{"id":370789,"date":"2026-10-05T06:18:18","date_gmt":"2026-10-05T06:18:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/360-orbit-login-guard\/"},"modified":"2026-10-07T14:07:54","modified_gmt":"2026-10-07T14:07:54","slug":"360-orbit-login-guard","status":"publish","type":"plugin","link":"https:\/\/es.wordpress.org\/plugins\/360-orbit-login-guard\/","author":22027235,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.17","stable_tag":"1.0.17","tested":"7.1.3","requires":"6.4","requires_php":"8.1","requires_plugins":null,"header_name":"360 Orbit Login Guard","header_author":"360 WP Orbit","header_description":"Protects the login area from brute-force attacks: rate limiting, login history and generic error messages \u2014 with a safe allowlist against accidental admin lockout.","assets_banners_color":"ffffff","last_updated":"2026-10-07 14:07:54","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/360wporbit.com\/plugins\/360-orbit-login-guard","header_author_uri":"https:\/\/360wporbit.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":343,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.10":{"tag":"1.0.10","author":"joergliwa","date":"2026-10-05 06:18:00","revision":3728192},"1.0.11":{"tag":"1.0.11","author":"joergliwa","date":"2026-10-05 06:37:19","revision":3728216},"1.0.12":{"tag":"1.0.12","author":"joergliwa","date":"2026-10-05 08:01:53","revision":3728343},"1.0.13":{"tag":"1.0.13","author":"joergliwa","date":"2026-10-05 08:52:25","revision":3728446},"1.0.15":{"tag":"1.0.15","author":"joergliwa","date":"2026-10-07 08:37:48","revision":3732143},"1.0.16":{"tag":"1.0.16","author":"joergliwa","date":"2026-10-07 09:18:29","revision":3732219},"1.0.17":{"tag":"1.0.17","author":"joergliwa","date":"2026-10-07 14:07:54","revision":3732742}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3728343,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3728343,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3728343,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3729118,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3729118,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.10","1.0.11","1.0.12","1.0.13","1.0.15","1.0.16","1.0.17"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3728202,"resolution":"1","location":"assets","locale":"","width":1400,"height":858},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3728202,"resolution":"2","location":"assets","locale":"","width":1400,"height":858}},"screenshots":{"1":"Status overview with currently locked IP addresses and the most recent login attempts.","2":"Settings: rate limiting, generic error messages, proxy header handling and lockout notification."}},"plugin_section":[],"plugin_tags":[2439,9374,602,600],"plugin_category":[38,54],"plugin_contributors":[284397],"plugin_business_model":[],"class_list":["post-370789","plugin","type-plugin","status-publish","hentry","plugin_tags-brute-force","plugin_tags-limit-login-attempts","plugin_tags-login","plugin_tags-security","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-joergliwa","plugin_committers-joergliwa"],"banners":{"banner":"https:\/\/ps.w.org\/360-orbit-login-guard\/assets\/banner-772x250.png?rev=3729118","banner_2x":"https:\/\/ps.w.org\/360-orbit-login-guard\/assets\/banner-1544x500.png?rev=3729118","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/360-orbit-login-guard\/assets\/icon.svg?rev=3728343","icon":"https:\/\/ps.w.org\/360-orbit-login-guard\/assets\/icon.svg?rev=3728343","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/360-orbit-login-guard\/assets\/screenshot-1.png?rev=3728202","caption":"Status overview with currently locked IP addresses and the most recent login attempts."},{"src":"https:\/\/ps.w.org\/360-orbit-login-guard\/assets\/screenshot-2.png?rev=3728202","caption":"Settings: rate limiting, generic error messages, proxy header handling and lockout notification."}],"raw_content":"<!--section=description-->\n<p>Login Guard addresses the most common WordPress attack of all: automated password guessing against \/wp-login.php.<\/p>\n\n<ul>\n<li>Rate limiting: locks an IP address out after too many failed attempts, for a configurable duration.<\/li>\n<li>Login history (7 days): every attempt with a pseudonymous fingerprint instead of the raw IP address, success or failure, and the user name tried (only readable if the account exists).<\/li>\n<li>Generic error messages: never reveals whether a user name exists.