Login protection plugins operate directly on authentication requests, retry counters, lockouts, cookies, client addresses, and administrative notifications. Limit Login Attempts version 1.7.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64690, confirming that the review focused on retry tracking, IP handling, lockout enforcement, authentication cookie checks, configuration access, and safe logging of failed attempts.
| Name of | Limit Login Attempts |
| Version | 1.7.2 |
| Active installations | 300,000+ |
| Description | Limits failed login attempts by IP for normal login and authentication cookies, with customizable lockouts, optional logging, email notifications, and reverse proxy support. |
| Security | Successfully tested for: SQL Injection (SQLi) Cross-Site Scripting (XSS) – Stored and Reflected Cross-Site Request Forgery (CSRF) Authentication Vulnerabilities Authentication Bypass Exploits Privilege Escalation Buffer Overflow Denial-of-Service (DoS) vectors Data Leakage Vulnerabilities Insecure Dependency Usage Remote Code Execution (RCE) Risks Unauthorized File Access Insufficient Injection Protection Information Disclosure via Misconfigured Endpoints |
| CleanTalk Certification | Proudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards. |
| Additional Information | Use Limit Login Attempts with confidence backed by the “Plugin Security Certification” (PSC). Set retry and lockout values deliberately, verify trusted proxy configuration, protect login logs, and test recovery access before deploying changes. |
| Plugin Security Certification by CleanTalk | ![]() |
| Logo of the plugin |
PSC by CleantalkJoin the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Key Features
Limit Login Attempts limits repeated authentication attempts for each client address. The controls apply to ordinary login requests and attempts made through authentication cookies. Administrators can tune retry and lockout thresholds, display remaining attempts, keep optional logs, send email notifications, and account for sites operating behind a reverse proxy.
Security Assurance
The CleanTalk Plugin Security Certification evaluation focused on accurate retry accounting, reliable lockout enforcement, validation of configuration changes, and consistent handling of authentication cookies. The review also considered client address normalization, reverse proxy trust, log content, notification triggers, option access, and protection against bypasses that could weaken the configured retry policy.
The plugin has been successfully tested for:
✅ Information Leakage Vulnerabilities
✅ SQL Injection Vulnerabilities
✅ Cross-Site Scripting (XSS) Attacks
✅ Cross-Site Request Forgery (CSRF) Attacks
✅ Authentication and Authentication Bypass Vulnerabilities
✅ Privilege Escalation Vulnerabilities
✅ Buffer Overflow Vulnerabilities
✅ Denial-of-Service (DoS) Vulnerabilities
✅ Data Leakage Vulnerabilities
✅ Insecure Dependencies
✅ Code Execution Vulnerabilities
✅ File Unauthorized Access Vulnerabilities
✅ Insufficient Injection Protection
Conclusion
With PSC-2026-64690, Limit Login Attempts version 1.7.2 demonstrates strong baseline security for login retry limits and lockout workflows. The certification addresses failed-attempt tracking, authentication cookies, client address handling, administrative settings, logs, and notifications. Site owners should confirm proxy behavior, keep emergency access procedures available, and review lockout data without exposing sensitive authentication details.
Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.
