

Your WordPress login page never stops getting knocked on. Around the clock, automated bots and scripts pound wp-login.php with endless username and password guesses. Most of it is background noise — but it drains your server resources, clutters your logs, and quietly probes for a weak spot. Techbox Login Security shuts down that noise and, just as importantly, shows you exactly who is trying to get into your site.
The moment you activate it, Techbox Login Security limits login attempts, locks out repeat offenders, blocks bad IP addresses, and records every sign-in attempt — so you can see who is knocking, stop the ones that should not be there, and keep your login page fast and quiet. No coding and no security expertise required.
Relentless brute-force and bot traffic is usually more of a constant nuisance than an instant break-in — it hammers your server, inflates your logs, and tests for weak passwords day and night. The real risk is not knowing what is happening at your login. When a site does get compromised, the tell-tale sign is often a brand-new user account or an unfamiliar login from a strange IP address. Techbox Login Security cuts the day-to-day noise and keeps a clear record of every attempt — so you can block repeat offenders and catch anything unusual before it becomes a problem.
Security software is often written for experts and leaves everyone else guessing. Techbox Login Security is different. It ships with smart defaults, uses plain-English settings, and clearly shows you what is happening at your login — so a first-time site owner and a seasoned agency both feel at home. No confusing jargon, no risky knobs you are afraid to touch, and a one-click way back to a safe baseline whenever you need it.
wp-login.php behind your own secret address so bots cannot even find your login page.Login protection usually stops at failed attempts and lockouts. Techbox Login Security also logs successful sign-ins — included free — so you can see which users and customers really log in, how often, and from which IP. For a membership site, online shop, or client portal, that is genuinely useful business insight, not just security: spot your most active members, notice a quiet account that suddenly springs back to life, or simply confirm that a customer got in. The Active sessions screen goes further, showing who is signed in right now — a quick read on real engagement and an easy way to manage or end sessions at a glance. (Pro adds the signed-in user’s role to each successful sign-in for even richer insight.)
On a fresh install Techbox Login Security applies a sensible “out of the box” posture so the site is protected immediately: login limits on (5 attempts / 15-minute lockout / 24-hour failure decay, escalating to a 24-hour lockout after repeat strikes), failed and successful logins logged, attempt feedback and the footer privacy notice on. Optional features (custom login URL, lockout emails, email login codes, login lockdown) stay off until you configure them. Every settings section has a Restore recommended action.
Want to understand the attacks, not just block them? Techbox Login Security Pro is a separate add-on that builds on everything in this free plugin and adds:
Pro is completely optional — this free plugin is fully functional on its own.
Storage and CSV exports are local to your site. The activity log and exports include IP addresses and usernames so you can audit sign-ins; remove or restrict access if your policies require it. This free plugin makes no third-party API calls for login enforcement or licensing. Paid capabilities live in a separate Pro add-on distributed outside WordPress.org.
This free plugin does not connect to external licensing, analytics, or update services. Updates ship through WordPress.org. Optional Pro features are provided by a separately installed add-on; that add-on’s own privacy and licensing disclosures apply when it is installed.