The Login Protection protects your Box's WordPress login from automated login attempts. If incorrect credentials are repeatedly entered from the same IP address, the Login Protection can temporarily block further login attempts from that IP address.
This prevents an IP address from making an unlimited number of login attempts.
You can find the Login Protection under Box > Settings > Security > Login Protection in the menu on the left.
How does Login Protection work?
Login Protection tracks failed attempts to log in to WordPress. If an IP address exceeds the number of failed attempts you've set, it will be blocked for the specified period.
You can configure both the number of allowed failed attempts and how long an IP address remains blocked in your Box settings.
💡 Your own IP address can also be blocked.
This can happen, for example, if you enter your password incorrectly several times and exceed the number of failed attempts you've configured.
If your IP address has been blocked, you may see the following message when trying to access the WordPress login:
"Your IP address has been banned from this site or you are not allowed to access this page."
How many failed login attempts can I allow?
Under Login attempts until lockout, you can set how many failed login attempts are allowed before an IP address is blocked.
Once this limit is exceeded, Login Protection blocks further login attempts from that IP address.
How long are IP addresses blocked?
Under Lockout duration (seconds), you can set how long an IP address remains blocked.
The lockout duration must be at least 600 seconds (10 minutes).
Once the specified time has passed, the IP address is automatically unblocked.
💡 Changes to your Login Protection settings can take up to 10 minutes to take effect. This also applies when unblocking previously blocked IP addresses.
Wo sehe ich geblockte IP Adressen?
1️⃣ Open Login Protection
Go to Box > Settings > Security > Login Protection in the menu on the left.
2️⃣ Open the list of locked out IP addresses
Click the grey arrow down button "Show locked out IPs" at the top of the Login Protection settings.
3️⃣ Check the locked out IP addresses
The list shows the IP addresses or hosts that have been locked out, the time of the lockout, and the available action for each entry.
How can I unblock IP addresses?
You can unblock individual IP addresses from the list of locked out IPs.
To reset the blocked attempts and unblock all currently locked out IP addresses, click Reset attempt counter at the top of the Login Protection settings.
Please note that it can take up to 10 minutes for the IP addresses to be unblocked.
My IP address has been locked out – what can I do?
If your own IP address has been locked out after too many failed login attempts, you can unblock it directly in the Login Protection settings.
1️⃣ Open Login Protection
Go to Box > Settings > Security > Login Protection in the menu on the left.
2️⃣ View the locked out IP addresses
Show locked out IPs by clicking on the grey arrow down button to open the list of currently locked out IP addresses.
3️⃣ Unblock your IP address
Find your IP address in the list and use the available action to unblock it.
Alternatively, you can click Reset attempt counter to reset the blocked attempts and unblock all currently locked out IP addresses.
💡 It can take up to 10 minutes for the IP address to be unblocked. Avoid making repeated login attempts during this time.
How can I add an IP address to the whitelist?
IP addresses on the Whitelist will not be blocked by Login Protection.
Enter the IP address you want to allow in the Whitelist field.
Add one entry per line, then click SAVE to confirm your changes.
You can add both individual IP addresses and IP ranges.
💡 Using a dynamic IP address? If your public IP address changes regularly, a whitelist entry only applies to the IP address currently listed.
How can I enable lockout notifications?
Under Notifications, enable Enable email notifications in case of lockout events and enter the email address where you want to receive the notifications.
You'll receive an email whenever Login Protection registers a new lockout.
💡 Brute force attacks and other automated login attempts are common on publicly accessible WordPress websites.
Depending on your website, enabling notifications may therefore result in a large number of emails.
Can I disable Login Protection?
Yes. However, we recommend keeping Login Protection enabled.
If you disable it, repeated failed login attempts will no longer be limited by Login Protection.
If you temporarily disable the feature for troubleshooting or a specific use case, we recommend enabling it again afterward.
An easier way to log in to WordPress with Single Sign On
With our Single Sign On, you can log in to WordPress directly from the Raidboxes Dashboard without having to enter your WordPress login credentials again.
This is particularly useful if you frequently mistype your WordPress credentials or don't have your password at hand. It helps you avoid failed login attempts through the standard WordPress login page.
Single Sign On does not replace Login Protection. Login Protection continues to protect the standard WordPress login from repeated failed login attempts.
🔐 Add an extra layer of protection to your WordPress login
In addition to Login Protection, you can add another layer of protection in front of your WordPress login using the server-side Website Access feature in your Box Overview.
Select Protect WordPress Login. Users will then need to enter the additional username and password before they can access the WordPress login page.
The username is predefined by Raidboxes and cannot be changed.
The password is generated automatically. You can change it yourself or use the corresponding button to generate a new password.
Under Website Access, you can choose which part of your website you want to protect:
No additional protection
Protect entire website
Protect WordPress Login
💡 Login Protection and Website Access are two different security features.
Login Protection limits repeated failed WordPress login attempts based on the IP address.
Protect WordPress Login via the Website access , on the other hand, adds an additional server-side password prompt before the WordPress login itself. You can use both features at the same time.
For more information, see Website Access – Password Protection.








