Title: Login Restrict
Author: skydev
Published: <strong>2019 年 7 月 27 日</strong>
Last modified: 2019 年 7 月 27 日

---

搜尋外掛

![](https://ps.w.org/login-restrict/assets/banner-772x250.jpg?rev=2129412)

這個外掛**並未在最新的 3 個 WordPress 主要版本上進行測試**。開發者可能不再對這個
外掛進行維護或提供技術支援，並可能會與更新版本的 WordPress 產生使用上的相容性問題。

![](https://ps.w.org/login-restrict/assets/icon.svg?rev=2129401)

# Login Restrict

 由 [skydev](https://profiles.wordpress.org/skydev/) 開發

[下載](https://downloads.wordpress.org/plugin/login-restrict.zip)

 * [詳細資料](https://tw.wordpress.org/plugins/login-restrict/#description)
 * [使用者評論](https://tw.wordpress.org/plugins/login-restrict/#reviews)
 *  [安裝方式](https://tw.wordpress.org/plugins/login-restrict/#installation)
 * [開發資訊](https://tw.wordpress.org/plugins/login-restrict/#developers)

 [技術支援](https://wordpress.org/support/plugin/login-restrict/)

## 外掛說明

By default WordPress allows unlimited login attempts through the login page but 
this will lock account after number of login attempts

Features

 * Limit the number of login attempts
 * Informs user about remaining attempts or block time on login page
 * Optional logging, optional email notification
 * Handles server behind reverse proxy
 * It is possible to whitelist IPs using a filter.

Plugin uses standard actions and filters only.

## 螢幕擷圖

[⌊screenshot-1.png⌉⌊screenshot-1.png⌉[

screenshot-1.png

[⌊screenshot-2.png⌉⌊screenshot-2.png⌉[

screenshot-2.png

[⌊screenshot-3.png⌉⌊screenshot-3.png⌉[

screenshot-3.png

## 安裝方式

 1. Download and extract plugin files to a wp-content/plugin directory.
 2. Activate the plugin through the WordPress admin interface.
 3. Customize the settings on the options page, if desired. If your server is located
    behind a reverse proxy make sure to change this setting.

## 常見問題集

  Why not reset failed attempts on a successful login?

This is very much by design. Otherwise you could brute force the “admin” password
by logging in as your own user every 4th attempt.

  What is this option about site connection and reverse proxy?

A reverse proxy is a server in between the site and the Internet (perhaps handling
caching or load-balancing). This makes getting the correct client IP to block slightly
more complicated.

The option default to NOT being behind a proxy — which should be by far the common
case.

  How do I know if my site is behind a reverse proxy?

You probably are not or you would know. We show a pretty good guess on the option
page. Set the option using this unless you are sure you know better.

  Can I whitelist my IP so I don’t get block?

First please consider if you really need this. Generally speaking it is not a good
idea to have exceptions to your security policies.

That said, there is now a filter which allows you to do it: “login_lmt_whitelist_ip”.

Example:
 function my_ip_whitelist($allow, $ip) { return ($ip == ‘my-ip’) ? true:
$allow; } add_filter(‘login_lmt_whitelist_ip’, ‘my_ip_whitelist’, 10, 2);

Note that we still do notification and logging as usual. This is meant to allow 
you to be aware of any suspicious activity from whitelisted IPs.

  I locked myself out testing this thing, what do I do?

Either wait, or:

If you know how to edit / add to PHP files you can use the IP whitelist functionality
described above. You should then use the “Restore Lockouts” button on the plugin
settings page and remove the whitelist function again.

If you have ftp / ssh access to the site rename the file “wp-content/plugins/login-
limit/login-limit.php” to deactivate the plugin.

If you have access to the database (for example through phpMyAdmin) you can clear
the login_lmt_blocks option in the wordpress options table. In a default setup this
would work: “UPDATE wp_options SET option_value = ” WHERE option_name = ‘login_lmt_blocks’”

## 使用者評論

這個外掛目前沒有任何使用者評論。

## 參與者及開發者

以下人員參與了開源軟體〈Login Restrict〉的開發相關工作。

參與者

 *   [ Skynet Technologies USA LLC ](https://profiles.wordpress.org/skydev/)
 *   [ wordpress.org ](https://profiles.wordpress.org/wordpressorg-1/)

[將〈Login Restrict〉外掛本地化為台灣繁體中文版](https://translate.wordpress.org/projects/wp-plugins/login-restrict)

### 對開發相關資訊感興趣？

任何人均可[瀏覽程式碼](https://plugins.trac.wordpress.org/browser/login-restrict/)、
查看 [SVN 存放庫](https://plugins.svn.wordpress.org/login-restrict/)，或透過 [RSS](https://plugins.trac.wordpress.org/log/login-restrict/?limit=100&mode=stop_on_copy&format=rss)
訂閱[開發記錄](https://plugins.trac.wordpress.org/log/login-restrict/)。

## 變更記錄

#### 1.0

 * Initial version

## 中繼資料

 *  版本 **1.0**
 *  最後更新 **7 年前**
 *  啟用安裝數 **10+**
 *  WordPress 版本需求 ** 3.0.1 或更新版本 **
 *  已測試相容的 WordPress 版本 **5.2.26**
 *  PHP 版本需求 ** 5.6 或更新版本 **
 *  語言
 * [English (US)](https://wordpress.org/plugins/login-restrict/)
 * 標籤:
 * [authentication](https://tw.wordpress.org/plugins/tags/authentication/)[login](https://tw.wordpress.org/plugins/tags/login/)
   [security](https://tw.wordpress.org/plugins/tags/security/)
 *  [進階檢視](https://tw.wordpress.org/plugins/login-restrict/advanced/)

## 評分

這個項目尚無任何評論記錄。

[撰寫評分](https://wordpress.org/support/plugin/login-restrict/reviews/#new-post)

[查看全部使用者評論](https://wordpress.org/support/plugin/login-restrict/reviews/)

## 參與者

 *   [ Skynet Technologies USA LLC ](https://profiles.wordpress.org/skydev/)
 *   [ wordpress.org ](https://profiles.wordpress.org/wordpressorg-1/)

## 技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

 [檢視技術支援論壇](https://wordpress.org/support/plugin/login-restrict/)

## 贊助

想要支援這個外掛的發展嗎？

 [ 贊助這個外掛 ](https://skynetindia.info)