Login Protection

Last updated: 10th July 2026 for CC Security Essentials Pro version 1.0

Introduction

WordPress websites are regularly targeted by automated attempts to guess administrator usernames and passwords.

These attacks are often referred to as brute-force attacks. Rather than exploiting a vulnerability, they repeatedly try different password combinations in the hope of discovering valid login credentials.

CC Security Essentials Pro helps reduce the effectiveness of these attacks by monitoring failed login attempts and temporarily restricting repeated unsuccessful logins.

The aim is to make automated password guessing significantly more difficult while allowing legitimate users to continue accessing the website normally.


How Login Protection Works

Each time a login attempt fails, CC Security Essentials Pro records information about the attempt.

If repeated failed attempts occur within the configured time period, the plugin temporarily prevents further login attempts for the configured lockout duration.

Once the lockout expires, normal login attempts are automatically permitted again.

Successful logins are unaffected.


Why Use Login Protection?

Strong passwords are an important part of website security, but they are only one layer of protection.

Without Login Protection, an attacker can continue trying different passwords indefinitely.

By temporarily restricting repeated failed attempts, Login Protection:

  • slows automated password guessing;
  • reduces repeated attacks against administrator accounts;
  • helps protect weaker passwords until they can be changed;
  • encourages legitimate users to notice incorrect passwords before repeatedly retrying them.

It works particularly well alongside Password Policies and Password Age Monitoring.


Configuring Login Protection

Open:

Security → Login Protection

The page allows you to configure when temporary restrictions are applied and how long they remain in effect.

The available settings are intentionally straightforward so that most websites can be protected without complicated configuration.


Maximum Failed Login Attempts

This setting determines how many consecutive failed login attempts are permitted before a temporary restriction is applied.

For most websites, the default value provides a sensible balance between usability and protection.

Lower values provide stronger protection but may inconvenience users who frequently mistype passwords.

Higher values provide greater tolerance for genuine mistakes but allow more incorrect attempts before protection is applied.


Monitoring Period

The monitoring period determines how long failed login attempts remain relevant.

For example:

  • 5 failed attempts within 10 minutes

is treated differently from:

  • 5 failed attempts over several days.

Using a relatively short monitoring period helps distinguish between occasional typing mistakes and repeated automated attacks.


Lockout Duration

When the configured threshold is reached, Login Protection temporarily restricts further login attempts.

The lockout duration determines how long that restriction remains in place.

Longer lockouts provide stronger resistance to automated attacks.

Shorter lockouts reduce the inconvenience should a legitimate user accidentally trigger the restriction.

After the configured period expires, login attempts are automatically permitted again.

No administrator intervention is normally required.


Login Messages

CC Security Essentials Pro displays clear, neutral messages when a temporary restriction is active.

These messages are intentionally designed to:

  • explain that login is temporarily unavailable;
  • avoid revealing unnecessary security information;
  • avoid confirming whether an account exists;
  • provide appropriate guidance without assisting attackers.

This helps maintain good security while remaining understandable for legitimate users.


Understanding Temporary Restrictions

A temporary restriction is not a permanent account lock.

It simply pauses further login attempts for a short period.

Once the configured duration has elapsed, normal login behaviour resumes automatically.

In most cases, users who accidentally trigger a restriction simply need to wait until the lockout expires before trying again.


Best Practice

For most websites we recommend:

  • enabling Login Protection;
  • using strong passwords;
  • enabling Password Policies where appropriate;
  • reviewing Password Age Monitoring periodically;
  • removing unused administrator accounts.

These measures complement one another and provide stronger protection than relying on any single feature alone.


Security Events

When Security Events are enabled, Login Protection can contribute useful information about authentication activity.

This allows authorised administrators to review repeated failed login attempts and identify patterns that may require further investigation.

Review security information periodically rather than waiting until a problem occurs.


Common Questions

Will Login Protection prevent legitimate users from signing in?

No.

Legitimate users can continue signing in normally using the correct password.

Only repeated unsuccessful login attempts contribute towards a temporary restriction.


What happens if I accidentally trigger a lockout?

Simply wait until the configured lockout period expires before trying again.

If you are unsure of your password, consider resetting it rather than continuing to guess.


Can I disable Login Protection?

Yes.

Like all CC Security Essentials Pro features, Login Protection can be enabled or disabled through its settings.

Some websites may choose not to use it, although it is recommended for the majority of WordPress installations.


Does Login Protection affect existing users?

Existing accounts continue to operate normally.

No changes are made to usernames or passwords.

The feature simply monitors failed authentication attempts and temporarily restricts repeated failures when necessary.


Troubleshooting

Legitimate users are being temporarily restricted

Review the configured:

  • maximum failed login attempts;
  • monitoring period;
  • lockout duration.

A website used by many administrators may benefit from slightly more forgiving thresholds.

Also confirm that users are entering the correct username and password.


Login attempts never become restricted

Check that:

  • Login Protection is enabled;
  • the configured threshold has actually been exceeded;
  • another security plugin is not intercepting login attempts first.

If another plugin already performs login protection, consider whether both protections are required.


A password manager repeatedly triggers restrictions

Some password managers automatically retry saved credentials.

Ensure that stored credentials are correct and remove outdated passwords where necessary.


I’m using another security plugin

Some security plugins include their own login protection.

Running multiple login restriction systems simultaneously may produce unexpected behaviour or unnecessary duplicate restrictions.

Review the Security Health and Compatibility information before enabling overlapping protections.


Related Articles

Continue with: