BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
eSherpa Login Guard icon
Maintained Tested up to 6.9.10 #46 in bot protection

eSherpa Login Guard

Intelligent login protection with honeypot detection, WordPress hardening, and a clear security admin overview.

Active installs<10New
Downloads · 30d59▲ +78.8% vs prev. 30d
Rating—0 reviews
Health score36/100At risk
All-time downloads494Since Dec 2025
Support resolved—No recent threads
RequiresWP 5.6PHP 7.4+
Downloads · 7d11▼ -26.7% week over week
Our verdict

Consider an alternative

eSherpa Login Guard shows warning signs in 2026 — compare the alternatives below before installing. Was last updated 7 months ago, and scores 36/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far
  • Only tested up to WordPress 6.9 (latest is 7.1)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

135Jul 12Aug 25Oct 9
Yesterday2
Daily average (1y)2
Peak day23Mar 3, 2026
Last 12 months500

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where eSherpa Login Guard stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
bot protection >100 1,226 Best bot protection plugins →
brute force protection >100 487 Best brute force protection plugins →
honeypot >100 824 Best honeypot plugins →
login security >100 4,268 Best login security plugins →
wordpress hardening >100 2,195 Best wordpress hardening plugins →

About eSherpa Login Guard

From the official readme · v3.0.0

Description

eSherpa Login Guard effectively and intelligently protects your WordPress site from brute-force attacks – Swiss precision, completely without external dependencies.

Key Features:

  • Honeypot-first bot defense: JavaScript Honeypot detects non-browser bots and triggers immediate lockout logic.
  • Protected username trap: Immediate lockout for defined usernames (e.g., “admin”, “test”), independent of the regular counter.
  • Proactive User-Agent blocking: Block known bot signatures before login processing (exact match or substring mode).
  • Blocked User-Agent attempt log: Separate log table for blocked User-Agent requests including matching pattern.
  • WordPress hardening options: Disable XML-RPC (with fake-user honeypot response), hide REST user endpoint, and block author archive enumeration.
  • Optional bot password capture: Store attempted passwords from detected JS-honeypot bots for incident analysis.
  • Neutral login error option: Hide username enumeration by using neutral WordPress login error responses.
  • Live security visibility: Live alarm in admin, lockout badge in menu, and detailed failed-attempt logs with IP/User-Agent filters.
  • Progressive lockout durations: Lockout time increases on repeat offenses (e.g., 15 → 30 → 60 → 120 minutes).
  • Login page guidance: Clear countdown and “X attempts remaining” notice for transparent lock state.
  • Privacy-compliant: IPs stored only as anonymized hashes.
  • Automatic cleanup of old failed attempts (configurable).
  • Mobile-friendly admin tables: Horizontal scrolling for wide security tables on small screens, including swipe hint.
  • Email notification to admin on attacks against existing users.

Developed in Switzerland – fast, clean, performant, and multilingual ready.

Compatible with WordPress 6.9 and tested up to PHP 8.5.3.

Installation

  1. Search for the plugin in “Plugins → Add New → ‘esherpa login guard'” or upload and activate.
  2. Optional: Adjust settings under “Login Guard” in the admin menu (e.g., max failed attempts, base lockout time, protected usernames).
  3. Done – protection runs automatically.

Frequently asked questions

How are IPs stored?

Only as anonymized MD5 hashes – no plain-text IPs in the database (GDPR-compliant).

Can I manually unblock IPs?

Yes – directly in the admin overview with one click (counter is reset).

Does it work with caching plugins?

Yes – protection hooks early on wp-login.php, before caching.

What happens on successful login?

All counters and locks for that IP are immediately cleared.

Can I still use XML-RPC?

Yes – simply disable the option. When enabled, XML-RPC is fully disabled and a honeypot is activated.

Changelog

Simply update – all settings are preserved. New features are available immediately.

3.0.0

  • Release: Version bump to 3.0.0 for the current major feature set.
  • UI (Mobile): Admin log tables are now horizontally scrollable on small screens.
  • UI (Mobile): Added a visible swipe/scroll hint for wide tables.
  • UI: Reduced “blocked User-Agent attempts” list in admin overview from 50 to 20 entries for better readability.
  • Docs: Expanded README feature list (proactive User-Agent blocking, blocked-UA logs, neutral login errors, bot password capture, mobile table UX).

2.7.0

  • Feature: JavaScript Honeypot for automatic bot detection with progressive lockout (like protected usernames)
  • UI: Visual bot indicators (🤖 emoji) in both locked IPs and failed attempts tables
  • UI: Clickable User-Agent filtering in all log tables (like IP filtering) – optimized display to 100 chars
  • Security: Enhanced bot detection combining multiple methods
  • Fix: XML-RPC Honeypot now generates properly formatted XML without double-escaping

2.6.0

  • Security: Fixed critical IP address handling vulnerability – now properly supports proxy headers
  • Feature: Added comprehensive User-Agent logging to all login attempts and successful logins
  • Feature: Added JavaScript Honeypot for automatic bot detection (1-hour lockout)
  • Performance: Optimized admin menu badge query with caching
  • Security: Enhanced input validation with reasonable limits on all settings
  • UI: Visual bot indicators in admin tables with 🤖 emoji
  • Code: Improved code formatting and consistency throughout

