Login protection now only counts failed logins, so it no longer gets in the way of real people.
What we fixed
Before, simply opening the login page counted as an attempt. Logging out and back in a few times could lock you out of wp-admin for a while, even though you never typed a wrong password.
How it works now
- Only wrong passwords count - opening the login page, logging out or being asked to log in again no longer counts
- Attackers are still stopped - after five wrong passwords, logins from that address are paused for about ten minutes
No action needed on your end.