Set up sign-in protection on Login & Access
Set BetterShield’s login attempt limits, hidden bot check, public form limits, allow and block lists, trusted proxies and session limits.
Login & Access controls who may try to sign in, how often, and how long sessions last. It is on BetterShield › Protect › Login & Access. Edits wait in a bar with Save and Discard.
How this site sees you, and lockouts
How this site sees you reads your own request (nothing is stored) and says whether visitors can be told apart.
- If lockouts are not running, it says why. Usually the fix is naming your proxy under Trusted proxies.
- If your request came through Cloudflare unannounced, press Yes, this site is behind Cloudflare. Turn that off withdraws that trust.
Lockouts lists recent pauses from sign-in and the public forms, running ones first, by network (such as 203.0.113.0/24). Release now ends a running one.
Note: Only a verified address is ever locked out. Others are recorded, never locked.
Sign-in protection
| Option | What it does | Why it matters | Default |
|---|---|---|---|
| Pause sign-in after repeated failures | After Failures allowed (3 to 100) wrong passwords from one connection within Counted within (minutes), sign-in from it pauses for Pause lasts (minutes) (both 1 to 1440). | Stops brute-force password guessing without locking the account. | On: 5 in 15 minutes, paused 15 minutes |
| Refuse obviously automated submissions | The hidden bot check: an invisible field and a clock on the sign-in, registration, comment and store account forms. Refuses scripts that fill every field or submit within two seconds. | Cuts bot noise; people see nothing. | On |
| Slow down repeated failed sign-ins | After two wrong passwords from one connection, the browser solves a small puzzle before the next try. Needs JavaScript, and HTTPS or localhost. | Guessing below the limit costs time; an unsolved puzzle never counts. | Off |
| Tell an account holder about a sign-in from a new network | Emails the account’s own address the first time it signs in from a new network, at most once a day. Blocks nothing. | The person who knows is told. | Off |
A connection paused again within a day is paused twice as long each time, up to a day; releasing one resets the doubling. Wrong two-factor codes and wrong application passwords also count. If the attempts named a real account, its owner is emailed an unlock link (see Locked out).
On multisite, each site keeps its own counts, lockouts and lists.
Signing in
Six sign-in fixes, all off by default, described in Hardening.
- Change the sign-in address: moves sign-in to an address you choose.
- Refuse application passwords: for site managers, or everyone.
- Refuse passwords found in known breaches: checks new passwords against Pwned Passwords.
- Keep low-privilege accounts out of the dashboard: sends a chosen role from wp-admin to the front page.
- Hide the dashboard from visitors: signed-out visitors get a 404 at /wp-admin/.
- Strengthen and rotate the sign-in keys: adds a secret to session keys.
Request protection
Counted apart from sign-ins, so a form never locks you out of your dashboard. Each form has Allowed before it closes (3 to 100), Counted within (minutes) and Closed for (minutes) (both 1 to 1440).
| Option | Past the limit | Default |
|---|---|---|
| Hold a burst of comments for moderation | Further comments from that connection wait in moderation. Nothing is discarded; moderators are never held. | On: 10 in 10 minutes, closed 30 minutes |
| Slow repeated password reset requests | Further requests get the answer a successful one gets, so no account is revealed. Accounts are never affected. | On: 8 in 15 minutes, closed 15 minutes |
| Slow repeated sign-ups | Further sign-ups are refused until later. Only where registration is open. | On: 8 in 1 hour, closed 1 hour |
Before you save, new numbers are replayed against the last two days of attempts.
Allowed and refused
| List | What it does | Default |
|---|---|---|
| Always allowed | Addresses never locked out, held by form limits or given the puzzle. Addresses only. | Empty |
| Never allowed to sign in | Refuses sign-in, never browsing. Each entry names an address or range, a username, a user-agent fragment, or a mix, with an optional note. | Empty |
| Trusted proxies | One address or range per comma for a reverse proxy in front of the site, so the visitor address it forwards (X-Forwarded-For) is believed. Cloudflare needs no entry. | Empty |
A Never allowed to sign in entry has these fields, plus an optional Note:
- IP address or CIDR range: matches verified connections only.
- Or a username: on its own, refused from anywhere, even an allowed address, with the answer a wrong password gets. Beside a range or user agent, refused only from there. Your own username cannot be added.
- Or a user-agent fragment: four characters or more. On its own, it applies to every connection.
Ranges can be no wider than /8 (IPv4) or /32 (IPv6). Each list holds up to 500 entries.
Sessions
| Option | What it does | Default |
|---|---|---|
| Sign out after idle (minutes) | Signs a session out after this long without activity, yours included. | 0 (no timeout) |
| Sessions per account | When an account signs in past the cap, its oldest session signs out. | 0 (no cap) |
Note: The idle timeout is 0 (off) or 5 to 1440 minutes (one day). The session cap (0 to 100) is unavailable where another plugin replaced WordPress’s session storage.
Who is signed in lists each session’s start, last activity and network. Sign out all their sessions signs one account out everywhere. Sign out everyone you can ends every session you may end, yours included. Both ask Yes, do it first.
Good to know
- Minimum password lengths are under Settings › General. See General settings.
- With Ask for my password before an action that removes a protection on, loosening a setting, releasing a lockout or signing people out asks for your password.
- Safe mode, from your recovery link, pauses everything on this screen.