[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsJquj-H_HHTRVQSX-gsjhkINIMR6svbdiAGGXrAvB7I":3,"$fAyjiwhwWPeHhEZjrn5Dasu_9tF8rBXs_FH8icsykaYU":138,"$fOvHqTqVwMuF-_ceY_sJeus3xSYG_z0lHzfwJYSiBacs":143},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":27,"fingerprints":27},"defyn-security-manager","Defyn Security Manager – Hide Login, 2FA & Brute-Force Protection","1.2.1","Defyn","https:\u002F\u002Fprofiles.wordpress.org\u002Fdefyndigital\u002F","\u003Cp>\u003Cstrong>Defyn Security Manager is a lightweight WordPress security plugin that hides your login page and locks down the back end.\u003C\u002Fstrong> Most attacks on WordPress start at one predictable place: \u003Ccode>\u002Fwp-admin\u003C\u002Fcode> and \u003Ccode>\u002Fwp-login.php\u003C\u002Fcode>. Defyn Security Manager moves that door, throttles attackers, adds two-factor authentication, and records every attempt so you always know who is knocking.\u003C\u002Fp>\n\u003Cp>No bloat, no upsell walls, and no account required. Install it, choose a secret login slug, and your login page disappears from bots and scanners.\u003C\u002Fp>\n\u003Ch4>What it does\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Hide the WordPress login URL.\u003C\u002Fstrong> Replace \u003Ccode>\u002Fwp-admin\u003C\u002Fcode> and \u003Ccode>\u002Fwp-login.php\u003C\u002Fcode> with any custom login URL you choose, so automated bots and brute-force scripts hit a dead end.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Decoy or 404 the old URLs.\u003C\u002Fstrong> Decide what attackers see at the original login addresses: a 404, a redirect, or a decoy login screen.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute-force protection.\u003C\u002Fstrong> Limit login attempts and automatically lock out IP addresses after repeated failures, with a one-click control to clear active lockouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-factor authentication (2FA).\u003C\u002Fstrong> Add TOTP-based two-factor authentication using Google Authenticator, Authy, 1Password, Microsoft Authenticator or Bitwarden, complete with backup codes and per-role enforcement.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API and XML-RPC protection.\u003C\u002Fstrong> Extend two-factor enforcement to the REST API and XML-RPC, with optional API hiding to shrink your attack surface.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Time-window access control.\u003C\u002Fstrong> Only allow logins during the hours and days you actually work, and block everything else.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP allowlisting.\u003C\u002Fstrong> Optionally restrict back-end access to trusted IP addresses or CIDR ranges.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity log and audit trail.\u003C\u002Fstrong> See login attempts, lockouts, scans of your old login URLs, and settings changes in one searchable log.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email alerts.\u003C\u002Fstrong> Get notified about lockouts, scans, and logins from new IP addresses.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why choose Defyn Security Manager\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Fast and focused.\u003C\u002Fstrong> A purpose-built login-security and login-hardening plugin, not a heavyweight suite that slows your site down.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recovery built in.\u003C\u002Fstrong> A documented emergency kill switch means you can never permanently lock yourself out.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy friendly.\u003C\u002Fstrong> Your data stays on your site. Nothing is sent to a third-party service.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built by an agency.\u003C\u002Fstrong> Maintained by \u003Ca href=\"https:\u002F\u002Fdefyn.com.au\" rel=\"nofollow ugc\">Defyn\u003C\u002Fa>, an Australian web design and development studio that runs this plugin on client sites every day.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Defyn Security Manager is ideal for anyone who wants to hide wp-admin, stop brute-force login attempts, limit login attempts, add 2FA to WordPress, and keep a clear security audit trail.