Hello,
let me shed some light on the general concept of Admin Tools. Our extension will protect your website on several layers, both with the .htaccess file and with the system plugin.
The system plugin is a little more clever than the .htaccess file, since it allows us to perform some reasoning before blocking an IP. A visitor could trigger several different security exceptions, if they are configured to be logged and it pass the frequency threshold, it will be blocked.
For example, inside WAF Configuration, you can tell Admin Tools to treat failed logins as security exceptions. This means that a visitor that is failing to login will be handled as if he was creating a malicious request, therefore it will be blocked in the same way.
Moreover, in the Hardening Options tab, you can tell Admin Tools to disable a user after he failed to login for a specific amount of times.
Hope this helps.
Davide Tampellini
Developer and Support Staff
🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!