M Security
Brute-force and spam defence that works on activation
What it does
Protects any WordPress site from brute-force login attacks and spam, with defaults that work the moment you activate it, even while the site is in maintenance mode. Protection runs locally: no cloud account is needed, and the optional shared threat feed stays off until you turn it on. Anonymised usage statistics are shared by default to help improve the plugin — never any personal data — and one switch turns them off. Updates arrive through the normal WordPress update screen.
Features
- Failed logins counted per IP and per username, across wp-login.php, XML-RPC and application passwords
- Escalating lockouts: 4 retries, 20 minutes, doubling on repeat offenders up to 24 hours
- Instant permanent ban for anyone trying a decoy username you define
- Optional bans for XML-RPC probes and ?author=N username scans
- Locked-out bots get a blank 403 and no login form to attack
- Country rules via GeoIP, and spam defence for comments, registration and forms
- Optional sharing of every ban with the M Blacklist feed, so other sites block the address in advance
- Statistics dashboard and widget with 7- and 30-day charts, plus an optional weekly e-mail report
- Automatic updates straight from majevski.com through the normal WordPress update screen
- One-click Spam & blacklist on the Comments screen; comments from blacklisted authors are refused outright
Installing it
- Download the ZIP above.
- In WordPress, go to Plugins → Add New → Upload Plugin, choose the ZIP and install it.
- Activate. The defaults are safe to leave alone; everything else is optional.
Licensed GPL-2.0-or-later. No account, no licence key, no phone-home. Where a plugin can talk to an outside service, that is off until you switch it on.
Related
Want something like this built?
Everything on this page was designed, built and is run by one person. If you need the same for your business, tell me what you have in mind.
Book a call opens in a new tab ← Plugins