Fuse Limit Logins

Limits login attempts. Nothing else, and nothing leaves your site.

Brute-force bots hammer every WordPress login page on the internet, all day, every day. Fuse Limit Logins counts failed attempts per IP and per username, locks out the offender with escalating timeouts, and gets out of the way. A successful login clears the slate.

The promise

  • Zero external calls. No cloud IP lists, no reputation service, no telemetry. Your visitors’ IPs never leave your server.
  • Zero upsells. No pro tier, no dashboard ads, no email marketing. The settings you see are all the settings there are.
  • Zero nagging. One optional email alert, off by default, and updates never switch it back on.
  • Covers the side doors. XML-RPC and WooCommerce logins count too, not just wp-login.php.
  • Proxy-aware, done right. Behind Cloudflare or a load balancer, it identifies the real visitor IP only from proxies you explicitly trust, which is the spot most limiters get wrong.

Do you even need it?

If you control your DNS and can set edge rate-limiting rules (Cloudflare’s free plan includes one), do that; bots get stopped before they reach your server at all. Fuse Limit Logins is for everyone else: shared hosting, no CDN, or sites where DNS belongs to someone who won’t touch it.

Privacy

Attempt records live in one database table on your server, capped at 30 days, usernames stored hashed. Uninstalling removes every trace: the table, the settings, everything. Documented in the plugin’s readme, verifiable in the code.

* Status: in development, headed for the WordPress.org plugin directory. Designed and built in Canada. This page will carry the install link the day it’s approved.