[WordPress] 外掛分享: DadsFam Login Security

首頁外掛目錄 › DadsFam Login Security
WordPress 外掛 DadsFam Login Security 的封面圖片
全新外掛
安裝啟用
尚無評分
剛更新
最後更新
問題解決
WordPress 6.0+ PHP 7.4+ v1.7.1 上架:2026-09-15

內容簡介

DadsFam Login Security 是一款專為保護 WordPress 登入表單而設計的外掛,能有效防止暴力破解攻擊,無需繁瑣的設定或手動操作。它提供即時監控、鎖定攻擊者及詳細的登入活動紀錄,確保網站安全。

【主要功能】
• 智能暴力破解鎖定功能
• IP 允許與拒絕名單
• 完整登入活動紀錄
• 實時儀表板顯示
• 電子郵件警報通知
• 蜜罐機制捕捉機器人

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.7.1) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「DadsFam Login Security」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

DadsFam Login Security protects the most-attacked part of your WordPress site — the login form — without making you read a manual or fiddle with servers.
Everything described below works on every site. Nothing is disabled, blurred out, time-limited or reduced.
It watches failed logins, locks out attackers automatically, escalates repeat offenders to a longer ban, and keeps a clean log of everything so you can see exactly what’s hitting your site.
What you get (free)

Smart brute-force lockouts — set how many tries are allowed and how long the lockout lasts. Repeat offenders get an automatic extended ban.
IP allow & deny lists — exact IPs, wildcards (1.2.3.*) and CIDR ranges (1.2.3.0/24). IPv4 and IPv6.
Full login activity log — every failed login, success, lockout and block, with IP, username and device. Searchable, filterable, auto-pruned.
Live dashboard — failed-login stats, a 14-day chart, top attacking IPs, and who’s locked out right now (with one-click unblock).
Email alerts — get a tidy, throttled email when a lockout triggers.
Generic login errors — stop attackers learning whether a username exists.
Honeypot bot trap — an invisible field that catches dumb bots.
Hardening — block user enumeration (?author=N and the REST API), kill XML-RPC pingback amplification, or disable XML-RPC entirely.

Pro Features (DadsFam Login Security Pro add-on)
The optional DadsFam Login Security Pro add-on plugs into the same screens and adds two-factor authentication (authenticator apps and email codes, with backup codes and trusted devices), CAPTCHA on the login form (Google reCAPTCHA, hCaptcha, Cloudflare Turnstile or a built-in maths question), a custom hidden login address, a branded login screen, strong-password and breached-password checks, idle auto-logout, scheduled security reports, and country blocking.
A word about PRO
Right, let me be straight with you, because I hate being sold to as much as you do.
Everything above is free and it stays free. The lockouts, the allow and deny lists, the activity log, the live dashboard, the email alerts, the bot traps and the hardening — none of those are premium features. Those are the things a login-security plugin should just do, and if I put them behind a paywall I would be taking the mickey.
There is a PRO add-on. It exists because I am a dad in Cape Town, and this is one of the things that puts food on the table at my house. That is the honest reason. Not “unlock your potential”, not “supercharge your workflow”. Just: if this plugin kept the bots off your login page and you can spare it, PRO helps me keep building.
What PRO adds is the second layer you reach for once the door is already locked — two-factor codes, a CAPTCHA, a hidden login address, breached-password checks, country blocking. That is extra security and convenience. It is not the plugin working properly, because the plugin already works properly.
So if the free one does everything you need, brilliant. Genuinely. Use it, and I hope your activity log stays boring. If you get to the point where a second factor or a hidden login would let you sleep better, PRO is at plugins.dadsfam.co.za.
Either way, thanks for using something I built. — Zak, DadsFam

延伸相關外掛

文章
Filter
Mastodon