Login LockDown records the IP address and timestamp of every failed WordPress login attempt. If more than a certain number of attempts are detected within a short period of time from the same IP range, then the login function is disabled for all requests from that range. This helps to prevent brute force password discovery. Currently the plugin defaults to a 1 hour lock out of an IP block after 3 failed login attempts within 5 minutes. This can be modified via the Options panel. Admisitrators can release locked out IP ranges manually from the panel.
Version 1.3 released - Fixed the issue that caused Login LockDown to not activate
correctly if it was not in a specific subdirectory, and adjusted the byline display to interact in a more friendly manner with
Wordpress 2.7 and up.
Note: If you need to use Login LockDown with WordPress 2.3.3 or earlier, then you can download version 1.1
here. However, I strongly advise anyone not
running WordPress 2.5.1 or higher to upgrade their installations, due to serious security risks.
Installation instructions:
1. Extract loginlockdown-1.3.zip into your plugins directory into its own folder
2. Activate the plugin in the Plugin options.
3. Customize the settings from the Options panel, if desired.
Requires at least WordPress 2.5, tested up to 2.7.1
Download: Login LockDown v1.3