[WordPress] 外掛分享: Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall

WordPress 外掛 Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall 的封面圖片。

前言介紹

外掛協作開發者

wpchefgadget |

外掛標籤

spam | firewall | security | Brute Force | login security |

內容簡介

Limit Login Attempts Reloaded 是一款WordPress外掛,可阻止暴力破解攻擊並透過限制常規登錄、XMLRPC、Woocommerce和自訂登錄頁面的登錄嘗試次數來優化您的網站性能。全球已下載超過 2 百萬次,是您登錄安全需求的唯一外掛。此外掛會封鎖特定IP位址和/或使用者名稱,使暴力破解攻擊變得困難或不可能。

WordPress 預設允許無限登錄嘗試次數,這可能會導致密碼易於暴力破解。

Limit Login Attempts Reloaded 外掛的功能包括限制同一 IP 的登錄嘗試次數、可設定鎖定時間、在登錄頁面上顯示留存的重試次數或鎖定時間、封鎖嘗試並發送電子郵件通知、記錄已封鎖的嘗試、使用者自定義的 IP 區域支援、Safelist/Blocklist IP 地址及用戶名稱,支援 IP 範圍等等。

高級的 Limit Login Attempts Reloaded 云端應用程式可提供優化您的登錄安全,提供先進的保護功能、能夠在多個網域之間同步安全名單/封鎖名單等等。

此外掛與 Sucuri、Wordfence 和 Ultimate Member 等其他外掛相容,支援多站台功能和 GDPR 規範。此外,該外掛還提供各種語言支援,歡迎社群協助翻譯。

從舊版的 Limit Login Attempts 外掛升級到 Limit Login Attempts Reloaded 外掛只需在您的網站後台的“外掛”部分中進行幾個簡單的步驟即可完成。所有設置將保持不變!

原文外掛簡介

Limit Login Attempts Reloaded functions as a robust deterrent against brute force attacks, bolstering your website’s security measures and optimizing its performance. It achieves this by restricting the number of login attempts allowed. This applies not only to the standard login method, but also to XMLRPC, Woocommerce, and custom login pages. With more than 2.5 million active users, this plugin fulfills all your login security requirements.
The plugin functions by automatically preventing further attempts from a particular Internet Protocol (IP) address and/or username once a predetermined limit of retries has been surpassed. This significantly weakens the effectiveness of brute force attacks on your website.
By default, WordPress permits an unlimited number of login attempts, posing a vulnerability where passwords can be easily deciphered through brute force methods.
Limit Login Attempts Reloaded Premium (Try Free with Micro Cloud)
Upgrade to Limit Login Attempts Reloaded Premium to extend cloud-based protection to the Limit Login Attempts Reloaded plugin, thereby enhancing your login security. The premium version includes a range of highly beneficial features, including IP intelligence to detect, counter and deny malicious login attempts. Your failed login attempts will be safely neutralized in the cloud so your website can function at its optimal performance during an attack.

Features (Free Version):

Limit Logins – Limit the number of retry attempts when logging in (per each IP).
Configurable Lockout Timings – Modify the amount of time a user or IP must wait after a lockout.
Remaining Tries – Informs the user about the remaining retries or lockout time on the login page.
Lockout Email Notifications – Informs the admin via email of lockouts.
Denied Attempt Logs – View a log of all denied attempts and lockouts.
IP & Username Safelist/Denylist – Control access to usernames and IPs.
New User Registration Protection (Micro Cloud Accounts) – Protects default WP registration.
Sucuri compatibility.
Wordfence compatibility.
Ultimate Member compatibility.
WPS Hide Login compatibility.
XMLRPC gateway protection.
Woocommerce login page protection.
Multi-site compatibility with extra MU settings.
GDPR compliant.
Custom IP origins support (Cloudflare, Sucuri, etc.).
llar_admin own capability.

Features (Premium Version):