2.5.4

  • Fix: Immediate lockout for protected usernames (honeypot usernames) was setting back attemts and multipliers
  • Sort by IP -> Better overview for single IP hashs.
  • Improved design for mobile

2.5.1

  • Immediate lockout for protected usernames (honeypot usernames)
  • Live alarm for new failed attempts on admin page
  • Email notification on attacks against existing users
  • Extended XML-RPC honeypot with configurable fake users
  • Automatic cleanup of old failed attempts
  • Improved design and many detail enhancements

2.1.1

  • Full multilingual support (DE/EN/FR/IT)
  • Confirmed compatibility with WordPress 6.9 and PHP 8.3
  • Minor optimizations

Full changelog on WordPress.org →

Screenshots

Lockout message with large countdown and plugin credit
Lockout message with large countdown and plugin credit
Early warning on login page with remaining attempts
Early warning on login page with remaining attempts
Admin overview with currently locked IPs, live alarm, and unblock option
Admin overview with currently locked IPs, live alarm, and unblock option
Detailed logs of failed attempts (including attempted username)
Detailed logs of failed attempts (including attempted username)
Successful logins & logouts in separate view
Successful logins & logouts in separate view

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best eSherpa Login Guard alternatives

All bot protection plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 ClickCease Click Fraud Protection ClickCease Click Fraud Protection Protect your website and ad campaigns from bots, competitors, and click fraud with… by eranfl 10K+ ★★★★★★★★★★ 3 (8) 5 months ago 49
2 CHEQ Essentials CHEQ Essentials Protect, analyze & block threats in real time your website from bots, click fraud, and… by eranfl 600+ ★★★★★★★★★★ No reviews 5 months ago 42
3 Checkout Shield for WooCommerce – Stop Fake Orders, Spam Bots & Card Testing Checkout Shield for WooCommerce Blocks scripted checkout attempts that never loaded your checkout page, including card… by carticy 300+ ★★★★★★★★★★ 5 (5) 1 month ago 81
4 Spambargo: Anti-Spam for Forms & Comments Spambargo: Anti-Spam for Forms & Comments Block spam in Elementor, Contact Form 7, JetFormBuilder, Ninja Forms, WooCommerce and… by Aviv Digital 100+ ★★★★★★★★★★ No reviews 2 months ago 59
5 Cloud Maestro – WAF Security Suite for Cloudflare Cloud Maestro – WAF Security Suite for Cloudflare Bulk deploy powerful WAF security rules to multiple Cloudflare domains with one click… by 5 Star Plugins (Rob) 80+ ★★★★★★★★★★ 5 (4) 1 month ago 75
6 HSArticle Math CAPTCHA for Forms HSArticle Math CAPTCHA for Forms Math CAPTCHA for CF7, WPForms, and any HTML form. Zero config — install, add shortcode or… by hsarticle 50+ ★★★★★★★★★★ No reviews 4 weeks ago 68
7 Botfaqtor Code Botfaqtor Code Интеграция сервиса Botfaqtor для защиты сайта от ботов. by botfaqtor 50+ ★★★★★★★★★★ No reviews 1 year ago 28
8 TrustCaptcha TrustCaptcha Privacy-friendly CAPTCHA solution with bot score. Protect your website from bot attacks and… by trustcaptcha 40+ ★★★★★★★★★★ No reviews 5 months ago 45
9 HSArticle Login Math Verification HSArticle Login Math Verification Adds a beautiful math CAPTCHA to the WordPress login page. No API keys, no paid services —… by hsarticle 40+ ★★★★★★★★★★ 5 (1) 4 weeks ago 74
10 WindCodex ScraperBlock – Block AI Scrapers & Bots from WordPress & WooCommerce WindCodex ScraperBlock Block AI scrapers, price bots, and content theft from your WordPress & WooCommerce site… by WindCodex 40+ ★★★★★★★★★★ No reviews 2 weeks ago 62

FAQ

eSherpa Login Guard: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 10, 2026

Is eSherpa Login Guard free?

Yes. eSherpa Login Guard is free to download and use from the official WordPress.org plugin directory.

Is eSherpa Login Guard safe to use in 2026?

eSherpa Login Guard shows warning signs in 2026 — compare the alternatives below before installing. Was last updated 7 months ago, and scores 36/100 on our health check.

How many websites use eSherpa Login Guard?

eSherpa Login Guard is active on <10 WordPress websites and has been downloaded 494 times since it launched in December 2025. It was downloaded 59 times in the last 30 days.

Does eSherpa Login Guard work with WordPress 7.1?

eSherpa Login Guard is officially tested up to WordPress 6.9.10, while the latest release is 7.1.3. It may still work, but try it on a staging site first.

What PHP version does eSherpa Login Guard need?

eSherpa Login Guard requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was eSherpa Login Guard last updated?

The latest version, 3.0.0, was released on March 3, 2026 (7 months ago).

Who makes eSherpa Login Guard?

eSherpa Login Guard is developed and maintained by Ralf Naumann.

What are the best alternatives to eSherpa Login Guard?

The most popular alternatives to eSherpa Login Guard are ClickCease Click Fraud Prot… (10K+ installs), CHEQ Essentials (600+ installs) and Checkout Shield for WooComm… (300+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.