FAQ
What does it cost?
Lite is free, and it is not a trial: every authentication event, all three channels, blocked usernames, the generated filters and jails, and the console. Pro is $59 one-off, with an optional $29/year renewal for updates.
Why can't fail2ban do this on its own?
Your web server's log shows a 200 for a wrong password and a 200 for a right one. fail2ban
matches lines in log files, and there is no line that tells those two apart. Craft knows the
difference, so the plugin writes it down in a format fail2ban already understands, and fail2ban
does the banning.
Is this the same idea as wp-fail2ban?
Yes, deliberately. The log lines are craft(host)[pid]: where WordPress writes wp(host)[pid]:.
fail2ban's own common.conf already parses that shape, and an admin who runs both recognises the
lines on sight.
Does it replace Craft's own login cooldown?
No, it works alongside it. Craft's cooldown protects one account from one attacker. fail2ban protects the site from one address, across every account and every request, at the firewall. A credential-stuffing run tries one password against ten thousand accounts, and no account's cooldown ever triggers.
Do I need shell access?
To install fail2ban, yes. Without it, Pro's built-in blocker enforces the same jails in PHP. It is the weaker option: a firewall drop costs an attacker a TCP timeout, while the blocker still spends a PHP worker and a database read on every attempt. But it is far better than nothing.
Does it slow the site down?
Not on ordinary requests. The plugin does work only when Craft raises a security event, or when a response is an error (Pro). Writing an event means one syslog call, one append to a file and one database insert.
The built-in blocker, when on, adds one indexed lookup to every request.
Will it break my full-page cache?
No. The 404 path never starts a session, so it never adds a Set-Cookie header. See
Troubleshooting.
Can somebody get an innocent address banned?
The plugin is designed so they can't:
- The client address comes off the socket unless you have named the proxies allowed to set it.
- When proxy headers are trusted, the chain is read right to left from your own proxy, never from whatever the visitor put at the front.
- Nothing a visitor types can add a line to the log. Values are flattened onto one line before they are written, and every filter is anchored on the address at the end of the line.
events/testuses203.0.113.7, an address reserved for documentation.
The one configuration that does it is a site behind a proxy that the plugin hasn't been told about. Setup warns about exactly that.
What about privacy and GDPR?
Usernames, which on most Craft sites are email addresses, appear in the log by default, because
"five failures for one account" is a useful thing to see. Turn on pseudonymizeUsernames and the
log channels get a stable, keyed, one-way hash instead. Query-string values are never logged. The
database copy keeps 30 days by default, and IP addresses are personal data in most readings of the
GDPR, so set ledgerRetentionDays to what your privacy notice says.
Does it handle IPv6?
Yes, everywhere: logging, ignoreIps, trusted proxies, CIDR ranges and the built-in blocker.
Addresses are compared as bytes, so 2001:db8::1 and its fully expanded form are the same address.
Does it work on a multi-site install?
Yes. By default the name inside craft(…) is the request's host, so lines from each site can be
told apart, and one jail bans across all of them. Set ident to fix one name for every site.
Can I log my own events?
Yes, from Twig or PHP, through the same channels and jails. See Raising your own events.
What is the difference between Lite and Pro?
Lite covers authentication: every login, token and reset event, all three channels, blocked usernames, the generated filters and jails, and the console. Pro adds enumeration, path probes, HTTP status logging, GraphQL failures, registrations, the built-in blocker and ban emails. See Installation for the full table.