Support
Log in Sign up

Brute-force protection and the login log (Free)

What it does: Counts failed logins per IP, locks the address out after the limit, and logs every attempt with the username tried and the country when it is known. How to access: GuardForge > Settings (limits), GuardForge > Login log (history), GuardForge > Unblock IP (release an address). Free/PRO: Free. Defaults: 5 attempts, 30-minute lockout, log kept 30 days. Notes:
  • Behind Cloudflare or another proxy the real client IP is read from the trusted-proxy chain, so a spoofed X-Forwarded-For cannot get somebody else locked out.
  • A row’s result is one of four values: success, failed, soft_locked (staging: counted, not enforced) or locked. The “Explain” button is drawn only on the three that went wrong — a successful login has nothing to explain, and paying a credit to be told so was the old behaviour.
  • Pro adds Cloudflare sync (a locked address is also blocked at the edge) and auto-lockdown (a burst of locked addresses can throw the whole site’s lockdown switch).
Forge AI Assistant Online

Hi! I'm the Guard Forge AI assistant. Ask me anything about the plugin — setup, features, troubleshooting, or development.

Just now
Powered by Forge AI · Browse docs