এয়া এৰি বিষয়বস্তুলৈ যাওক
WordPress.org

অসমীয়া

  • থীমসমূহ
  • প্লাগিনসমূহ
  • News
  • সাহায্য
  • বিষয়
  • অৱদান আগবঢ়াওক
  • যোগাযোগ
  • WordPress পাওক
WordPress পাওক
WordPress.org

Plugin Directory

Phantom User Lockout

  • প্লাগিন দাখিল কৰক
  • মোৰ প্ৰিয়বোৰ
  • লগ ইন কৰক
  • প্লাগিন দাখিল কৰক
  • মোৰ প্ৰিয়বোৰ
  • লগ ইন কৰক

Phantom User Lockout

efraing-ৰ দ্বাৰা
ডাউনল’ড কৰক
  • বিশদ বিৱৰণ
  • পৰ্য্যালোচনা
  • ইনষ্টলেশ্যন
  • বিকাশ
সাহায্য

বৰ্ণনা

Bots guess usernames like “admin” and “administrator”. On most sites those names don’t exist, so any attempt with them is a bot. Phantom User Lockout records each one and blocks the IP address that made it.

For every attempt with a username that doesn’t exist on your site, you get:

  • The time, in site time with UTC on hover
  • The username and the password that was tried
  • The IP address, shown as IP Blocked, Not blocked or Safe
  • Where the IP is: city, region and country
  • Who owns it: the hosting company or network (for example “AS53667 FranTech Solutions”) and the reverse hostname
  • How the attempt came in: the login form, XML-RPC (every guess inside a system.multicall batch gets its own row), REST API application passwords, or another login form
  • The user agent and the requested URL

Blocking

  • An IP is blocked after its first attempt with a username that doesn’t exist. You can raise that threshold.
  • Blocks are permanent. They only lift when you press Unblock.
  • A blocked visitor gets a 403 page that reads “IP Blocked”.
  • By default a block covers the login page, XML-RPC, REST logins and any other form that logs in through WordPress. You can widen it to the whole site.
  • Optionally, the plugin can also block IPs that enter the wrong password for a real username. This is off by default, and the default threshold is 3 wrong passwords.

Built not to lock you out

  • Real accounts are never recorded unless you turn on the real-account option, and even then their passwords are never stored.
  • If a username is within two letters of a real login or email, it’s treated as a typo by one of your own people. It’s logged with the password hidden and never causes a block.
  • Safe IPs are never recorded or blocked. Add yours with one click: “Add my current IP address to the list”.
  • A signed-in administrator is never blocked. Neither are the server’s own address and loopback.
  • Emergency switch: add define( 'BOTLO_DISABLE', true ); to wp-config.php.

The plugin never edits .htaccess or any other server file.

External services

To show where an IP address is and who owns its network, the plugin looks the address up with ipinfo.io.

  • What is sent: only the IP address that made the login attempt, plus your ipinfo.io token if you entered one in Settings. No information about your site, your users or your visitors is sent.
  • When: once per new IP address, in the background shortly after its first attempt, or when an administrator opens the Phantom User Lockout screen while a lookup is still pending.
  • Turning it off: Settings → Location lookups.
  • ipinfo.io terms of service: https://ipinfo.io/terms-of-service
  • ipinfo.io privacy policy: https://ipinfo.io/privacy-policy

Privacy

The plugin stores IP addresses, user agents, usernames and passwords from failed login attempts that used usernames which don’t exist. It adds suggested wording to Settings → Privacy → Policy Guide.

ইনষ্টলেশ্যন

  1. Upload the plugin through Plugins → Add New → Upload Plugin, or install it from the directory.
  2. Activate it.
  3. Open Phantom User Lockout in the admin menu, go to Blocked & Safe IPs and click Add my current IP address to the list. Do the same from every place you or your staff log in.
  4. If your site is behind a proxy or CDN and every visitor shows the same IP, change Visitor IP comes from in Settings.

সঘনাই উত্থাপিত প্ৰশ্ন

I locked myself out.

Add define( 'BOTLO_DISABLE', true ); to wp-config.php, or rename the plugin’s folder over FTP. Then log in, unblock your IP, add it to Safe IPs, and remove the line.

Why record the password?

It shows you which password lists are being used against your site. It’s only recorded for usernames that don’t exist, so it never belongs to a real account. You can turn it off under Settings → Passwords.

Does it replace a lockout plugin like Limit Login Attempts?

It can run next to one. Those plugins lock an IP out for a while after failed logins. Phantom User Lockout records what was tried and blocks the IP permanently.

