Protection Against DDoS

Protects your WordPress site from DDoS and brute-force attacks. Ingeniously simple and VERY effective.

Author:WPChef (profile at
WordPress version required:3.5.2
WordPress version tested:5.4.10
Plugin version:1.5.2
Added to WordPress repository:01-07-2016
Last updated:29-04-2020
Warning! This plugin has not been updated in over 2 years. It may no longer be maintained or supported and may have compatibility issues when used with more recent versions of WordPress.
Rating, %:100
Rated by:4
Plugin URI:
Total downloads:41 393
Active installs:6 000+
plugin download
Click to start download

This plugin resolves performance issues caused by brute force attacks described in the WordPress Codex here:

From WordPress Codex:

Due to the nature of these attacks, you may find your server’s memory goes through the roof, causing performance problems. This is because the number of http requests (that is the number of times someone visits your site) is so high that servers run out of memory.

A common attack point on WordPress is to hammer the wp-login.php file over and over until they get in or the server dies. You can do some things to protect yourself.

Protection Against DDoS plugin addresses these issues very well.

It also allows to deny access to common WordPress features that get frequently attacked, like xmlrpc or RSS feeds pages.

CloudFlare users can allow or deny access for visitors from specified countries.

All checks are done via the .htaccess file so that bogus requests can’t even reach your WordPress site and get bounced at the web server level. You can also specify exactly where they can be bounced to.


  • Doesn’t have any known conflicts with any other security plugins.
  • Fully compatible with WordPress multisites.

Advanced users can get more technical information on the FAQ page.