Security Ninja Pro can limit failed logins, show a warning on the login form, and hide detailed login errors. Settings are on Security Ninja → Firewall → Settings under login / login form protection.
Protect the login form
Keep this enabled on production sites. Turn it off briefly only while you debug a login issue, then turn it back on.
Login notice
Optional message on the login form. Default text is: “Warning: Multiple failed login attempts will get you banned.”
Auto-ban rules for failed logins
IPs that fail login too often are banned locally.
Defaults: 5 failed logins within 5 minutes → ban for 2 hours.
You can raise the attempt limit, widen the window, or lengthen the ban. On sites with many real users who mistype passwords, avoid very strict values.
Failed-password lockouts are separate from temporary or magic login links. If a contractor link is blocked, check Filter Suspicious Queries or Change login URL, not only the auto-ban rules. See Temporary login plugins.
Hide login errors
WordPress can reveal whether a username exists. When this option is on, visitors see a generic message such as “Error: Something went wrong” instead.
Check Security Ninja → Events for the real failure reason when you need details.
You can also change the login URL so bots have a harder time finding the form.
