WordPress: Consciously configure login blocks and IP storage
Requirements
WordPress administration access; With reverse proxies, additional knowledge of the trustworthy source for the client IP.
Limit Login Attempts Reloaded limits login attempts based on IP address and username and can use cloud protection. For “We don’t save!” only capture security events, limit retention, and evaluate cloud functions separately. Also configure the trusted IP source behind proxies correctly.
Check
After the change, check browser memory, network connections and web server, proxy and application logs separately. A product setting does not automatically prove that no visitor IP is stored at all levels.
Classification
To differentiate between technically necessary processing, security logging and permanent storage, additionally use IP processing and IP storage: the crucial difference . Security data should be dedicated, access-restricted and only retained for as long as necessary.
Reduction
If the protection after the reduction is not sufficient, reactivate the required blocking logic and evaluate cloud functions and IP retention separately again.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.