[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fz7bbeOvXqpd_DqTX_lLz41P_8GKztigeFBwD7K9fiK0":3,"$fmVTi2Q988BrcfHZxwiaOPZvRDzWAKfhENL6k1qwcyX4":129,"$fQxTqVmKhx02hyhGYMXS5woTVZM0NrAOHy_wZ11EaFB0":134},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"discovery_status":30,"vulnerabilities":31,"developer":32,"crawl_stats":28,"alternatives":38,"analysis":28,"fingerprints":28},"loginarmor-email-2fa","LoginArmor – Email 2FA","1.2","TechArk Solutions","https:\u002F\u002Fprofiles.wordpress.org\u002Fgotechark\u002F","\u003Cp>LoginArmor adds an extra layer of protection to WordPress logins by requiring a one-time verification code after a valid username and password are entered.\u003C\u002Fp>\n\u003Ch4>Key features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Email-based one-time passcodes for WordPress logins\u003C\u002Fli>\n\u003Cli>Apply 2FA to selected user roles\u003C\u002Fli>\n\u003Cli>Apply 2FA to specific users\u003C\u002Fli>\n\u003Cli>Optional grace period before activation is enforced\u003C\u002Fli>\n\u003Cli>Recovery codes for backup access\u003C\u002Fli>\n\u003Cli>Customizable email subject and login code email template\u003C\u002Fli>\n\u003Cli>Optional debug logging to \u003Ccode>wp-content\u002Fuploads\u002Floginarmor-email-2fa\u002Floginarmor-debug.log\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Automatic log rotation to prevent unbounded log file growth\u003C\u002Fli>\n\u003Cli>Compatible with WordPress application passwords and REST API clients\u003C\u002Fli>\n\u003Cli>Dedicated settings screen inside the WordPress admin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How it works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>A user enters a valid username and password.\u003C\u002Fli>\n\u003Cli>LoginArmor sends a one-time code to the user’s email address.\u003C\u002Fli>\n\u003Cli>The user enters the code to complete login.\u003C\u002Fli>\n\u003Cli>If needed, the user can use a recovery code instead.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Recovery codes\u003C\u002Fh4>\n\u003Cp>The plugin includes recovery codes as a backup login option. Codes are stored securely as hashes in user meta. Plaintext codes are shown only temporarily so users can save or download them once.\u003C\u002Fp>\n\u003Ch4>Grace period\u003C\u002Fh4>\n\u003Cp>You can optionally set a grace period in days. During the grace period, eligible users can continue signing in while they complete activation. After the grace period ends, 2FA is enforced.\u003C\u002Fp>\n\u003Ch4>No external service required\u003C\u002Fh4>\n\u003Cp>LoginArmor uses WordPress email delivery and does not require a third-party 2FA service.\u003C\u002Fp>\n\u003Ch4>Developer notes\u003C\u002Fh4>\n\u003Cp>The plugin exposes a filter for sites running behind a reverse proxy (Cloudflare, load balancers, etc.) that need to supply the real visitor IP:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>add_filter( 'la2fa_get_client_ip', function( $ip ) {\n    return $_SERVER['HTTP_CF_CONNECTING_IP'] ?? $_SERVER['REMOTE_ADDR'] ?? 'unknown';\n} );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Without this filter the plugin behaves exactly as before — it reads \u003Ccode>REMOTE_ADDR\u003C\u002Fcode> by default.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>LoginArmor does not connect to an external third-party verification service.\u003C\u002Fp>\n\u003Cp>The plugin may process and store the following data on your WordPress site:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Email-based one-time passcodes for login verification\u003C\u002Fli>\n\u003Cli>Recovery code hashes stored in user meta\u003C\u002Fli>\n\u003Cli>Optional debug log entries in \u003Ccode>wp-content\u002Fuploads\u002Floginarmor-email-2fa\u002Floginarmor-debug.log\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Temporary transients used for login, cooldown, and verification flow\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This data stays on your site unless your own email delivery system or hosting stack routes it elsewhere.\u003C\u002Fp>\n","Add secure email-based 2FA authentication to WordPress logins with OTP verification, recovery codes, a grace period, and flexible user targeting.",10,323,100,1,"2026-06-05T06:59:00.000Z","7.0.2","6.0","7.4",[20,21,22,23,24],"2fa","email-otp","login-security","recovery-codes","two-factor-authentication","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Floginarmor-email-2fa.1.2.zip",0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":33,"display_name":7,"profile_url":8,"plugin_count":34,"total_installs":13,"avg_security_score":13,"avg_patch_time_days":35,"trust_score":36,"computed_at":37},"gotechark",6,30,94,"2026-08-28T18:51:24.645Z",[39,58,74,91,112],{"slug":40,"name":41,"version":42,"author":43,"author_profile":44,"description":45,"short_description":46,"active_installs":47,"downloaded":48,"rating":49,"num_ratings":50,"last_updated":51,"tested_up_to":16,"requires_at_least":52,"requires_php":53,"tags":54,"homepage":25,"download_link":57,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"wordfence-login-security","Wordfence Login Security","1.1.16","wfryan","https:\u002F\u002Fprofiles.wordpress.org\u002Fwfryan\u002F","\u003Ch3>WORDFENCE LOGIN SECURITY\u003C\u002Fh3>\n\u003Cp>Wordfence Login Security contains a subset of the functionality found in the full Wordfence plugin: Two-factor Authentication, XML-RPC Protection, and Login Page CAPTCHA.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>This plugin is being discontinued on or around July 1, 2026.