Automatically locks out IPs after repeated failed login attempts. Always on, server-side, bypass-proof.
Always active. Brute force protection runs automatically on every password-protected page and login endpoint. No configuration needed — but you can review and clear active lockouts below.
Current settings
—
Loading…
Login lockouts
IPSiteAttemptsUnlocks in
Loading…
Rate-limit blocks
IPs temporarily blocked for exceeding the request rate limit (too many requests too fast — automated abuse).