Title: Phantom User Lockout
Author: efraing
Published: <strong>ستمبر 29, 2026</strong>
Last modified: ستمبر 29, 2026

---

Search plugins

![](https://ps.w.org/phantom-user-lockout/assets/banner-772x250.png?rev=3719463)

![](https://ps.w.org/phantom-user-lockout/assets/icon-256x256.png?rev=3719463)

# Phantom User Lockout

 By [efraing](https://profiles.wordpress.org/efraing/)

[Download](https://downloads.wordpress.org/plugin/phantom-user-lockout.1.2.0.zip)

 * [Details](https://bcc.wordpress.org/plugins/phantom-user-lockout/#description)
 * [Reviews](https://bcc.wordpress.org/plugins/phantom-user-lockout/#reviews)
 *  [Installation](https://bcc.wordpress.org/plugins/phantom-user-lockout/#installation)
 * [Development](https://bcc.wordpress.org/plugins/phantom-user-lockout/#developers)

 [Support](https://wordpress.org/support/plugin/phantom-user-lockout/)

## Description

Bots guess usernames like “admin” and “administrator”. On most sites those names
don’t exist, so any attempt with them is a bot. Phantom User Lockout records each
one and blocks the IP address that made it.

For every attempt with a username that doesn’t exist on your site, you get:

 * The time, in site time with UTC on hover
 * The username and the password that was tried
 * The IP address, shown as **IP Blocked**, **Not blocked** or **Safe**
 * Where the IP is: city, region and country
 * Who owns it: the hosting company or network (for example “AS53667 FranTech Solutions”)
   and the reverse hostname
 * How the attempt came in: the login form, XML-RPC (every guess inside a system.
   multicall batch gets its own row), REST API application passwords, or another
   login form
 * The user agent and the requested URL

#### Blocking

 * An IP is blocked after its first attempt with a username that doesn’t exist. 
   You can raise that threshold.
 * Blocks are permanent. They only lift when you press **Unblock**.
 * A blocked visitor gets a 403 page that reads “IP Blocked”.
 * By default a block covers the login page, XML-RPC, REST logins and any other 
   form that logs in through WordPress. You can widen it to the whole site.
 * Optionally, the plugin can also block IPs that enter the wrong password for a
   real username. This is off by default, and the default threshold is 3 wrong passwords.

#### Built not to lock you out

 * Real accounts are never recorded unless you turn on the real-account option, 
   and even then their passwords are never stored.
 * If a username is within two letters of a real login or email, it’s treated as
   a typo by one of your own people. It’s logged with the password hidden and never
   causes a block.
 * **Safe IPs** are never recorded or blocked. Add yours with one click: “Add my
   current IP address to the list”.
 * A signed-in administrator is never blocked. Neither are the server’s own address
   and loopback.
 * Emergency switch: add `define( 'BOTLO_DISABLE', true );` to wp-config.php.

The plugin never edits .htaccess or any other server file.

### External services

To show where an IP address is and who owns its network, the plugin looks the address
up with **ipinfo.io**.

 * **What is sent:** only the IP address that made the login attempt, plus your 
   ipinfo.io token if you entered one in Settings. No information about your site,
   your users or your visitors is sent.
 * **When:** once per new IP address, in the background shortly after its first 
   attempt, or when an administrator opens the Phantom User Lockout screen while
   a lookup is still pending.
 * **Turning it off:** Settings  Location lookups.
 * ipinfo.io terms of service: https://ipinfo.io/terms-of-service
 * ipinfo.io privacy policy: https://ipinfo.io/privacy-policy

### Privacy

The plugin stores IP addresses, user agents, usernames and passwords from failed
login attempts that used usernames which don’t exist. It adds suggested wording 
to Settings  Privacy  Policy Guide.

## Installation

 1. Upload the plugin through Plugins  Add New  Upload Plugin, or install it from the
    directory.
 2. Activate it.
 3. Open **Phantom User Lockout** in the admin menu, go to **Blocked & Safe IPs** and
    click **Add my current IP address to the list**. Do the same from every place you
    or your staff log in.
 4. If your site is behind a proxy or CDN and every visitor shows the same IP, change**
    Visitor IP comes from** in Settings.

## FAQ

### I locked myself out.

Add `define( 'BOTLO_DISABLE', true );` to wp-config.php, or rename the plugin’s 
folder over FTP. Then log in, unblock your IP, add it to Safe IPs, and remove the
line.

### Why record the password?

It shows you which password lists are being used against your site. It’s only recorded
for usernames that don’t exist, so it never belongs to a real account. You can turn
it off under Settings  Passwords.

### Does it replace a lockout plugin like Limit Login Attempts?

It can run next to one. Those plugins lock an IP out for a while after failed logins.
Phantom User Lockout records what was tried and blocks the IP permanently.

### Can it block the whole site, not just the login page?

Yes: Settings  “A blocked IP cannot reach”. Pages served from a caching plugin’s
disk cache never reach WordPress, so those can’t be covered.

### Where is the data kept?

In two database tables of the plugin’s own. Attempt rows are removed after 180 days
or 100,000 rows, whichever comes first, and you can change both limits. Blocked 
IPs are kept until you unblock them. Deactivating the plugin keeps everything. Deleting
the plugin removes the tables and the settings.

### Where do I get help?

Post in the plugin’s support forum at https://wordpress.org/support/plugin/phantom-
user-lockout/. Include your WordPress and PHP versions, and what you see in the 
Attempts log. Don’t post passwords or your own IP address there, because the forum
is public.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Phantom User Lockout” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ efraing ](https://profiles.wordpress.org/efraing/)

[Translate “Phantom User Lockout” into your language.](https://translate.wordpress.org/projects/wp-plugins/phantom-user-lockout)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/phantom-user-lockout/),
check out the [SVN repository](https://plugins.svn.wordpress.org/phantom-user-lockout/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/phantom-user-lockout/)
by [RSS](https://plugins.trac.wordpress.org/log/phantom-user-lockout/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.2.0

 * Renamed from Login Lockout to Phantom User Lockout.

#### 1.1.0

 * First public release.
 * Records login attempts with usernames that don’t exist, including the password
   tried, the IP’s location and its hosting company.
 * Permanent IP blocks, lifted only by Unblock.
 * Safe IPs, with a one-click “Add my current IP address to the list”.
 * Optional blocking after wrong passwords for real accounts (default 3).
 * Option to stop recording passwords.
 * CSV export.

## Meta

 *  Version **1.2.0**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.2 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/phantom-user-lockout/)
 * Tags
 * [block ip](https://bcc.wordpress.org/plugins/tags/block-ip/)[Brute Force](https://bcc.wordpress.org/plugins/tags/brute-force/)
   [honeypot](https://bcc.wordpress.org/plugins/tags/honeypot/)[login](https://bcc.wordpress.org/plugins/tags/login/)
   [security](https://bcc.wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://bcc.wordpress.org/plugins/phantom-user-lockout/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/phantom-user-lockout/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/phantom-user-lockout/reviews/)

## Contributors

 *   [ efraing ](https://profiles.wordpress.org/efraing/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/phantom-user-lockout/)