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All of its features are already included in the main Wordfence plugin, which is also available to use for free. We recommend installing Wordfence to continue receiving updates, security improvements, and full functionality.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwordfence\u002F\" rel=\"ugc\">Install the full Wordfence plugin\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Two-factor authentication (2FA), one of the most secure forms of remote system authentication available.\u003C\u002Fli>\n\u003Cli>Use any TOTP-based authenticator app or service like Google Authenticator, Authy, 1Password or FreeOTP.\u003C\u002Fli>\n\u003Cli>Enable 2FA for any WordPress user role.\u003C\u002Fli>\n\u003Cli>Completely free to use, no limits or restrictions of any kind.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>LOGIN PAGE CAPTCHA\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Easily enable Google ReCAPTCHA v3 on your login and registration pages.\u003C\u002Fli>\n\u003Cli>Stops bots from logging in without inconveniencing your site visitors.\u003C\u002Fli>\n\u003Cli>Robust protection against password guessing and credential stuffing attacks distributed across large IP pools\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>XML-RPC PROTECTION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>XML-RPC is the biggest target for WordPress attacks, but is often overlooked.\u003C\u002Fli>\n\u003Cli>Protect XML-RPC with 2FA or disable it altogether if it’s not needed.\u003C\u002Fli>\n\u003C\u002Ful>\n","Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.",60000,1329360,78,26,"2026-04-29T15:29:00.000Z","4.7","7.0",[20,55,22,56,24],"captcha","security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwordfence-login-security.1.1.16.zip",{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":27,"downloaded":66,"rating":27,"num_ratings":27,"last_updated":67,"tested_up_to":16,"requires_at_least":17,"requires_php":68,"tags":69,"homepage":72,"download_link":73,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"loginberry","LoginBerry – 2FA, Passwordless & Email Verification","1.0.3","BerryPress","https:\u002F\u002Fprofiles.wordpress.org\u002Fberrypress\u002F","\u003Cp>LoginBerry bundles \u003Cstrong>account verification\u003C\u002Fstrong>, \u003Cstrong>two-factor authentication (2FA)\u003C\u002Fstrong>, \u003Cstrong>passwordless login\u003C\u002Fstrong>, \u003Cstrong>login logs\u003C\u002Fstrong>, and optional \u003Cstrong>last-login tracking\u003C\u002Fstrong>. Each feature can be enabled or disabled independently. Outgoing codes are delivered by \u003Cstrong>email\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>The plugin works for standard WordPress sites. When WooCommerce is active, additional customer- and order-related options are available (for example 2FA on the My Account login form and optional account activation tied to orders).\u003C\u002Fp>\n\u003Ch4>User-facing behavior (when features are enabled)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Account verification:\u003C\u002Fstrong> After registration, the user signs in and completes activation on the configured activation page using a six-digit code sent by email.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-factor authentication:\u003C\u002Fstrong> After a successful username and password, the user enters a second code sent by email. Per-role modes are Required, Optional, or Disabled.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Passwordless login:\u003C\u002Fstrong> On \u003Ccode>wp-login.php\u003C\u002Fcode>, eligible roles may request a one-time email code instead of entering a password.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login logs:\u003C\u002Fstrong> Success and failure records are listed in the WordPress admin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Last-login tracking:\u003C\u002Fstrong> Successful login times can be recorded and displayed in a Last Login column under \u003Cstrong>Users \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> All Users\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Authentication codes are email-based; end users do not install a separate authenticator app for the flows described here.\u003C\u002Fp>\n\u003Ch4>Account verification\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>New accounts receive a six-digit activation code by email.\u003C\u002Fli>\n\u003Cli>After fifteen failed activation attempts, the account is locked until an administrator intervenes.\u003C\u002Fli>\n\u003Cli>Administrators can resend codes, activate accounts manually, and unlock accounts from \u003Cstrong>Users \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> All Users\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Two-factor authentication (2FA)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Per-role setting: Required, Optional, or Disabled.\u003C\u002Fli>\n\u003Cli>Optional mode allows users to enable 2FA from the profile when permitted by role.\u003C\u002Fli>\n\u003Cli>Supported on \u003Ccode>wp-login.php\u003C\u002Fcode> and on the WooCommerce \u003Cstrong>My Account\u003C\u002Fstrong> login form.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Passwordless login\u003C\u002Fh4>\n\u003Cp>Let users log in without a password – just enter a username or email and receive a one-time login code. Improves user experience while maintaining strong security through email verification.