Login Obfuscator is a WordPress plugin that changes how failed login attempts are answered, with the stated aim of making login responses less predictable to brute-force bots. On failed logins, it sends HTTP 403 Forbidden instead of the HTTP 200 OK status that WordPress normally returns, and the page says this can confuse automated tools that rely on predictable response codes.
Its documented behavior is limited to a basic form of login URL obfuscation. The description says it is meant to confuse trivial automated scanners and brute-force scripts, and that some bots may slow down or stop attacking after receiving the 403 response. It is described as a first-step mitigation rather than a comprehensive security solution, and it is explicitly presented as one layer in a broader security strategy. The same text recommends combining it with strong passwords, two-factor authentication, login attempt limits, WordPress and plugin updates, and a web application firewall or security plugin.
The plugin is offered for WordPress. The page includes a GitHub source-code link and a WordPress.org download link, indicating that it is available through WordPress.org and has source code on GitHub.
In the Security & compliance platforms space, Login Obfuscator takes a focused approach. It focuses on reducing the risk of brute-force attacks on WordPress sites by making login responses less predictable. Login Obfuscator is a consumer product aimed at wordPress site owners and administrators. It is available for free. It ships for the web.
Login Obfuscator first shipped in 2025. Among its 4 catalogued features are HTTP 403 on failed login, brute-force protection, and Login URL obfuscation.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do