WP Login Attempts
WP login attempts is a security plugin which can add Google reCAPTCHA to the WordPress login page, and protect the site from brute force attacks. Brute Force Attack tries usernames and passwords over and over again…
Consider an alternative
WP Login Attempts shows warning signs in 2026 — compare the alternatives below before installing. It runs on 300+ sites, is rated 4/5 and was last updated 1 year ago, and scores 39/100 on our health check.
- Small user base (300+ active installs)
- Very few reviews so far
- No update in over a year
- Only tested up to WordPress 6.8 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where WP Login Attempts stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| Login Attempts | #45 |
| Login Authentication | >100 |
| login limit | #93 |
| login link | >100 |
| login recaptcha | #86 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 4 from 4 reviews
About WP Login Attempts
From the official readme · v5.5Description
WP login attempts is a security plugin which can add Google reCAPTCHA to the WordPress login page, and protect the site from brute force attacks. Brute Force Attack tries usernames and passwords over and over again, until it gets in. WP Login Attempts limit rate of login attempts and blocks IP temporarily. It detects bots by captcha verification.
This plugin supports Google reCAPTCHA Version 2 and Version 3. Also, you can monitor failed login attempts and error logs.
WP login attempts plugin gives you the ability to change the URL of the login page to anything you want. This plugin restricts access to the wp-admin and wp-login.php page, so you can bookmark or remember the URL for future. Deactivating this plugin brings your site back exactly to the state it was before.
WP login attempts is a very lightweight plugin that lets you customize your WordPress admin login page easily and safely. This plugin allows you to change the background colour, background image, custom logo, logo Link, hide your password on the form and many more features through custom CSS.
Features
Allows the maximum number of attempts to the login page
Notify the user about remaining retries or lockout time on the login page
Monitor error Logs and email notifications
Disable the limit login feature without disabling the plugin
Google reCAPTCHA v2
Google reCAPTCHA v3
Hides wp-login.php, wp-admin directory and blocks access
Allows you to rename login URL
Custom Logo in the login form
Background Color and Background image on the login form page
Here’s a link to the documentation for the plugin. This will help you learn more about its features and how to use it.
Documentation
For any feedback or queries regarding this plugin, please contact our Support team.
Installation
- Download and extract plugin files to a wp-content/plugin directory.
- Activate the plugin through the Plugins menu in the WordPress admin.
- The page will redirect you to the settings or go to the under Setting menu -> WP Login Attempts sub menu page.
Frequently asked questions
I locked myself out testing maximum login attempts, what do I do?
Either wait or: If you have FTP / ssh access to the site rename the file “wp-content/plugins/wp-login-attempts” to deactivate the plugin. If you have access to the database (for example through phpMyAdmin) you can clear the wla_lim_lockouts_cal option in the wordpress options table. In a default setup this would work: “UPDATE wp_options SET option_value = ” WHERE option_name = ‘wla_lim_lockouts_cal'”
Why am I seeing, “Please wait 20 minutes” error message when I try to login?
You’ve tried to log in with the wrong password or username more than four times. Please wait for 20 minutes, then reset the password by clicking “Lost your password” link.
I forgot my login URL?
Either go to your MySQL database and look for the value of wla_lim_hide_login_page in the options table or remove the wp-login-attempts folder from your plugins folder, log in through wp-login.php and reinstall the plugin.
Is it working in localhost?
Yes, It will work on your local machine also.
How to get Google reCAPTCHA Site Key and Secret Key?
1] To get the Site Key and Secret Key, go to the Google reCAPTCHA Admin Console. URL: https://www.google.com/recaptcha/admin#list 2] Sign into your Google account to proceed to the reCAPTCHA dashboard. 3] After Sign in, you will be redirected to your Google reCAPTCHA dashboard. 4] Now, you will need to provide your domain (website URL) and specify the reCAPTCHA version to create Site Key and Secret Key. 5] You can also read our Step-by-Step Instructions in Detail.
Captcha image is not working, How to solve it?
Go to the reCaptcha setting and click the Get the API key link. once you create a new key from google admin console [ https://www.google.com/recaptcha/admin#list ] please don’t forget to add your domain/site. Copy the Site and Secret key and paste them in our Google reCaptcha setting page.
Can we disable the login limit feature without disabling the plugin?
Yes, there is an option to disable in the plugin attempts settings menu.
Changelog
Stable Release
5.5
Stable Release
5.4
Stable Release
5.3
Stable Release
5.2
Stable Release
5.1
Stable Release
5.0
Second Stable Release
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best WP Login Attempts alternatives
All Login Attempts plugins →FAQ
WP Login Attempts: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 30, 2026
Is WP Login Attempts free?
Yes. WP Login Attempts is free to download and use from the official WordPress.org plugin directory.
Is WP Login Attempts safe to use in 2026?
WP Login Attempts shows warning signs in 2026 — compare the alternatives below before installing. It runs on 300+ sites, is rated 4/5 and was last updated 1 year ago, and scores 39/100 on our health check.
How many websites use WP Login Attempts?
WP Login Attempts is active on 300+ WordPress websites and has been downloaded 5,675 times since it launched in December 2019. It was downloaded 111 times in the last 30 days.
Does WP Login Attempts work with WordPress 7.1?
WP Login Attempts is officially tested up to WordPress 6.8.10, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does WP Login Attempts need?
WP Login Attempts requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was WP Login Attempts last updated?
The latest version, 5.5, was released on April 30, 2025 (1 year ago).
Who makes WP Login Attempts?
WP Login Attempts is developed and maintained by Galaxy Weblinks.
What are the best alternatives to WP Login Attempts?
The most popular alternatives to WP Login Attempts are Limit Login Attempts (Spam… (200+ installs), Jeba Limit Login Attempts (90+ installs) and Simple Login Guard (10+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card