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Toggle between password and passwordless login on wp-login.php\u003C\u002Fli>\n\u003Cli>One-time email codes on \u003Ccode>wp-login.php\u003C\u002Fcode>, controlled per role.\u003C\u002Fli>\n\u003Cli>When both passwordless login and 2FA are enabled for the same role, the passwordless flow does not require a separate 2FA step (email possession is already verified).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WooCommerce\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Optional automatic account activation when an WooCommerce order is created.\u003C\u002Fli>\n\u003Cli>Optional restriction so that only \u003Cstrong>paid\u003C\u002Fstrong> orders trigger activation.\u003C\u002Fli>\n\u003Cli>Integration points include classic checkout, block checkout (Store API), and paid-order completion hooks, as implemented in the plugin.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Login logs\u003C\u002Fh4>\n\u003Cp>Monitor all login activity on your site. Essential for detecting suspicious behavior and meeting security compliance requirements for e-commerce stores.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records successful and failed login attempts\u003C\u002Fli>\n\u003Cli>Logs username, email, IP address, and timestamp\u003C\u002Fli>\n\u003Cli>Stores login history in a dedicated database table for more efficient querying as the log grows\u003C\u002Fli>\n\u003Cli>View, search, filter, and delete logs from a dedicated admin page\u003C\u002Fli>\n\u003Cli>Optionally track each user’s most recent successful login and show it under \u003Cstrong>Users \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> All Users\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Identify patterns of brute force attacks and suspicious login activity\u003C\u002Fli>\n\u003Cli>Audit trail for security compliance and fraud investigation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Last-login tracking can be enabled independently of full login logging under \u003Cstrong>BerryPress \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> LoginBerry \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Login Logs\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch4>Admin interface\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Centralized settings under \u003Cstrong>BerryPress \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> LoginBerry\u003C\u002Fstrong>, with separate screens per feature.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Email templates\u003C\u002Fh4>\n\u003Cp>HTML email templates for activation, 2FA, and passwordless login ship in the plugin \u003Ccode>templates\u002F\u003C\u002Fcode> directory. To override, copy the desired template into the active theme or child theme under \u003Ccode>templates\u002Floginberry\u002F\u003C\u002Fcode> (see each template file header for the exact path).\u003C\u002Fp>\n\u003Ch4>Email delivery\u003C\u002Fh4>\n\u003Cp>Reliable outbound email is required for codes to arrive. Typical setups use the hosting provider’s mail relay, a transactional email API (for example Brevo, Mailchimp Transactional \u002F Mandrill, Postmark, SendGrid, Amazon SES), or a WordPress plugin that sends mail via SMTP or a provider API. Test delivery with a real signup or code request before relying on the feature in production.\u003C\u002Fp>\n\u003Ch4>Typical use cases\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Reducing unwanted or automated registrations and limiting abuse of disposable email addresses.\u003C\u002Fli>\n\u003Cli>Verifying that a customer or member controls the email address on file.\u003C\u002Fli>\n\u003Cli>Adding a second factor after password entry for selected roles.\u003C\u002Fli>\n\u003Cli>Reviewing login success and failure history in the admin.\u003C\u002Fli>\n\u003Cli>WooCommerce: applying optional post-order account activation, including a paid-order-only mode where configured.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Roadmap\u003C\u002Fh4>\n\u003Cp>LoginBerry is a brand new plugin and we are improving it quickly based on real user feedback. If you have ideas, feature requests, or run into a theme-specific styling issue, we would love to hear from you.\u003C\u002Fp>\n\u003Cp>Planned work includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Configurable failed-attempt limits (instead of the fixed fifteen for activation lockout)\u003C\u002Fli>\n\u003Cli>Custom activation page URL\u003C\u002Fli>\n\u003Cli>Custom redirect URL after successful verification\u003C\u002Fli>\n\u003Cli>Rate limiting on code verification attempts\u003C\u002Fli>\n\u003Cli>Social login options\u003C\u002Fli>\n\u003Cli>Improved styling flexibility and theme compatibility\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Feedback and compatibility reports are welcome via the plugin support channels. New features are prioritized based on user feedback.\u003C\u002Fp>\n","Complete login security for WordPress & WooCommerce: LoginBerry adds email-based account verification, optional two-factor authentication (2FA), o &hellip;",403,"2026-07-22T02:37:00.000Z","8.0",[20,70,22,71,24],"email-verification","passwordless-login","https:\u002F\u002Fberrypress.