Login LockDown - A WordPress Enhanced Login Security Plugin
Login LockDown records the IP address and timestamp of every failed WordPress login attempt. If more than a
certain number of attempts are detected within a short period of time from the same
IP range, then the login function is disabled for all requests from that range.
This helps to prevent brute force password discovery. Currently the plugin defaults
to a 1 hour lock out of an IP block after 3 failed login attempts within 5 minutes. This can be modified
via the Options panel. Admisitrators can release locked out IP ranges manually from the panel.
Version 1.5 released - Implemented wp_nonce security in the options and lockdown release forms in the admin screen.
Fixed a security hole with an improperly escaped SQL query. Encoded certain outputs in the admin panel using esc_attr() to prevent XSS attacks.
Fixed an issue with the 'Lockout Invalid Usernames' option not functioning as intended.
1. Extract login-lockdown.1.5.zip into your plugins directory into its own folder
2. Activate the plugin in the Plugin options.
3. Customize the settings from the Options panel, if desired.
Requires at least WordPress 2.5, tested up to 2.8.6
Download: Login LockDown v1.5