BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
WP Login Attempts icon
Slowing down Tested up to 6.8.10 #1 in Login Attempts

WP Login Attempts

WP login attempts is a security plugin which can add Google reCAPTCHA to the WordPress login page, and protect the site from brute force attacks. Brute Force Attack tries usernames and passwords over and over again…

Active installs300+100+ tier
Downloads · 30d111▲ +12.1% vs prev. 30d
Rating4/54 reviews
Health score39/100At risk
All-time downloads5.7KSince Dec 2019
Support resolved—No recent threads
RequiresWP 4.5PHP 7.4+
Downloads · 7d26▼ -31.6% week over week
Our verdict

Consider an alternative

WP Login Attempts shows warning signs in 2026 — compare the alternatives below before installing. It runs on 300+ sites, is rated 4/5 and was last updated 1 year ago, and scores 39/100 on our health check.

  • Small user base (300+ active installs)
  • Very few reviews so far
  • No update in over a year
  • Only tested up to WordPress 6.8 (latest is 7.1)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

369Jul 2Aug 15Sep 29
Yesterday4
Daily average (1y)2
Peak day21Apr 8, 2026
Last 12 months879

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where WP Login Attempts stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
Login Attempts #45 1,202 Best Login Attempts plugins →
Login Authentication >100 1,785 Best Login Authentication plugins →
login limit #93 2,235 Best login limit plugins →
login link >100 4,906 Best login link plugins →
login recaptcha #86 603 Best login recaptcha plugins →

Version adoption

Share of active sites per release.

  • 5.578.4%
  • 5.115.5%
  • 5.26.1%

Rating breakdown

★★★★★★★★★★ 4 from 4 reviews

  • 5★75.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★25.0%

About WP Login Attempts

From the official readme · v5.5

Description

WP login attempts is a security plugin which can add Google reCAPTCHA to the WordPress login page, and protect the site from brute force attacks. Brute Force Attack tries usernames and passwords over and over again, until it gets in. WP Login Attempts limit rate of login attempts and blocks IP temporarily. It detects bots by captcha verification.

This plugin supports Google reCAPTCHA Version 2 and Version 3. Also, you can monitor failed login attempts and error logs.

WP login attempts plugin gives you the ability to change the URL of the login page to anything you want. This plugin restricts access to the wp-admin and wp-login.php page, so you can bookmark or remember the URL for future. Deactivating this plugin brings your site back exactly to the state it was before.

WP login attempts is a very lightweight plugin that lets you customize your WordPress admin login page easily and safely. This plugin allows you to change the background colour, background image, custom logo, logo Link, hide your password on the form and many more features through custom CSS.

Features

Allows the maximum number of attempts to the login page
Notify the user about remaining retries or lockout time on the login page
Monitor error Logs and email notifications
Disable the limit login feature without disabling the plugin
Google reCAPTCHA v2
Google reCAPTCHA v3
Hides wp-login.php, wp-admin directory and blocks access
Allows you to rename login URL
Custom Logo in the login form
Background Color and Background image on the login form page

Here’s a link to the documentation for the plugin. This will help you learn more about its features and how to use it.
Documentation
For any feedback or queries regarding this plugin, please contact our Support team.

Installation

  1. Download and extract plugin files to a wp-content/plugin directory.
  2. Activate the plugin through the Plugins menu in the WordPress admin.
  3. The page will redirect you to the settings or go to the under Setting menu -> WP Login Attempts sub menu page.

Frequently asked questions

I locked myself out testing maximum login attempts, what do I do?

Either wait or: If you have FTP / ssh access to the site rename the file “wp-content/plugins/wp-login-attempts” to deactivate the plugin. If you have access to the database (for example through phpMyAdmin) you can clear the wla_lim_lockouts_cal option in the wordpress options table. In a default setup this would work: “UPDATE wp_options SET option_value = ” WHERE option_name = ‘wla_lim_lockouts_cal'”

Why am I seeing, “Please wait 20 minutes” error message when I try to login?

You’ve tried to log in with the wrong password or username more than four times. Please wait for 20 minutes, then reset the password by clicking “Lost your password” link.

I forgot my login URL?

Either go to your MySQL database and look for the value of wla_lim_hide_login_page in the options table or remove the wp-login-attempts folder from your plugins folder, log in through wp-login.php and reinstall the plugin.

Is it working in localhost?

Yes, It will work on your local machine also.

How to get Google reCAPTCHA Site Key and Secret Key?

1] To get the Site Key and Secret Key, go to the Google reCAPTCHA Admin Console. URL: https://www.google.com/recaptcha/admin#list 2] Sign into your Google account to proceed to the reCAPTCHA dashboard. 3] After Sign in, you will be redirected to your Google reCAPTCHA dashboard. 4] Now, you will need to provide your domain (website URL) and specify the reCAPTCHA version to create Site Key and Secret Key. 5] You can also read our Step-by-Step Instructions in Detail.

Captcha image is not working, How to solve it?

Go to the reCaptcha setting and click the Get the API key link. once you create a new key from google admin console [ https://www.google.com/recaptcha/admin#list ] please don’t forget to add your domain/site. Copy the Site and Secret key and paste them in our Google reCaptcha setting page.

Can we disable the login limit feature without disabling the plugin?

Yes, there is an option to disable in the plugin attempts settings menu.

Changelog

Stable Release

5.5

Stable Release

5.4

Stable Release

5.3

Stable Release

5.2

Stable Release

5.1

Stable Release

5.0

Second Stable Release

Full changelog on WordPress.org →

Screenshots

Required reCAPTCHA enable
Required reCAPTCHA enable
Too many logins failed attempts.
Too many logins failed attempts.
Google ReCaptcha version 2
Google ReCaptcha version 2
Google ReCaptcha version 3
Google ReCaptcha version 3
Login attempts setting page
Login attempts setting page
reCaptcha setting page
reCaptcha setting page
Lockout logs
Lockout logs
Statistics
Statistics
Login page design
Login page design

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best WP Login Attempts alternatives

All Login Attempts plugins →

FAQ

WP Login Attempts: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 30, 2026

Is WP Login Attempts free?

Yes. WP Login Attempts is free to download and use from the official WordPress.org plugin directory.

Is WP Login Attempts safe to use in 2026?

WP Login Attempts shows warning signs in 2026 — compare the alternatives below before installing. It runs on 300+ sites, is rated 4/5 and was last updated 1 year ago, and scores 39/100 on our health check.

How many websites use WP Login Attempts?

WP Login Attempts is active on 300+ WordPress websites and has been downloaded 5,675 times since it launched in December 2019. It was downloaded 111 times in the last 30 days.

Does WP Login Attempts work with WordPress 7.1?

WP Login Attempts is officially tested up to WordPress 6.8.10, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does WP Login Attempts need?

WP Login Attempts requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was WP Login Attempts last updated?

The latest version, 5.5, was released on April 30, 2025 (1 year ago).

Who makes WP Login Attempts?

WP Login Attempts is developed and maintained by Galaxy Weblinks.

What are the best alternatives to WP Login Attempts?

The most popular alternatives to WP Login Attempts are Limit Login Attempts (Spam… (200+ installs), Jeba Limit Login Attempts (90+ installs) and Simple Login Guard (10+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.