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Floginberry.1.0.3.zip",{"slug":75,"name":76,"version":77,"author":78,"author_profile":79,"description":80,"short_description":81,"active_installs":27,"downloaded":82,"rating":27,"num_ratings":27,"last_updated":83,"tested_up_to":84,"requires_at_least":85,"requires_php":25,"tags":86,"homepage":25,"download_link":89,"security_score":90,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"secureauth-authenticator-2fa","SecureAuth Authenticator 2FA","1.0.0","Helmi","https:\u002F\u002Fprofiles.wordpress.org\u002Fhelmimubarak\u002F","\u003Cp>\u003Cstrong>SecureAuth Authenticator 2FA\u003C\u002Fstrong> enhances your WordPress login security by requiring a time-based one-time password (TOTP) in addition to the regular username and password. The TOTP code is generated by an authenticator app on your mobile device, adding an extra layer of protection even if your password is compromised.\u003C\u002Fp>\n\u003Cp>This plugin is lightweight, secure, and easy to use. It integrates directly into the user profile page to allow users to set up and manage their two-factor authentication with ease.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Adds a TOTP (Time-Based One-Time Password) field to the login form.\u003C\u002Fli>\n\u003Cli>User-friendly 2FA setup available on each user’s profile page.\u003C\u002Fli>\n\u003Cli>Generates secret keys and displays QR codes for scanning with mobile apps.\u003C\u002Fli>\n\u003Cli>Compatible with apps like Google Authenticator, Microsoft Authenticator, and Authy.\u003C\u002Fli>\n\u003Cli>Secure handling with nonce verification and input sanitization.\u003C\u002Fli>\n\u003Cli>No external libraries required (except Google Chart API for QR code).\u003C\u002Fli>\n\u003C\u002Ful>\n","Adds TOTP-based two-factor authentication (2FA) via SecureAuth Authenticator to your WordPress login page.",408,"2025-07-09T00:00:00.000Z","6.8.6","5.0",[20,22,87,24,88],"totp","wordpress-security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecureauth-authenticator-2fa.1.0.0.zip",92,{"slug":92,"name":93,"version":94,"author":95,"author_profile":96,"description":97,"short_description":98,"active_installs":99,"downloaded":100,"rating":36,"num_ratings":101,"last_updated":102,"tested_up_to":16,"requires_at_least":85,"requires_php":103,"tags":104,"homepage":107,"download_link":108,"security_score":109,"vuln_count":110,"unpatched_count":27,"last_vuln_date":111,"fetched_at":29},"all-in-one-wp-security-and-firewall","All-In-One Security (AIOS) – Security and Firewall","5.4.9","David Anderson \u002F Team Updraft","https:\u002F\u002Fprofiles.wordpress.org\u002Fdavidanderson\u002F","\u003Ch3>THE TOP RATED WORDPRESS SECURITY AND FIREWALL PLUGIN\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios&utm_creative_format=description\" rel=\"nofollow ugc\">All-in-One Security (AIOS)\u003C\u002Fa> is a WordPress security plugin from the same, trusted team that brought you UpdraftPlus.\u003C\u002Fp>\n\u003Cp>It’s called ‘All-In-One’ because it’s packed full of ways to keep your WordPress website(s) safe and secure.\u003C\u002Fp>\n\u003Cp>It includes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login security features\u003C\u002Fstrong> keep bots at bay. Lock out users based on a configurable number of login attempts, get two-factor authentication and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File and database security.\u003C\u002Fstrong> Get notified of file changes that occur outside of normal operations. Block access to key files and scan files and folders to spot insecure permissions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Firewall.\u003C\u002Fstrong> Get PHP, .htaccess and 6G firewall rules courtesy of Perishable Press. Spot and block fake Google Bots and more!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Spam prevention.\u003C\u002Fstrong> Prevent annoying spam comments and reduce unnecessary load on the server. Automatically and permanently block IP addresses that exceed a set number of spam comments.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit log.\u003C\u002Fstrong> View events happening on your WordPress website. Find out if a plugin or theme has been added, removed, updated and more.\u003C\u002Fp>\n\u003Ch4>WHY ALL-IN-ONE SECURITY?\u003C\u002Fh4>\n\u003Cp>AIOS has a near-perfect \u003Cstrong>4.7 \u002F 5-star user rating\u003C\u002Fstrong> across more than 1 million installs.\u003C\u002Fp>\n\u003Cp>Great for beginners and experts alike. AIOS guides you logically and clearly through each of its features which are all clearly explained. Security features are marked as basic, intermediate and advanced. Each step increases your security score. Turn them on and watch your protection grow!\u003C\u002Fp>\n\u003Cp>We have a large support team of software developers. That means we have the availability and the skillset to help you with the trickiest of queries.\u003C\u002Fp>\n\u003Cp>We comb the WordPress plugin directory for support tickets daily – most queries are responded to within 24 hours.\u003C\u002Fp>\n\u003Cp>\u003Cem>Excellent plugin with numerous well-thought-out options for making a website more secure. I have been using it for years and am very happy with it. I recently had a small problem setting up a website and – even as a non-premium user – I received support very quickly. Highly recommended!\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>For even more ways to stay safe and secure, upgrade to \u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002Fpricing?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios_premium&utm_creative_format=description\" rel=\"nofollow ugc\">AIOS Premium\u003C\u002Fa> – it packs a punch security-wise, whilst being \u003Cstrong>extremely cost-competitive\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch4>LOGIN SECURITY\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication (TFA)\u003C\u002Fstrong> – Require TFA for specific user roles. Supports Google Authenticator, Microsoft Authenticator, Authy, and many more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detect and manage ‘admin’ usernames\u003C\u002Fstrong> – Identify default ‘admin’ usernames and guide users to change them to protect against brute force attacks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Identify and correct identical login and display names\u003C\u002Fstrong> – Detect cases where the display name matches the username and provide guidance to improve login security.