Developers
invisnet |
Download Stats
Today | 25 |
Yesterday | 69 |
Last Week | 449 |
All Time | 120,223 |
fail2ban is one of the simplest and most effective security measures you can implement to prevent brute-force attacks.
WP fail2ban logs all login attempts - including via XML-RPC, whether successful or not, to syslog using LOG_AUTH. For example:
Oct 17 20:59:54 foobar wordpress(www.example.com)[1234]: Authentication failure for admin from 192.168.0.1 Oct 17 21:00:00 foobar wordpress(www.example.com)[2345]: Accepted password for admin from 192.168.0.1
WPf2b comes with three fail2ban
filters: wordpress-hard.conf
, wordpress-soft.conf
, and wordpress-extra.conf
. These are designed to allow a split between immediate banning (hard) and the traditional more graceful approach (soft), with extra rules for custom configurations.
Features
Allow Pingbacks with XML-RPC Blocked [Premium only] Pingbacks might be a relic of a bygone age, but they're still nice to have. Wf2b can now allow Pingsbacks while blocking other XML-RPC requests.
Block XML-RPC Requests [Premium only] Allow access for Jetpack and other trusted IPs while blocking everything else; introduces a new "hard" filter.
Block Countries [Premium only] Nothing but attacks from some countries? Block them!
Multisite Support Version 4.3 introduced proper support for multisite networks.
Block username logins Sometimes it's not possible to block user enumeration (for example, if your theme provides Author profiles). Version 4.3 added support for requiring the use of email addresses for login.
Filter for Empty Username Login Attempts Some bots will try to login without a username. Version 4.3 logs these attempts and provides an "extra" filter to match them.
syslog Dashboard Widget Ever wondered what's being logged? The new dashboard widget shows the last 5 messages; the Premium version keeps a full history to help you analyse and prevent attacks.
-
Support for 3rd-party Plugins Version 4.2 introduced a simple API for authors to integrate their plugins with WPf2b, with 2 experimental add-ons:
- Contact Form 7
- Gravity Forms
CloudFlare and Proxy Servers WPf2b can be configured to work with CloudFlare and other proxy servers.
Comments WPf2b can log comments (see
WP_FAIL2BAN_LOG_COMMENTS
) and attempted comments (seeWP_FAIL2BAN_LOG_COMMENTS_EXTRA
).Pingbacks WPf2b logs failed pingbacks, and can log all pingbacks. For an overview see
WP_FAIL2BAN_LOG_PINGBACKS
.Spam WPf2b can log comments marked as spam. See
WP_FAIL2BAN_LOG_SPAM
.Block User Enumeration WPf2b can block user enumeration.
Work-Arounds for Broken syslogd WPf2b can be configured to work around most syslogd weirdness. For an overview see
WP_FAIL2BAN_SYSLOG_SHORT_TAG
andWP_FAIL2BAN_HTTP_HOST
.Blocking Users WPf2b can be configured to short-cut the login process when the username matches a regex. For an overview see
WP_FAIL2BAN_BLOCKED_USERS
.mu-plugins
Support WPf2b can easily be configured as a must-use plugin - see Configuration.
Releases (46 )
Version | Release Date | Change Log |
---|---|---|
4.4.0.9 | 2022-12-08 |
|
4.4.0.8 | 2022-11-03 |
|
4.4.0.6 | 2022-10-02 |
|
4.4.0.4 | 2022-03-04 |
|
4.4.0.3 | 2022-02-26 |
|
4.3.0.9 | 2020-12-31 |
|
4.3.0.8 | 2020-09-22 |
|
4.3.0.7 | 2020-08-15 |
|
4.3.0.6 | 2020-08-04 |
|
4.3.0.5 | 2020-07-30 |
|
4.3.0.4 | 2020-07-27 | To take advantage of the new features you will need up update your |
4.2.8.1 | 2020-05-04 | |
4.3.0-RC4 | 2020-04-30 | |
4.2.8 | 2020-04-17 |
|
4.3.0-RC3 | 2020-04-16 | |
4.2.7.1 | 2019-09-30 |
|
4.2.7 | 2019-09-24 |
|
4.2.6 | 2019-09-23 |
|
4.2.5 | 2019-07-15 |
|
4.2.4 | 2019-06-23 |
|
4.2.3 | 2019-05-16 |
|
4.2.2 | 2019-04-20 |
|
4.2.1 | 2019-04-20 |
|
4.1.0 | 2019-03-13 |
|
4.0.2 | 2019-01-28 |
|
4.0.1 | 2019-01-25 |
|
3.6.0 | 2018-11-07 |
|
3.5.3 | 2017-07-04 |
|
3.5.1 | 2016-08-09 |
|
3.5.0 | 2016-08-07 |
|
3.0.3 | 2016-07-07 |
|
3.0.2 | 2016-06-23 |
|
3.0.1 | 2016-04-21 |
|
3.0.0 | 2016-03-28 |
|
2.3.2 | 2015-10-21 |
|
2.3.1 | 2015-10-21 | |
2.3.0 | 2014-11-03 |
|
2.2.1 | 2014-08-09 |
|
2.2.0 | 2014-08-07 |
|
2.1.1 | 2014-03-03 |
|
2.1.0 | 2013-08-28 |
|
2.0.0 | 2013-08-05 |
|
1.2.1 | 2013-04-12 | Update FAQ. |
1.2 | 2012-12-20 | Fix harmless warning. |
1.1 | 2012-11-18 | Minor cosmetic updates. |
1.0 | 2012-10-19 | Initial release. |