
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall Security & Risk Analysis
wordpress.org/plugins/limit-login-attempts-reloadedBlock excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.
Is Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall Safe to Use in 2026?
Generally Safe
Score 98/100Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall has a strong security track record. Known vulnerabilities have been patched promptly.
The 'limit-login-attempts-reloaded' plugin v2.26.28 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce checks on all its AJAX handlers. The lack of critical or high severity taint flows and no currently unpatched CVEs are also strong indicators of a generally secure recent state.
However, concerns arise from the presence of one AJAX handler without authentication checks, which represents a direct attack vector. While the static analysis did not reveal dangerous functions or raw SQL, the vulnerability history shows a pattern of past issues, including high and medium severity vulnerabilities, particularly related to missing authorization, excessive authentication attempts, and cross-site scripting. This history suggests a need for continued vigilance and a robust review process for future updates. The 70% proper output escaping, while not critically low, indicates room for improvement in preventing potential cross-site scripting vulnerabilities.
In conclusion, the plugin has strengths in its handling of SQL and AJAX nonces. Nevertheless, the single unprotected AJAX endpoint and the historical vulnerability data warrant attention. The plugin is not without risks, and ongoing monitoring and prompt patching of any newly discovered vulnerabilities will be crucial.
Key Concerns
- Unprotected AJAX handler found
- Output escaping not fully comprehensive (70%)
- History of past high severity vulnerabilities
- History of past medium severity vulnerabilities
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Limit Login Attempts Reloaded <= 2.25.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Limit Login Attempts Reloaded <= 2.25.25 - Missing Authorization
Limit Login Attempts Reloaded <= 2.17.3 - Login Rate Limiting Bypass
Limit Login Attempts Reloaded <= 2.15.2 - Reflected Cross-Site Scripting
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall Attack Surface
AJAX Handlers 26
Shortcodes 1
WordPress Hooks 42
Maintenance & Trust
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall Maintenance & Trust
Maintenance Signals
Community Trust
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall Alternatives
VMP Security – Firewall, Malware Scan, and Login Security
vmpfence-security
Your all-in-one WordPress security solution. Stop hackers with our firewall, detect malware before it spreads, and protect your site.
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Anti-Malware Security and Brute-Force Firewall
gotmls
This Anti-Malware scanner searches for Malware, Viruses, and other security threats and vulnerabilities on your server and it helps you fix them.
Defender Security – Malware Scanner, Login Security & Firewall
defender-security
WordPress security plugin with malware scanner, IP blocking, audit logs, antivirus scans, firewall, 2FA, brute force login security, and more.
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall Developer Profile
3 plugins · 2.0M total installs
How We Detect Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/limit-login-attempts-reloaded/assets/css/login.css/wp-content/plugins/limit-login-attempts-reloaded/assets/css/styles.css/wp-content/plugins/limit-login-attempts-reloaded/assets/js/dist/app.js/wp-content/plugins/limit-login-attempts-reloaded/assets/js/login.js/wp-content/plugins/limit-login-attempts-reloaded/assets/js/vendors.js/wp-content/plugins/limit-login-attempts-reloaded/assets/js/dist/app.js/wp-content/plugins/limit-login-attempts-reloaded/assets/js/login.js/wp-content/plugins/limit-login-attempts-reloaded/assets/js/vendors.jslimit-login-attempts-reloaded/assets/css/login.css?ver=limit-login-attempts-reloaded/assets/css/styles.css?ver=limit-login-attempts-reloaded/assets/js/dist/app.js?ver=limit-login-attempts-reloaded/assets/js/login.js?ver=limit-login-attempts-reloaded/assets/js/vendors.js?ver=HTML / DOM Fingerprints
llar-login-formllar-login-wrapperllar_stats_widget<!-- LLAR --><!-- limit-login-attempts-reloaded -->data-llar-noncedata-llar-endpointllarlla_ajax_object/wp-json/llar/v1/ajax_check_login