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent user enumeration\u003C\u002Fstrong> – Block unauthorised access to URLs that can reveal sensitive information such as usernames or other details.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control login attempts\u003C\u002Fstrong> – Prevent brute force attacks by limiting the number of failed login attempts. Choose how many login attempts are allowed, set lockout durations, and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Force user logout\u003C\u002Fstrong> – Automatically log out users after a specified period of time. Unattended sessions are closed, reducing the risk of unauthorised access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manually approve new registrations\u003C\u002Fstrong> – Review and approve new user registrations to prevent spam and fake sign-ups.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enhance WordPress salt security\u003C\u002Fstrong> – Adds 64 extra characters to WordPress salts, rotating them weekly. Makes cracking passwords virtually impossible, even if your database is stolen.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002F\u003Cbr \u002F>\n\u003Cstrong>Monitor and manage active sessions\u003C\u002Fstrong> – If a user is logged in who shouldn’t be, log them out or add them to a blacklist.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SPAM PREVENTION\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block spam coming from bots\u003C\u002Fstrong> – Reduce the load on your server and improve the user experience by automatically blocking spam comments from bots.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Monitor spam IP addresses\u003C\u002Fstrong> – Monitor the IP addresses of people or bots leaving spam comments. Choose which ones to block based on a configurable number of comments left.\u003C\u002Fp>\n\u003Ch4>FILE \u002F DATABASE Security\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Scan and fix file permissions\u003C\u002Fstrong> – Scan for insecure file permissions. Click once to fix issues and safeguard critical files and folders.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Disable PHP file editing\u003C\u002Fstrong> – Disable editing of PHP files (such as plugins and themes) via the dashboard. It’s often the first tool that attackers use as it allows for code execution.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Protect sensitive files\u003C\u002Fstrong> – Prevent access to files like readme.html that might reveal information about your WordPress installation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File change scanner\u003C\u002Fstrong> – Get notified of any file changes which occur on your system. Exclude files and folders which change as part of normal operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent image hotlinking\u003C\u002Fstrong> – Prevent other websites from displaying your images via hotlinking and protect server bandwidth.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Secure database backups\u003C\u002Fstrong> – Perform a database backup via UpdraftPlus from AIOS. Change the default ‘wp_’ prefix to hide your WordPress database from hackers.\u003C\u002Fp>\n\u003Ch4>FIREWALL\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Get .htaccess firewall rules\u003C\u002Fstrong> – Deny access to the .htaccess and wp-config.php files. Disable the server signature and limit file uploads to a configurable size.**\u003C\u002Fp>\n\u003Cp>Block access to the debug.log file and prevent Apache servers from listing the contents of a directory when an index.php file is not present\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Get PHP firewall rules\u003C\u002Fstrong> – PHP firewall rules prevent malicious users from exploiting well-known vulnerabilities in XML-RPC. Safeguard your content by disabling RSS and Atom feeds and avoid cross-site scripting (XSS) attacks.\u003Cbr \u002F>\nBlock fake Google bots and POST requests made by bots – Block fake Google bots and stop bots from making POST requests by blocking IP addresses where the user-agent and referrer fields are blank.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Utilise 6G firewall rules\u003C\u002Fstrong> – Employ flexible blacklist rules to reduce the number of malicious URL requests that hit your website (courtesy of Perishable Press).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>And more\u003C\u002Fstrong> – Blacklist (and whitelist) IP ranges and user agents and block unauthorized access to data by disabling REST API access for non-logged-in requests.\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION ENHANCED [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication\u003C\u002Fstrong> is included in the free plugin. Upgrade to Premium if you’d like to:\u003Cbr \u002F>\nRequire TFA after a set time period – Mandate TFA for all admins or other roles after their accounts reach a specified age.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control how often TFA is required\u003C\u002Fstrong> – Set TFA to be required after a certain number of days on trusted devices instead of every login.