<\/li>\n<li>Safe allowlist behaviour: an IP address from which someone with administrator rights recently signed in successfully is only locked out after ten times the usual number of failed attempts, so a few typos never lock you out.<\/li>\n<li>Disable XML-RPC: closes the known bypass of rate limiting via system.multicall.<\/li>\n<li>Protection against user name enumeration (?author= parameter and the public REST user list).<\/li>\n<li>Export and import of all settings as JSON, to set up several sites the same way.<\/li>\n<li>WP-CLI: inspect the status and unlock IP addresses even when wp-admin itself is unreachable.<\/li>\n<\/ul>\n\n<h4>Free version vs. Pro<\/h4>\n\n<p>The free version is complete on its own: rate limiting, login history, generic error messages, XML-RPC and enumeration protection, and settings export\/import.<\/p>\n\n<p><strong>Login Guard Pro<\/strong> adds:<\/p>\n\n<ul>\n<li>Two-factor authentication (TOTP) for individual accounts or entire roles, compatible with common authenticator apps.<\/li>\n<li>A custom login URL instead of \/wp-login.php, with a 404 for the real address.<\/li>\n<li>Notification when an account signs in from an unknown device.<\/li>\n<li>A fixed allow\/block list for IP addresses.<\/li>\n<li>Automatic update notifications directly in the WordPress admin.<\/li>\n<\/ul>\n\n<p>Login Guard Pro is a separate plugin available from the author; it is not required to use the free version.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP under <em>Plugins \u2192 Add New \u2192 Upload Plugin<\/em>, or install it from the plugin directory.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Open the <strong>Login Guard<\/strong> menu and review the defaults under \"Settings\" (they already suit most sites).<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20i%20lock%20myself%20out%3F\"><h3>Can I lock myself out?<\/h3><\/dt>\n<dd><p>This is exactly the scenario the safety net protects against: an IP address from which a person with administrator rights recently signed in successfully is only locked out after ten times the usual number of failed attempts. In addition, every lockout can be lifted with one click under \"Status &amp; Lockouts\", and if wp-admin is unreachable, via WP-CLI (<code>wp 360-orbit-login-guard unlock &lt;ip&gt;<\/code>).<\/p><\/dd>\n<dt id=\"are%20raw%20ip%20addresses%20stored%3F\"><h3>Are raw IP addresses stored?<\/h3><\/dt>\n<dd><p>No. The login history only stores a pseudonymous fingerprint (a hash of the IP address and a secret random value generated by the plugin). The plugin does not send any data to external services.<\/p><\/dd>\n<dt id=\"what%20happens%20on%20deactivation%3F\"><h3>What happens on deactivation?<\/h3><\/dt>\n<dd><p>Rate limiting and all other protections stop immediately and the daily clean-up cron job is unscheduled. The existing login history and all settings are kept and are back immediately after reactivation. Only \"Delete\" in the plugin list removes them permanently.<\/p><\/dd>\n<dt id=\"which%20languages%20does%20the%20admin%20interface%20support%3F\"><h3>Which languages does the admin interface support?<\/h3><\/dt>\n<dd><p>The admin interface follows the language configured in WordPress. Translations are delivered as WordPress.org language packs (translate.wordpress.org, text domain <code>360-orbit-login-guard<\/code>); German is maintained by the author. You are welcome to contribute further languages there.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.17<\/h4>\n\n<ul>\n<li>The 360 WP Orbit overview now also lists the new plugin 360 Orbit Database Cleaner.<\/li>\n<\/ul>","raw_excerpt":"Protects your login against brute-force attacks: rate limiting, login history and generic error messages, with a safety net against admin lockout.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/370789","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=370789"}],"author":[{"embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/joergliwa"}],"wp:attachment":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=370789"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=370789"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=370789"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=370789"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=370789"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=370789"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}