
DadsFam Login Security protects the most-attacked part of your WordPress site — the login form — without making you read a manual or fiddle with servers.
Everything described below works on every site. Nothing is disabled, blurred out, time-limited or reduced.
It watches failed logins, locks out attackers automatically, escalates repeat offenders to a longer ban, and keeps a clean log of everything so you can see exactly what’s hitting your site.
What you get (free)
- Smart brute-force lockouts — set how many tries are allowed and how long the lockout lasts. Repeat offenders get an automatic extended ban.
- IP allow & deny lists — exact IPs, wildcards (
1.2.3.*) and CIDR ranges (1.2.3.0/24). IPv4 and IPv6. - Full login activity log — every failed login, success, lockout and block, with IP, username and device. Searchable, filterable, auto-pruned.
- Live dashboard — failed-login stats, a 14-day chart, top attacking IPs, and who’s locked out right now (with one-click unblock).
- Email alerts — get a tidy, throttled email when a lockout triggers.
- Generic login errors — stop attackers learning whether a username exists.
- Honeypot bot trap — an invisible field that catches dumb bots.
- Hardening — block user enumeration (
?author=Nand the REST API), kill XML-RPC pingback amplification, or disable XML-RPC entirely.
Pro Features (DadsFam Login Security Pro add-on)
The optional DadsFam Login Security Pro add-on plugs into the same screens and adds two-factor authentication (authenticator apps and email codes, with backup codes and trusted devices), CAPTCHA on the login form (Google reCAPTCHA, hCaptcha, Cloudflare Turnstile or a built-in maths question), a custom hidden login address, a branded login screen, strong-password and breached-password checks, idle auto-logout, scheduled security reports, and country blocking.
A word about PRO
Right, let me be straight with you, because I hate being sold to as much as you do.
Everything above is free and it stays free. The lockouts, the allow and deny lists, the activity log, the live dashboard, the email alerts, the bot traps and the hardening — none of those are premium features. Those are the things a login-security plugin should just do, and if I put them behind a paywall I would be taking the mickey.
There is a PRO add-on. It exists because I am a dad in Cape Town, and this is one of the things that puts food on the table at my house. That is the honest reason. Not “unlock your potential”, not “supercharge your workflow”. Just: if this plugin kept the bots off your login page and you can spare it, PRO helps me keep building.
What PRO adds is the second layer you reach for once the door is already locked — two-factor codes, a CAPTCHA, a hidden login address, breached-password checks, country blocking. That is extra security and convenience. It is not the plugin working properly, because the plugin already works properly.
So if the free one does everything you need, brilliant. Genuinely. Use it, and I hope your activity log stays boring. If you get to the point where a second factor or a hidden login would let you sleep better, PRO is at plugins.dadsfam.co.za.
Either way, thanks for using something I built. — Zak, DadsFam
Screenshots

The dashboard: protection status in one sentence, a finish-locking-down checklist, live stats, the 14-day chart and who is locked out right now.

Activity: every sign-in attempt, filtered with one click, with “Block for good” on any row.

Settings: pick Relaxed, Balanced or Strict, flip plain-English switches, and put your own address on the allow list with one click.