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Customise design layout\u003C\u002Fstrong> – Adjust the TFA design to match your website’s existing layout and branding.\u003Cbr \u002F>\nEmergency codes – Generate one-time use emergency codes to regain access if you lose your TFA device.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Multisite Compatible\u003C\u002Fstrong> – Ensure compatibility with WordPress multisite networks and their sub-sites for consistent TFA application.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Integration with login forms\u003C\u002Fstrong> – Integrate TFA with various login forms, including WooCommerce, Affiliates-WP, Elementor Pro, bbPress, and ‘Theme My Login’ without additional coding.\u003C\u002Fp>\n\u003Ch4>SMART 404 BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block IPs based on 404 errors\u003C\u002Fstrong> – Detect hackers probing your URLs via script and bots by the 404 errors they leave behind.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 Configuration\u003C\u002Fstrong> – Set a figure for the maximum number of 404 events allowed before an IP address is blocked. Choose a time period within which the 404 events must occur (e.g., 10 errors within 10 minutes).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 block by URL string\u003C\u002Fstrong> – Instantly block an IP address if a 404 event includes a specific URL string.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 whitelisting\u003C\u002Fstrong> – Prevent particular IP addresses from being permanently blocked due to 404 events.\u003C\u002Fp>\n\u003Ch4>COUNTRY BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block traffic to the entire site or to specific pages or posts\u003C\u002Fstrong> – Useful if you’re an e-commerce site and you want to block sales to some countries for shipping or tax reasons.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Whitelist some users from blocked countries\u003C\u002Fstrong> – Whitelist IP addresses or IP ranges even if they are part of a blocked country.\u003C\u002Fp>\n\u003Ch4>MALWARE SCANNING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Automatic malware scanning\u003C\u002Fstrong> – Detect and protect against the latest malware, trojans, and spyware.\u003Cbr \u002F>\nAlerts you to blacklisting by search engines – Monitor your site for blacklisting by search engines due to malicious code.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Response time monitoring\u003C\u002Fstrong> – Keep track of your website’s response time to identify and address any performance issues.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Uptime monitoring\u003C\u002Fstrong> – Checks your website’s uptime every 5 minutes and alerts you immediately if your site or server goes down.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advice and malware removal\u003C\u002Fstrong> – Need hands-on advice and support for malware removal? Our team of genuine cybersecurity experts is here to help.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Notification if something’s amiss\u003C\u002Fstrong> – Receive notifications about any issues with your site so you can address problems before they escalate.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cp>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u003C\u002Fp>\n\u003Ch4>Developers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you are a developer and you need some extra hooks or filters for this plugin then let us know.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Translations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All-In-One Security plugin can be translated to any language.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Currently available translations:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>Hungarian\u003C\u002Fli>\n\u003Cli>Italian\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Chinese\u003C\u002Fli>\n\u003Cli>Portuguese (Brazil)\u003C\u002Fli>\n\u003Cli>Persian\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy Policy\u003C\u002Fh4>\n\u003Cp>This plugin may collect IP addresses for security reasons such as mitigating brute force login threats and malicious activity.\u003C\u002Fp>\n\u003Cp>The collected information is stored on your server. No information is transmitted to third parties or remote server locations.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n","Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.",1000000,37886136,1710,"2026-06-05T06:33:00.000Z","5.6",[105,22,106,56,24],"firewall","malware-scanning","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fall-in-one-wp-security-and-firewall\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fall-in-one-wp-security-and-firewall.5.4.9.zip",75,27,"2026-06-05 11:51:22",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":99,"downloaded":120,"rating":121,"num_ratings":122,"last_updated":123,"tested_up_to":16,"requires_at_least":85,"requires_php":25,"tags":124,"homepage":25,"download_link":126,"security_score":121,"vuln_count":127,"unpatched_count":27,"last_vuln_date":128,"fetched_at":29},"limit-login-attempts-reloaded","Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention","3.3.4","WPChef","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpchefgadget\u002F","\u003Cp>Protect your WordPress website against brute force attacks, bot attacks, and unauthorized login attempts with one of the most trusted login security plugins for WordPress.