\u003C\u002Fp>\n","Hide wp-admin behind a custom login URL and stop brute-force attacks with two-factor authentication, login limits, IP rules and an activity log.",20,202,0,"2026-07-17T04:48:00.000Z","6.8.6","5.8","7.4",[19,20,21,22,23],"brute-force","hide-login","login","security","two-factor","https:\u002F\u002Fdefyn.com.au\u002Fplugins\u002Fdefyn-security-manager","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdefyn-security-manager.1.2.1.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"defyndigital",2,30,94,"2026-08-24T01:17:41.374Z",[38,59,79,101,121],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":26,"num_ratings":48,"last_updated":49,"tested_up_to":50,"requires_at_least":51,"requires_php":52,"tags":53,"homepage":55,"download_link":56,"security_score":26,"vuln_count":57,"unpatched_count":13,"last_vuln_date":58,"fetched_at":28},"xo-security","XO Security","3.11.0","ishitaka","https:\u002F\u002Fprofiles.wordpress.org\u002Fishitaka\u002F","\u003Cp>XO Security is a plugin to enhance login related security.\u003Cbr \u002F>\nThis plugin does not write to .htaccess file. Besides Apache, LiteSpeed, Nginx and IIS also work.\u003C\u002Fp>\n\u003Ch4>Functions\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Record login log.\u003C\u002Fli>\n\u003Cli>Limit login attempts.\u003C\u002Fli>\n\u003Cli>Add Captcha to the login form and comment form.\u003C\u002Fli>\n\u003Cli>Change the URL of the login page.\u003C\u002Fli>\n\u003Cli>Enable two-factor authentication (2FA) for login.\u003C\u002Fli>\n\u003Cli>Login Alert.\u003C\u002Fli>\n\u003Cli>Disable login by mail address.\u003C\u002Fli>\n\u003Cli>Disable login by user name.\u003C\u002Fli>\n\u003Cli>Change login error message.\u003C\u002Fli>\n\u003Cli>Disable XML-RPC and XML-RPC Pingback.\u003C\u002Fli>\n\u003Cli>Disable REST API.\u003C\u002Fli>\n\u003Cli>Disable author archive page.\u003C\u002Fli>\n\u003Cli>Remove comment author class of comments list.\u003C\u002Fli>\n\u003Cli>Remove the username from the oEmbed response data.\u003C\u002Fli>\n\u003Cli>WooCommerce login page protection.\u003C\u002Fli>\n\u003Cli>Anti-spam comment.\u003C\u002Fli>\n\u003Cli>Hide WordPress version information.\u003C\u002Fli>\n\u003Cli>Edit the author slug.\u003C\u002Fli>\n\u003Cli>Disable RSS and Atom feeds.\u003C\u002Fli>\n\u003Cli>Activate maintenance mode.\u003C\u002Fli>\n\u003Cli>Delete the readme.html file.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WordPress multisite considerations\u003C\u002Fh4>\n\u003Cp>If you set the login page separately for the main site and the subsite, you will not be able to use the password loss function of the subsite. We recommend that you set the login page to be common to all sites.\u003C\u002Fp>\n","XO Security is a plugin to enhance login related security.",30000,397056,11,"2026-07-19T10:16:00.000Z","7.0.2","6.0","7.2",[19,21,54,22,23],"maintenance","https:\u002F\u002Fxakuro.com\u002Fwordpress\u002Fxo-security\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fxo-security.3.11.0.zip",1,"2017-02-07 00:00:00",{"slug":60,"name":61,"version":62,"author":63,"author_profile":64,"description":65,"short_description":66,"active_installs":67,"downloaded":68,"rating":26,"num_ratings":69,"last_updated":70,"tested_up_to":50,"requires_at_least":71,"requires_php":72,"tags":73,"homepage":77,"download_link":78,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"login-armor","Login Armor","2.4.5","wpformation","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpformation\u002F","\u003Cp>\u003Cstrong>Twelve security modules. One lightweight plugin. Zero compromise.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Login Armor is a complete WordPress security stack built for agencies, freelancers and pros who deliver audit-ready sites. No premium tier, no bundled marketing dashboard, no telemetry. Every module runs locally, ships with safe defaults, and stays out of your way.\u003C\u002Fp>\n\u003Cp>Stop juggling Wordfence’s bloat, Solid Security’s upsells, and Limit Login Attempts’ gaps — Login Armor delivers twelve independent modules in about one megabyte.\u003C\u002Fp>\n\u003Ch4>New in 2.4.0\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Request Firewall\u003C\u002Fstrong> — an optional, 8G-inspired PHP filter that blocks malicious requests (SQL injection, code execution, traversal, XSS, disallowed HTTP methods) before WordPress finishes loading, on Apache, Nginx and LiteSpeed alike. Off by default, it starts in monitor mode and never filters logged-in administrators; every block is logged, aggregated to one incident per IP per hour.