Performance Optimizer – Offload the burden of excessive failed logins from your server to protect your server resources, resulting in improved speed and efficiency of your website.
Enhanced IP Intelligence – Identify repetitive and suspicious login attempts to detect potential brute force attacks. IPs with known malicious activity are stored and used to help prevent and counter future attacks.
Enhanced Throttling – Longer lockout intervals each time a malicious IP or username tries to login unsuccessfully.
Deny By Country – Block logins by country by simply selecting the countries you want to deny.
Auto IP Denylist – Automatically add IP addresses to your active cloud deny list that repeatedly fail login attempts.
New User Registration Protection – Protects default WP registration.
Global Denylist Protection – Utilize our active cloud IP data from thousands of websites in the LLAR network.
Synchronized Lockouts – Lockout IP data can be shared between multiple domains for enhanced protection in your network.
Synchronized Safelist/Denylist – Safelist/Denylist IP and username data can be shared between multiple domains.
Premium Support – Email support with a security tech.
Auto Backups of All IP Data – Store your active IP data in the cloud.
Successful Logins Log – Store successful logins in the cloud including IP info, city, state and lat/long.
Enhanced lockout logs – Gain valuable insights into the origins of IPs that are attempting logins.
CSV Download of IP Data – Download IP data direclty from the cloud.
Supports IPV6 Ranges For Safelist/Denylist
Unlock The Locked Admin – Easily unlock the locked admin through the cloud.

*Some features require higher level plans.
Upgrading from the old Limit Login Attempts plugin?

Go to the Plugins section in your site’s backend.
Remove the Limit Login Attempts plugin.
Install the Limit Login Attempts Reloaded plugin.

All your settings will be kept intact!
Many languages are currently supported in the Limit Login Attempts Reloaded plugin but we welcome any additional ones.
Help us bring Limit Login Attempts Reloaded to even more countries.
Translations: Bulgarian, Brazilian Portuguese, Catalan, Chinese (Traditional), Czech, Dutch, Finnish, French, German, Hungarian, Norwegian, Persian, Romanian, Russian, Spanish, Swedish, Turkish
Plugin uses standard actions and filters only.
Based on the original code from Limit Login Attempts plugin by Johan Eenfeldt.
Branding Guidelines
Limit Login Attempts Reloaded™ is a trademark of Atlantic Silicon Inc. When writing about the plugin, please make sure to use Reloaded after Limit Login Attempts. Limit Login Attempts is the old plugin.

Limit Login Attempts Reloaded (correct)
Limit Login Attempts (incorrect)

各版本下載點

  • 方法一:點下方版本號的連結下載 ZIP 檔案後,登入網站後台左側選單「外掛」的「安裝外掛」,然後選擇上方的「上傳外掛」,把下載回去的 ZIP 外掛打包檔案上傳上去安裝與啟用。
  • 方法二:透過「安裝外掛」的畫面右方搜尋功能,搜尋外掛名稱「Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall」來進行安裝。

(建議使用方法二,確保安裝的版本符合當前運作的 WordPress 環境。


2.0.0 | 2.1.0 | 2.2.0 | 2.3.0 | 2.4.0 | 2.5.0 | 2.6.1 | 2.6.2 | 2.6.3 | 2.7.0 | 2.7.1 | 2.7.2 | 2.7.3 | 2.7.4 | 2.8.0 | 2.8.1 | 2.9.0 | trunk | 2.10.0 | 2.10.1 | 2.11.0 | 2.12.0 | 2.12.1 | 2.12.2 | 2.12.3 | 2.13.0 | 2.14.0 | 2.15.0 | 2.15.1 | 2.15.2 | 2.16.0 | 2.17.0 | 2.17.1 | 2.17.2 | 2.17.3 | 2.17.4 | 2.18.0 | 2.19.0 | 2.19.1 | 2.19.2 | 2.20.0 | 2.20.1 | 2.20.2 | 2.20.3 | 2.20.4 | 2.20.5 | 2.20.6 | 2.21.0 | 2.21.1 | 2.22.0 | 2.22.1 | 2.23.0 | 2.23.1 | 2.23.2 | 2.24.0 | 2.24.1 | 2.25.0 | 2.25.1 | 2.25.2 | 2.25.3 | 2.25.4 | 2.25.5 | 2.25.6 | 2.25.7 | 2.25.8 | 2.25.9 | 2.26.0 | 2.26.1 | 2.26.2 | 2.26.3 | 2.26.4 | 2.26.5 | 2.26.6 | 2.26.7 | 2.26.8 | 2.26.9 | 2.25.10 | 2.25.11 | 2.25.12 | 2.25.13 | 2.25.14 | 2.25.15 | 2.25.16 | 2.25.17 | 2.25.18 | 2.25.19 | 2.25.20 | 2.25.21 | 2.25.22 | 2.25.23 | 2.25.24 | 2.25.25 | 2.25.26 | 2.25.27 | 2.25.28 | 2.25.29 | 2.26.10 | 2.26.11 | 2.26.12 | 2.26.13 | 2.26.14 | 2.26.15 | 2.26.16 | 2.26.17 | 2.26.18 | 2.26.19 |

延伸相關外掛(你可能也想知道)

文章
Filter
Apply Filters
Mastodon