These files replace the standard locked out and blocked messages with the intent of providing minimal information to an attacker. The default messages break many security best practices in the interest of user friendliness, which is immeterial for websites that only have a handful of people logging in.
- The new lockout and blocked messages included in this repo are not user friendly
- These files must be re-copied after each Wordfence update, as the update will re-install the default files
- They are not recommended for use on sites that:
- Have many users logging in with username/password combinations
- Have users who frequently forget their passwords
- connect to your server via SFTP
- cd to
/wp-content/plugins/wordfence/lib
- backup the original files:
wf503.php
andwfLockedOut.php
- copy the files in this repo to
/wp-content/plugins/wordfence/lib
, and overwrite the existing files - NOTE: these files must be re-copied after each Wordfence update, as the update will re-install the default files