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Guided onboarding\u003C\u002Fstrong> — a first-run wizard offers a one-click “safe baseline” that turns on the no-risk essentials, so a beginner is protected in seconds. The same “Apply safe baseline” button stays available any time.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Login Armor\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>No upsells, ever.\u003C\u002Fstrong> No “premium” tier, no greyed-out “Pro” buttons. Every feature is GPL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No external services to sign up for.\u003C\u002Fstrong> No API keys, no remote dashboards, no telemetry. The only outbound calls are opt-in: Have I Been Pwned (breach\u002Fpassword checks), Slack\u002FDiscord\u002Fwebhook (notifications), the keyless ipwho.is API (geolocation), and your own WordPress 7 AI connector.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built to be invisible.\u003C\u002Fstrong> Sub-megabyte ZIP, lazy-loaded modules, indexed queries — under 2 ms on a normal login flow.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multisite-aware, PHP 8.1-native, production-grade defaults.\u003C\u002Fstrong> Network-activate a fleet, configure per-site, manage from a complete WP-CLI suite; zero-config gets you 80 percent of the protection.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Twelve independent modules\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Hide Login\u003C\u002Fstrong> — Replace wp-login.php with a custom slug; the old URL returns a 404, and a branded pre-activation modal lets you pick or generate the slug and emails it to you so you can’t lock yourself out. Compatible with multisite, reverse proxies and password-recovery flows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute Force Protection\u003C\u002Fstrong> — Cascading lockouts escalating to a 24-hour ban, with subnet blocking and trusted X-Forwarded-For; lostpassword, register, XML-RPC and the REST users endpoint are all gated when an IP is locked, and every lockout surfaces as an incident.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hardening\u003C\u002Fstrong> — Fifteen one-click toggles across surface reduction, credential hardening, request filtering and account monitoring: disable XML-RPC\u002Fpingbacks, the file editor, version exposure, application passwords and author enumeration; block reserved usernames (Unicode-confusable detection); add a login honeypot; get alerted on new administrators.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Factor Authentication\u003C\u002Fstrong> — TOTP, one-time codes by email and printable backup codes, with trusted devices for thirty days, per-role enforcement, a configurable grace period and an email recovery flow when the authenticator is lost.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Detection and Incidents\u003C\u002Fstrong> — A real-time engine groups raw events into six attack patterns, each with a drill-down (timeline, source IPs, target users, severity, UA fingerprint) and one-click actions (reset password, block subnet, mark resolved).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity Log\u003C\u002Fstrong> — A compliance-ready, tamper-evident (hash-chained) audit trail of admin actions across seven logger domains, with filtering, CSV export, configurable retention and optional signed webhook forwarding to a SIEM.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Page Security Headers\u003C\u002Fstrong> — Content-Security-Policy, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options on wp-login.php and the lockout page, in two presets with an optional CSP report-uri; baseline headers can optionally extend site-wide.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Breach Check\u003C\u002Fstrong> — Detect logins using a breached password via privacy-preserving k-anonymity against Have I Been Pwned (only a 5-character SHA-1 prefix leaves the server); optional XposedOrNot email lookup, fail-soft so an outage never blocks login.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password Policy\u003C\u002Fstrong> — Enforce strong, unique passwords at registration, profile update and reset: minimum length and character classes, forbid the username inside the password, optionally reject breached passwords, with optional non-locking expiration nudges.