WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

Firewall & login

Login form protection

Configure Pro login protection: auto-ban failed attempts, login notice, and hide login errors under Firewall Settings.

Security Ninja Pro can limit failed logins, show a warning on the login form, and hide detailed login errors. Settings are on Security Ninja → Firewall → Settings under login / login form protection.

Login Form Protection settings on Firewall

Protect the login form

Keep this enabled on production sites. Turn it off briefly only while you debug a login issue, then turn it back on.

Login notice

Optional message on the login form. Default text is: “Warning: Multiple failed login attempts will get you banned.”

Auto-ban rules for failed logins

IPs that fail login too often are banned locally.

Defaults: 5 failed logins within 5 minutes → ban for 2 hours.

You can raise the attempt limit, widen the window, or lengthen the ban. On sites with many real users who mistype passwords, avoid very strict values.

Failed-password lockouts are separate from temporary or magic login links. If a contractor link is blocked, check Filter Suspicious Queries or Change login URL, not only the auto-ban rules. See Temporary login plugins.

Hide login errors

WordPress can reveal whether a username exists. When this option is on, visitors see a generic message such as “Error: Something went wrong” instead.

Check Security Ninja → Events for the real failure reason when you need details.

You can also change the login URL so bots have a harder time finding the form.

Video walkthrough

Watch how login form protection stops brute-force attacks.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image