack and\u002For Pingbacks.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Block Countries\u003C\u002Fstrong> [Premium]\u003Cbr \u002F>\nSometimes you just need a bigger hammer – if you’re seeing nothing but attacks from some countries, block them!\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Cloudflare and Proxy Servers\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>WPf2b\u003C\u002Fem> will work with \u003Ca href=\"https:\u002F\u002Fwp-fail2ban.com\u002Ffeatures\u002Fcloudflare-and-proxy-servers\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=wp-fail2ban-premium-5.4.1\" rel=\"nofollow ugc\">Cloudflare\u003C\u002Fa>, and the Premium version will automatically update the list of Cloudflare IP addresses.\u003Cbr \u002F>\nYou can also configure your own list of trusted proxies.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>syslog Dashboard Widget\u003C\u002Fstrong>\u003Cbr \u002F>\nEver wondered what’s being logged? The dashboard widget shows the last 5 messages; the Premium version keeps a full history to help you analyse and prevent attacks.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Site Health Check\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>WPf2b\u003C\u002Fem> will (try to) check that your \u003Ccode>fail2ban\u003C\u002Fcode> configuration is sane and that the filters are up to date; out-of-date filters are the primary cause of \u003Cem>WPf2b\u003C\u002Fem> not working as well as it can.\u003Cbr \u002F>\nWhen did you last run the Site Health tool?\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>\u003Ccode>mu-plugins\u003C\u002Fcode> Support\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>WPf2b\u003C\u002Fem> can easily be configured as a “must-use plugin” – see \u003Ca href=\"https:\u002F\u002Fdocs.wp-fail2ban.com\u002Fen\u002F5.4\u002Fconfiguration.html?utm_source=wordpress.org&utm_medium=readme&utm_campaign=wp-fail2ban-premium-5.4.1#mu-plugins-support\" rel=\"nofollow ugc\">Configuration\u003C\u002Fa>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>API to Extend \u003Cem>WPf2b\u003C\u002Fem>\u003C\u002Fstrong>\u003Cbr \u002F>\nIf your plugin can detect behaviour which should be blocked, why reinvent the wheel?\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Event Hooks\u003C\u002Fstrong> [Premium]\u003Cbr \u002F>\nNeed to do something special when \u003Cem>WPf2b\u003C\u002Fem> detects a particular event? \u003Ca href=\"https:\u002F\u002Fdocs.wp-fail2ban.com\u002Fen\u002F5.4\u002Fdevelopers\u002Fevents.html?utm_source=wordpress.org&utm_medium=readme&utm_campaign=wp-fail2ban-premium-5.4.1\" rel=\"nofollow ugc\">There’s a hook for that\u003C\u002Fa>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Premium\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Web Application Firewall (WAF)\u003C\u002Fli>\n\u003Cli>Akismet support.\u003C\u002Fli>\n\u003Cli>Block XML‑RPC while allowing Jetpack and\u002For Pingbacks.\u003C\u002Fli>\n\u003Cli>Block Countries.\u003C\u002Fli>\n\u003Cli>Auto-update Cloudflare IPs.\u003C\u002Fli>\n\u003Cli>Event log.\u003C\u002Fli>\n\u003Cli>Event hooks.\u003C\u002Fli>\n\u003C\u002Ful>\n","WP fail2ban uses fail2ban to protect your WordPress site.",60000,1998749,84,71,"2025-04-29T15:21:00.000Z","6.8.6","4.2",[19,135,21,22,136],"fail2ban","syslog","https:\u002F\u002Fwp-fail2ban.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-fail2ban.5.4.1.zip",91,"2019-02-25 00:00:00",{"error":142,"url":143,"statusCode":144,"statusMessage":145,"message":145},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fgeticed-failed-login-alerts\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":74,"versions":147},[148,154,161,168],{"version":6,"download_url":23,"svn_tag_url":149,"released_at":25,"has_diff":150,"diff_files_changed":151,"diff_lines":25,"trac_diff_url":152,"vulnerabilities":153,"is_current":142},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fgeticed-failed-login-alerts\u002Ftags\u002F1.3\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fgeticed-failed-login-alerts%2Ftags%2F1.2&new_path=%2Fgeticed-failed-login-alerts%2Ftags%2F1.3",[],{"version":155,"download_url":156,"svn_tag_url":157,"released_at":25,"has_diff":150,"diff_files_changed":158,"diff_lines":25,"trac_diff_url":159,"vulnerabilities":160,"is_current":150},"1.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgeticed-failed-login-alerts.1.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fgeticed-failed-login-alerts\u002Ftags\u002F1.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fgeticed-failed-login-alerts%2Ftags%2F1.1&new_path=%2Fgeticed-failed-login-alerts%2Ftags%2F1.2",[],{"version":162,"download_url":163,"svn_tag_url":164,"released_at":25,"has_diff":150,"diff_files_changed":165,"diff_lines":25,"trac_diff_url":166,"vulnerabilities":167,"is_current":150},"1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgeticed-failed-login-alerts.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fgeticed-failed-login-alerts\u002Ftags\u002F1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fgeticed-failed-login-alerts%2Ftags%2F1.0&new_path=%2Fgeticed-failed-login-alerts%2Ftags%2F1.1",[],{"version":169,"download_url":170,"svn_tag_url":171,"released_at":25,"has_diff":150,"diff_files_changed":172,"diff_lines":25,"trac_diff_url":25,"vulnerabilities":173,"is_current":150},"1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgeticed-failed-login-alerts.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fgeticed-failed-login-alerts\u002Ftags\u002F1.0\u002F",[],[]]