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Management\u003C\u002Fstrong> — Idle-timeout logout measured on real page loads, a maximum session lifetime regardless of “remember me”, an optional single-active-device restriction, and a one-click “sign out all other devices”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Geolocation\u003C\u002Fstrong> — Show the attacker’s country on the Incidents and Events tabs; lazy, cached thirty days, capped per page load, private ranges never sent. Keyless ipwho.is by default, swappable for an offline database via a filter.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Request Firewall\u003C\u002Fstrong> — An optional, 8G-inspired PHP filter that blocks malicious query strings, paths, HTTP methods and (opt-in) user-agents\u002Freferrers before WordPress loads, on Apache\u002FNginx\u002FLiteSpeed alike; off by default, starts in monitor mode, never filters admins, skips REST\u002Fcron\u002FWP-CLI, with an IP\u002Fpath allowlist (CIDR). Not scored.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>AI Security Briefing (optional)\u003C\u002Fh4>\n\u003Cp>Built on the WordPress 7 native AI Client, one click turns your last thirty days of activity into a plain-language verdict, an IP picture and a short list of prioritised actions; “Explain with AI” does the same on a single incident. Minimised mode (anonymised signals) is the default and deep mode is an explicit opt-in. No API key is stored — it uses your own WordPress AI connector, so provider and cost stay yours. It always leads with a deterministic facts snapshot that works with or without AI.\u003C\u002Fp>\n\u003Ch4>Plus\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Guided onboarding\u003C\u002Fstrong> — a first-run wizard with a one-click safe baseline (Simple) or manual setup (Advanced); the “Apply safe baseline” button stays available, and upgrading sites never see the wizard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security score\u003C\u002Fstrong> — a weighted 0-100 read of your posture with a one-click “next best action”; observability features (geolocation, notifications, the AI assistant) are deliberately not scored.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conflict detection\u003C\u002Fstrong> — warns when another login-security plugin (Wordfence, Solid Security, Sucuri, All-In-One Security, SecuPress and more) or a cache plugin (with Hide Login on) could clash.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notifications\u003C\u002Fstrong> — email, Slack, Discord or webhook with SSRF-safe URL validation, severity threshold and rate limiting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-CLI suite\u003C\u002Fstrong> and a \u003Cstrong>dashboard widget\u003C\u002Fstrong> (14-day sparkline, six headline metrics).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Douze modules de sécurité. Une seule extension légère. Zéro compromis.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Login Armor est une stack complète de sécurité WordPress conçue pour les agences, les freelances et les pros qui livrent des sites prêts à passer un audit. Pas de version premium, pas de tableau de bord marketing intégré, pas de télémétrie. Chaque module tourne en local, embarque des réglages par défaut sécurisés, et reste discret.\u003C\u002Fp>\n\u003Cp>Fini de jongler entre la lourdeur de Wordfence, les fenêtres d’upsell de Solid Security et les angles morts de Limit Login Attempts — Login Armor regroupe douze modules indépendants en environ un méga-octet.\u003C\u002Fp>\n\u003Ch4>Nouveau en 2.4.0\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Pare-feu de requêtes\u003C\u002Fstrong> : un filtre PHP optionnel, inspiré du pare-feu 8G, qui bloque les requêtes malveillantes (injection SQL, exécution de code, traversée de répertoires, XSS, méthodes HTTP non autorisées) avant même que WordPress ait fini de charger, aussi bien sur Apache que Nginx ou LiteSpeed. Désactivé par défaut, il démarre en mode surveillance et ne filtre jamais les administrateurs connectés ; chaque blocage est journalisé, agrégé en un incident par IP et par heure.