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\" rel=\"nofollow ugc\">Limit Login Attempts Security\u003C\u002Fa> strengthens your WordPress login security by limiting failed login attempts, blocking malicious IPs, securing wp-login.php, protecting XML-RPC, and adding powerful firewall and 2FA protection without slowing down your website.\u003C\u002Fp>\n\u003Cp>Trusted by 2 million WordPress websites, Limit Login Attempts Security is designed specifically to protect the most targeted part of your website: the login page.\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FS3nf8Zpbcfs?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>Why Use Limit Login Attempts Security?\u003C\u002Fh4>\n\u003Cp>By default, WordPress allows unlimited login attempts. This creates a major security vulnerability where bots and attackers can repeatedly guess usernames and passwords until they gain access. This is especially important in the age of AI, where attackers now have access to faster and more sophisticated tools than ever before.\u003C\u002Fp>\n\u003Cp>Limit Login Attempts Security helps stop:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Brute force attacks\u003C\u002Fli>\n\u003Cli>Bot login attacks\u003C\u002Fli>\n\u003Cli>Credential stuffing attacks\u003C\u002Fli>\n\u003Cli>XML-RPC attacks\u003C\u002Fli>\n\u003Cli>Unauthorized login attempts\u003C\u002Fli>\n\u003Cli>WooCommerce login abuse\u003C\u002Fli>\n\u003Cli>Malicious IP access attempts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin automatically blocks excessive login attempts and locks out suspicious IP addresses and usernames before attackers can gain access.\u003C\u002Fp>\n\u003Ch4>Features Included in the Free Version\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Login Security & Brute Force Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Limit login attempts by IP address and username\u003C\u002Fli>\n\u003Cli>Automatically lock out suspicious login activity\u003C\u002Fli>\n\u003Cli>Adjustable lockout duration and retry limits\u003C\u002Fli>\n\u003Cli>Protect wp-login.php from automated attacks\u003C\u002Fli>\n\u003Cli>Prevent brute force login attacks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>2FA \u002F Multi-Factor Authentication (MFA)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Built-in two-factor authentication (2FA)\u003C\u002Fli>\n\u003Cli>Add an additional layer of login protection\u003C\u002Fli>\n\u003Cli>Improve WordPress account security\u003C\u002Fli>\n\u003Cli>Secure administrator and user logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Firewall & Bot Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Block malicious login requests\u003C\u002Fli>\n\u003Cli>Detect suspicious login behavior\u003C\u002Fli>\n\u003Cli>Reduce bot-based login attacks\u003C\u002Fli>\n\u003Cli>Lightweight firewall-focused login protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>WooCommerce & Plugin Compatibility\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Protects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WooCommerce login pages\u003C\u002Fli>\n\u003Cli>XML-RPC login requests\u003C\u002Fli>\n\u003Cli>Custom login pages\u003C\u002Fli>\n\u003Cli>WordPress multisite installations\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Compatible With:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Wordfence\u003C\u002Fli>\n\u003Cli>Sucuri\u003C\u002Fli>\n\u003Cli>Ultimate Member\u003C\u002Fli>\n\u003Cli>MemberPress\u003C\u002Fli>\n\u003Cli>WPS Hide Login\u003C\u002Fli>\n\u003Cli>Cloudflare and reverse proxy setups\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Login Monitoring & Notifications\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Failed login attempt logs\u003C\u002Fli>\n\u003Cli>Lockout email notifications\u003C\u002Fli>\n\u003Cli>Denied attempt tracking\u003C\u002Fli>\n\u003Cli>Login retry visibility for users\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Access Controls\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>IP safelist and denylist support\u003C\u002Fli>\n\u003Cli>Username safelist and denylist support\u003C\u002Fli>\n\u003Cli>IPv6 range support\u003C\u002Fli>\n\u003Cli>Custom IP origin configuration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Premium Features (Start Your Free 14 Day Trial)\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fplans\u002F\" rel=\"nofollow ugc\">Upgrade to Limit Login Attempts Security Premium\u003C\u002Fa> to extend protection with cloud-based login security and advanced attack prevention.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Cloud Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Real-time malicious IP intelligence\u003C\u002Fli>\n\u003Cli>Global denylist protection\u003C\u002Fli>\n\u003Cli>Synchronized lockouts across websites\u003C\u002Fli>\n\u003Cli>Auto IP denylist generation\u003C\u002Fli>\n\u003Cli>Cloud-based login attack mitigation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Enhanced Performance Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Offload excessive failed login requests from your server\u003C\u002Fli>\n\u003Cli>Reduce server strain during attacks\u003C\u002Fli>\n\u003Cli>Improve stability under heavy attack conditions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced Security Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Country-based login blocking\u003C\u002Fli>\n\u003Cli>Enhanced throttling and lockout escalation\u003C\u002Fli>\n\u003Cli>Registration page protection\u003C\u002Fli>\n\u003Cli>Successful login tracking\u003C\u002Fli>\n\u003Cli>Enhanced lockout analytics and geolocation data\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Multi-Site & Team Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Shared safelist and denylist syncing\u003C\u002Fli>\n\u003Cli>Shared lockout protection between domains\u003C\u002Fli>\n\u003Cli>Cloud backups of IP security data\u003C\u002Fli>\n\u003Cli>CSV exports of login and IP activity\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Premium Support\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Access to security-focused support specialists\u003C\u002Fli>\n\u003Cli>Faster troubleshooting and assistance\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Lightweight Security Built for WordPress\u003C\u002Fh4>\n\u003Cp>Unlike many large security suites, Limit Login Attempts Security focuses specifically on login security and brute force protection.