Posted By Gregory

WP Cerber Security & Antispam

Professional grade WordPress security and anti-spam plugin. Protects from brute force attacks by limiting the number of login attempts through the login form, XML-RPC / REST API requests or using auth cookies. Restricts access with the Black IP Access List and the White IP Access List. Tracks user and intruder activity with powerful notifications.


Pack of useful and five star rated features you’ll love

See the full list of security features

Always improving

WP Cerber is an always-improving security plugin that gains new features every month. The author with his world-class engineering experience constantly iterates upon every part of plugin’s security algorithms making the plugin smarter and more reliable with every new release. Subscribe to Cerber’s newsletter to get early access to the latest technologies.





How does WP Cerber protect websites?

By default, WordPress allows unlimited login attempts through the login form, XML-RPC or by sending special cookies. This allows passwords to be cracked with relative ease via a brute-force attack.

WP Cerber blocks intruders by IP or subnet from making further attempts after a specified limit on retries is reached, making brute force attacks or distributed brute force attacks from botnets impossible.

With the plugin, you can create a Black IP Access List and White IP Access List to restrict logins from a particular IP address, subnet or IP range.

Moreover, you can create your Custom login page and forget about automatic attacks, which require constant attention and consumes significant server resources. If an attacker tries to access wp-login.php they will get a 404 Error response and, optionally, will be locked out for a configured period of time.

WP Cerber tracks time, IP addresses and usernames for successful and failed login attempts, logins, logouts, password changes, blocked IPs and actions taken by itself.

You can hide WordPress dashboard (/wp-admin/) when a user isn’t logged in. If the user isn’t logged in and they attempt to access the dashboard by requesting /wp-admin/, WP Cerber will return a 404 Error.

Massive botnet brute force attack? That’s no longer a problem. WP Cerber automatically activates Citadel mode after several unsuccessful login attempts and prevent your site from making further attempts to break in with any username.

What does “Cerber” mean?

Cerber is derived from the name Cerberus. In Greek and Roman mythology, Cerberus is a multi-headed dog with a serpent’s tail, a mane of snakes, and a lion’s claws. Nobody can bypass this angry dog. Now you can order WP Cerber to guard the entrance to your site too.

See people reviews from around the world Download plugin from WordPress.org
Do you have an idea for a cool new feature you would love to see in WP Cerber? Feel free to submit your idea here: New Feature Request

Last posts from WordPress security blog


I'm a team lead in Cerber Tech. I'm a software & database architect, WordPress - PHP - SQL - JavaScript developer. I started coding in 1993 on IBM System/370 (yeah, that was amazing days) and today software engineering at Cerber Tech is how I make my living. I've taught to have high standards for myself as well as using them in developing software solutions.