Description
At a glance
Looking for Phantom User Lockout v1.2.0? It is available here as a free GPL download for WordPress — updated September 29, 2026 · requires WordPress 6.2+ & PHP 7.2+.
Bots guess usernames like “admin” and “administrator”. On most sites those names don’t exist, so any attempt with them is a bot. Phantom User Lockout records each one and blocks the IP address that made it.
For every attempt with a username that doesn’t exist on your site, you get:
- The time, in site time with UTC on hover
- The username and the password that was tried
- The IP address, shown as IP Blocked, Not blocked or Safe
- Where the IP is: city, region and country
- Who owns it: the hosting company or network (for example “AS53667 FranTech Solutions”) and the reverse hostname
- How the attempt came in: the login form, XML-RPC (every guess inside a system.multicall batch gets its own row), REST API application passwords, or another login form
- The user agent and the requested URL
Blocking
- An IP is blocked after its first attempt with a username that doesn’t exist. You can raise that threshold.
- Blocks are permanent. They only lift when you press Unblock.
- A blocked visitor gets a 403 page that reads “IP Blocked”.
- By default a block covers the login page, XML-RPC, REST logins and any other form that logs in through WordPress. You can widen it to the whole site.
- Optionally, the plugin can also block IPs that enter the wrong password for a real username. This is off by default, and the default threshold is 3 wrong passwords.
Built not to lock you out
- Real accounts are never recorded unless you turn on the real-account option, and even then their passwords are never stored.
- If a username is within two letters of a real login or email, it’s treated as a typo by one of your own people. It’s logged with the password hidden and never causes a block.
- Safe IPs are never recorded or blocked. Add yours with one click: “Add my current IP address to the list”.
- A signed-in administrator is never blocked. Neither are the server’s own address and loopback.
- Emergency switch: add
define( 'BOTLO_DISABLE', true );to wp-config.php.
The plugin never edits .htaccess or any other server file.
External services
To show where an IP address is and who owns its network, the plugin looks the address up with ipinfo.io.
- What is sent: only the IP address that made the login attempt, plus your ipinfo.io token if you entered one in Settings. No information about your site, your users or your visitors is sent.
- When: once per new IP address, in the background shortly after its first attempt, or when an administrator opens the Phantom User Lockout screen while a lookup is still pending.
- Turning it off: Settings Location lookups.
- ipinfo.io terms of service: https://ipinfo.io/terms-of-service
- ipinfo.io privacy policy: https://ipinfo.io/privacy-policy
Privacy
The plugin stores IP addresses, user agents, usernames and passwords from failed login attempts that used usernames which don’t exist. It adds suggested wording to Settings Privacy Policy Guide.
Frequently asked questions
What is Phantom User Lockout?
Phantom User Lockout is a free WordPress plugin available under the GPL license. The current version is 1.2.0.
Is Phantom User Lockout free to download?
Yes — Phantom User Lockout 1.2.0 is a free GPL download with no hidden fees, no account needed, and no feature locked behind a paywall in this package.
How do I install Phantom User Lockout 1.2.0?
Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.
What are the requirements for Phantom User Lockout?
Phantom User Lockout 1.2.0 requires WordPress 6.2 or higher and PHP 7.2 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.
When was Phantom User Lockout last updated?
Version 1.2.0 was last updated on September 29, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.
Is the Phantom User Lockout download safe?
The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.
Technical details
| Version | 1.2.0 |
|---|---|
| Last updated | September 29, 2026 |
| Requires WordPress | 6.2 or higher |
| Requires PHP | 7.2 or higher |
| Author | efraing |
| Tags | block-ip, brute-force, honeypot, login, security |
Download Phantom User Lockout
Download Phantom User Lockout WP PluginNote: if the download does not start, disable your ad blocker and try again.