eSherpa Login Guard
Intelligent login protection with honeypot detection, WordPress hardening, and a clear security admin overview.
Consider an alternative
eSherpa Login Guard shows warning signs in 2026 — compare the alternatives below before installing. Was last updated 7 months ago, and scores 36/100 on our health check.
- Small user base (<10 active installs)
- Very few reviews so far
- Only tested up to WordPress 6.9 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where eSherpa Login Guard stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| bot protection | >100 |
| brute force protection | >100 |
| honeypot | >100 |
| login security | >100 |
| wordpress hardening | >100 |
About eSherpa Login Guard
From the official readme · v3.0.0Description
eSherpa Login Guard effectively and intelligently protects your WordPress site from brute-force attacks – Swiss precision, completely without external dependencies.
Key Features:
- Honeypot-first bot defense: JavaScript Honeypot detects non-browser bots and triggers immediate lockout logic.
- Protected username trap: Immediate lockout for defined usernames (e.g., “admin”, “test”), independent of the regular counter.
- Proactive User-Agent blocking: Block known bot signatures before login processing (exact match or substring mode).
- Blocked User-Agent attempt log: Separate log table for blocked User-Agent requests including matching pattern.
- WordPress hardening options: Disable XML-RPC (with fake-user honeypot response), hide REST user endpoint, and block author archive enumeration.
- Optional bot password capture: Store attempted passwords from detected JS-honeypot bots for incident analysis.
- Neutral login error option: Hide username enumeration by using neutral WordPress login error responses.
- Live security visibility: Live alarm in admin, lockout badge in menu, and detailed failed-attempt logs with IP/User-Agent filters.
- Progressive lockout durations: Lockout time increases on repeat offenses (e.g., 15 → 30 → 60 → 120 minutes).
- Login page guidance: Clear countdown and “X attempts remaining” notice for transparent lock state.
- Privacy-compliant: IPs stored only as anonymized hashes.
- Automatic cleanup of old failed attempts (configurable).
- Mobile-friendly admin tables: Horizontal scrolling for wide security tables on small screens, including swipe hint.
- Email notification to admin on attacks against existing users.
Developed in Switzerland – fast, clean, performant, and multilingual ready.
Compatible with WordPress 6.9 and tested up to PHP 8.5.3.
Installation
- Search for the plugin in “Plugins → Add New → ‘esherpa login guard'” or upload and activate.
- Optional: Adjust settings under “Login Guard” in the admin menu (e.g., max failed attempts, base lockout time, protected usernames).
- Done – protection runs automatically.
Frequently asked questions
How are IPs stored?
Only as anonymized MD5 hashes – no plain-text IPs in the database (GDPR-compliant).
Can I manually unblock IPs?
Yes – directly in the admin overview with one click (counter is reset).
Does it work with caching plugins?
Yes – protection hooks early on wp-login.php, before caching.
What happens on successful login?
All counters and locks for that IP are immediately cleared.
Can I still use XML-RPC?
Yes – simply disable the option. When enabled, XML-RPC is fully disabled and a honeypot is activated.
Changelog
Simply update – all settings are preserved. New features are available immediately.
3.0.0
- Release: Version bump to 3.0.0 for the current major feature set.
- UI (Mobile): Admin log tables are now horizontally scrollable on small screens.
- UI (Mobile): Added a visible swipe/scroll hint for wide tables.
- UI: Reduced “blocked User-Agent attempts” list in admin overview from 50 to 20 entries for better readability.
- Docs: Expanded README feature list (proactive User-Agent blocking, blocked-UA logs, neutral login errors, bot password capture, mobile table UX).
2.7.0
- Feature: JavaScript Honeypot for automatic bot detection with progressive lockout (like protected usernames)
- UI: Visual bot indicators (🤖 emoji) in both locked IPs and failed attempts tables
- UI: Clickable User-Agent filtering in all log tables (like IP filtering) – optimized display to 100 chars
- Security: Enhanced bot detection combining multiple methods
- Fix: XML-RPC Honeypot now generates properly formatted XML without double-escaping
2.6.0
- Security: Fixed critical IP address handling vulnerability – now properly supports proxy headers
- Feature: Added comprehensive User-Agent logging to all login attempts and successful logins
- Feature: Added JavaScript Honeypot for automatic bot detection (1-hour lockout)
- Performance: Optimized admin menu badge query with caching
- Security: Enhanced input validation with reasonable limits on all settings
- UI: Visual bot indicators in admin tables with 🤖 emoji
- Code: Improved code formatting and consistency throughout
2.5.4
- Fix: Immediate lockout for protected usernames (honeypot usernames) was setting back attemts and multipliers
- Sort by IP -> Better overview for single IP hashs.
- Improved design for mobile
2.5.1
- Immediate lockout for protected usernames (honeypot usernames)
- Live alarm for new failed attempts on admin page
- Email notification on attacks against existing users
- Extended XML-RPC honeypot with configurable fake users
- Automatic cleanup of old failed attempts
- Improved design and many detail enhancements
2.1.1
- Full multilingual support (DE/EN/FR/IT)
- Confirmed compatibility with WordPress 6.9 and PHP 8.3
- Minor optimizations
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best eSherpa Login Guard alternatives
All bot protection plugins →FAQ
eSherpa Login Guard: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 10, 2026
Is eSherpa Login Guard free?
Yes. eSherpa Login Guard is free to download and use from the official WordPress.org plugin directory.
Is eSherpa Login Guard safe to use in 2026?
eSherpa Login Guard shows warning signs in 2026 — compare the alternatives below before installing. Was last updated 7 months ago, and scores 36/100 on our health check.
How many websites use eSherpa Login Guard?
eSherpa Login Guard is active on <10 WordPress websites and has been downloaded 494 times since it launched in December 2025. It was downloaded 59 times in the last 30 days.
Does eSherpa Login Guard work with WordPress 7.1?
eSherpa Login Guard is officially tested up to WordPress 6.9.10, while the latest release is 7.1.3. It may still work, but try it on a staging site first.
What PHP version does eSherpa Login Guard need?
eSherpa Login Guard requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was eSherpa Login Guard last updated?
The latest version, 3.0.0, was released on March 3, 2026 (7 months ago).
Who makes eSherpa Login Guard?
eSherpa Login Guard is developed and maintained by Ralf Naumann.
What are the best alternatives to eSherpa Login Guard?
The most popular alternatives to eSherpa Login Guard are ClickCease Click Fraud Prot… (10K+ installs), CHEQ Essentials (600+ installs) and Checkout Shield for WooComm… (300+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card