Can it block the whole site, not just the login page?

Yes: Settings → “A blocked IP cannot reach”. Pages served from a caching plugin’s disk cache never reach WordPress, so those can’t be covered.

Where is the data kept?

In two database tables of the plugin’s own. Attempt rows are removed after 180 days or 100,000 rows, whichever comes first, and you can change both limits. Blocked IPs are kept until you unblock them. Deactivating the plugin keeps everything. Deleting the plugin removes the tables and the settings.

Where do I get help?

Post in the plugin’s support forum at https://wordpress.org/support/plugin/phantom-user-lockout/. Include your WordPress and PHP versions, and what you see in the Attempts log. Don’t post passwords or your own IP address there, because the forum is public.

পৰ্য্যালোচনা

এই প্লাগিনৰ বাবে কোনো পৰ্য্যালোচনা নাই।

অৱদানকাৰী আৰু বিকাশকাৰীসকল

“Phantom User Lockout” হৈছে মুক্ত উৎসৰ ছফ্টৱেৰ। এইসকল লোকে এই প্লাগিনত অৱদান আগবঢ়াইছে।

অৱদানকাৰীসকল
  • efraing

আপোনাৰ ভাষাত “Phantom User Lockout” অনুবাদ কৰক।

বিকাশৰ প্ৰতি আগ্ৰহী?

ক’ড ব্ৰাউজ কৰক, SVN ৰিপজিটৰী চাওক নাইবা RSS-দ্বাৰা বিকাশৰ পঞ্জী ছাবস্ক্ৰাইব কৰক।

সলনি-পঞ্জী

1.2.0

  • Renamed from Login Lockout to Phantom User Lockout.

1.1.0

  • First public release.
  • Records login attempts with usernames that don’t exist, including the password tried, the IP’s location and its hosting company.
  • Permanent IP blocks, lifted only by Unblock.
  • Safe IPs, with a one-click “Add my current IP address to the list”.
  • Optional blocking after wrong passwords for real accounts (default 3).
  • Option to stop recording passwords.
  • CSV export.

মেটা

  • 1.2.0 সংস্কৰণ
  • 13 ঘণ্টা আগত শেষবাৰ আপডে’ট হৈছিল
  • সক্ৰিয় ইনষ্টলেশ্যন 10টাতকৈ কম
  • WordPress-ৰ সংস্কৰণ 6.2 বা তাতকৈ ওপৰৰ
  • ইমানলৈকে পৰীক্ষা কৰা হৈছে 7.1.2
  • PHP-ৰ সংস্কৰণ 7.2 বা তাতকৈ ওপৰৰ
  • ভাষা
    English (US)
  • block ipBrute Forcehoneypotloginsecurity
    টেগবোৰ
  • উচ্চখাপৰ ভিউ

ৰে’টিংবোৰ

এতিয়ালৈ কোনো পৰ্য্যালোচনা দাখিল কৰা হোৱা নাই।

Your review

সকলো পৰ্য্যালোচনা চাওক

অৱদানকাৰীসকল

  • efraing

সাহায্য

কিবা ক’বলগীয়া আছে? সহায় লাগে?

সাহায্যৰ ফ’ৰাম চাওক

  • সন্দৰ্ভ
  • বাতৰি
  • হ’ষ্টিং
  • গোপনীয়তা
  • প্ৰদৰ্শনী
  • থীমবোৰ
  • প্লাগিনবোৰ
  • আৰ্হিবোৰ
  • শিকক
  • সাহায্য
  • বিকাশকাৰী
  • WordPress.tv ↗
  • জড়িত হৈ পৰক
  • অনুষ্ঠানবোৰ
  • দান কৰক ↗
  • Swag ↗
  • WordPress.com ↗
  • মেট ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

অসমীয়া

  • আমাৰ X (আগৰ Twitter) একাউণ্টলৈ যাওক
  • আমাৰ Bluesky একাউণ্টলৈ যাওক
  • আমাৰ Mastodon একাউণ্টলৈ যাওক
  • আমাৰ Threads একাউণ্টলৈ যাওক
  • আমাৰ Facebook পৃষ্ঠালৈ যাওক
  • আমাৰ Instagram একাউণ্টলৈ যাওক
  • আমাৰ LinkedIn একাউণ্টলৈ যাওক
  • আমাৰ TikTok একাউণ্টলৈ যাওক
  • আমাৰ YouTube চেনেললৈ যাওক
  • আমাৰ Tumblr একাউণ্টলৈ যাওক
ক’ডেই কবিতা।
The WordPress® trademark is the intellectual property of the WordPress Foundation.