\u003C\u002Fp>\n\u003Cp>This means:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Faster performance\u003C\u002Fli>\n\u003Cli>Less server overhead\u003C\u002Fli>\n\u003Cli>Easier configuration\u003C\u002Fli>\n\u003Cli>Strong protection without unnecessary bloat\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Protect More Than Just wp-login.php\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Security secures:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>wp-login.php\u003C\u002Fli>\n\u003Cli>XML-RPC\u003C\u002Fli>\n\u003Cli>WooCommerce logins\u003C\u002Fli>\n\u003Cli>Custom login forms\u003C\u002Fli>\n\u003Cli>Registration pages\u003C\u002Fli>\n\u003Cli>Multisite logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Trusted by Millions of WordPress Websites\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Security is one of the most widely used WordPress login security plugins and has helped protect millions of websites from brute force attacks and malicious login activity.\u003C\u002Fp>\n\u003Cp>Whether you run:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>A personal blog\u003C\u002Fli>\n\u003Cli>WooCommerce store\u003C\u002Fli>\n\u003Cli>Membership website\u003C\u002Fli>\n\u003Cli>Agency\u003C\u002Fli>\n\u003Cli>Business website\u003C\u002Fli>\n\u003Cli>Enterprise WordPress network\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Limit Login Attempts Security helps secure your login experience with modern WordPress login protection.\u003C\u002Fp>\n\u003Ch4>Upgrading from the Original Limit Login Attempts Plugin?\u003C\u002Fh4>\n\u003Cp>Switching is easy:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Remove the old Limit Login Attempts plugin\u003C\u002Fli>\n\u003Cli>Install Limit Login Attempts Security\u003C\u002Fli>\n\u003Cli>Your settings will remain intact\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Translation Support\u003C\u002Fh4>\n\u003Cp>Currently translated into multiple languages including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Dutch\u003C\u002Fli>\n\u003Cli>Turkish\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Romanian\u003C\u002Fli>\n\u003Cli>Chinese (Traditional)\u003C\u002Fli>\n\u003Cli>Brazilian Portuguese\u003C\u002Fli>\n\u003Cli>And more\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Secure Your WordPress Login Today\u003C\u002Fh4>\n\u003Cp>Install Limit Login Attempts Security and protect your WordPress website with:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Login security\u003C\u002Fli>\n\u003Cli>Two-Factor Authentication (2FA)\u003C\u002Fli>\n\u003Cli>Brute force protection\u003C\u002Fli>\n\u003Cli>Firewall security\u003C\u002Fli>\n\u003Cli>Bot protection\u003C\u002Fli>\n\u003Cli>XML-RPC protection\u003C\u002Fli>\n\u003Cli>WooCommerce login protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Without slowing down your website.\u003C\u002Fp>\n","WordPress login security with brute force protection, Two-factor authentication (2FA\u002FMFA), firewall, IP\u002Fcountry blocking, and login monitoring",91831747,98,1468,"2026-07-08T11:06:00.000Z",[20,125,105,22,56],"brute-force","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flimit-login-attempts-reloaded.3.3.4.zip",4,"2023-12-20 00:00:00",{"error":130,"url":131,"statusCode":132,"statusMessage":133,"message":133},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Floginarmor-email-2fa\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":135,"versions":136},3,[137,143,150],{"version":6,"download_url":26,"svn_tag_url":138,"released_at":28,"has_diff":139,"diff_files_changed":140,"diff_lines":28,"trac_diff_url":141,"vulnerabilities":142,"is_current":130},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Floginarmor-email-2fa\u002Ftags\u002F1.2\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Floginarmor-email-2fa%2Ftags%2F1.1&new_path=%2Floginarmor-email-2fa%2Ftags%2F1.2",[],{"version":144,"download_url":145,"svn_tag_url":146,"released_at":28,"has_diff":139,"diff_files_changed":147,"diff_lines":28,"trac_diff_url":148,"vulnerabilities":149,"is_current":139},"1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Floginarmor-email-2fa.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Floginarmor-email-2fa\u002Ftags\u002F1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Floginarmor-email-2fa%2Ftags%2F1.0&new_path=%2Floginarmor-email-2fa%2Ftags%2F1.1",[],{"version":151,"download_url":152,"svn_tag_url":153,"released_at":28,"has_diff":139,"diff_files_changed":154,"diff_lines":28,"trac_diff_url":28,"vulnerabilities":155,"is_current":139},"1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Floginarmor-email-2fa.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Floginarmor-email-2fa\u002Ftags\u002F1.0\u002F",[],[]]