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Assistant de configuration\u003C\u002Fstrong> : à la première activation, un assistant propose une « base sûre » en un clic qui active les essentiels sans risque — un débutant est protégé en quelques secondes. Le même bouton « Appliquer la base sûre » reste disponible à tout moment.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pourquoi Login Armor\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Aucun upsell, jamais.\u003C\u002Fstrong> Pas de niveau « premium », pas de boutons « Pro » grisés. Tout est en GPL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Aucun service externe à activer.\u003C\u002Fstrong> Pas de clé API, pas de tableau distant, pas de télémétrie. Les seuls appels sortants sont opt-in : Have I Been Pwned (fuites\u002Fmots de passe), Slack\u002FDiscord\u002Fwebhook (notifications), l’API sans clé ipwho.is (géolocalisation) et votre propre connecteur IA WordPress 7.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conçu pour être invisible.\u003C\u002Fstrong> ZIP de moins d’un méga, modules chargés à la demande, requêtes indexées — sous 2 ms sur un flux de connexion normal.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compatible multisite, natif PHP 8.1, réglages prêts pour la production.\u003C\u002Fstrong> Activation réseau d’une flotte, configuration par site, pilotage via une suite WP-CLI complète ; sans configuration, vous avez déjà 80 % de la protection.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Douze modules indépendants\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Masquer la connexion\u003C\u002Fstrong> : remplace wp-login.php par une URL personnalisée (l’ancienne renvoie une 404) ; une modale de pré-activation choisit ou génère le slug et vous l’envoie par e-mail pour éviter tout verrouillage. Compatible multisite, reverse proxies et récupération de mot de passe.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Protection contre la force brute\u003C\u002Fstrong> : verrouillages en cascade montant à un bannissement de 24 h, blocage de sous-réseaux et support X-Forwarded-For ; lostpassword, register, XML-RPC et l’endpoint REST users sont bloqués pour une IP verrouillée, et chaque verrouillage devient un incident.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Renforcement\u003C\u002Fstrong> : quinze bascules en un clic (réduction de surface, identifiants, filtrage des requêtes, surveillance des comptes) — désactiver XML-RPC\u002Fpingbacks, l’éditeur de fichiers, l’exposition de version, les mots de passe applicatifs et l’énumération d’auteurs ; bloquer les identifiants réservés (homoglyphes Unicode) ; ajouter un pot de miel ; être alerté à la création d’un administrateur.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Authentification à deux facteurs\u003C\u002Fstrong> : TOTP, codes à usage unique par e-mail et codes de secours imprimables, avec appareils de confiance 30 jours, application par rôle, période de grâce configurable et récupération par e-mail en cas de perte.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Détection et incidents\u003C\u002Fstrong> : un moteur en temps réel regroupe les événements en six patterns d’attaque, chacun avec une vue détaillée (chronologie, IP sources, comptes cibles, sévérité, empreinte UA) et des actions en un clic.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Journal d’activité\u003C\u002Fstrong> : piste d’audit conforme et inviolable (chaîne de hachage) des actions admin sur sept domaines, avec filtrage, export CSV, rétention configurable et transfert webhook signé optionnel vers un SIEM.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>En-têtes de sécurité\u003C\u002Fstrong> : CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy et X-Content-Type-Options sur wp-login.php et la page de verrouillage, en deux préréglages avec CSP report-uri optionnel ; les en-têtes de base peuvent s’étendre à tout le site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Détection de fuites\u003C\u002Fstrong> : repère les connexions avec un mot de passe fuité via k-anonymat sur Have I Been Pwned (seul un préfixe SHA-1 de 5 caractères sort) ; vérification e-mail XposedOrNot optionnelle, fail-soft.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Politique de mot de passe\u003C\u002Fstrong> : impose des mots de passe forts à l’inscription, au profil et à la réinitialisation (longueur, classes de caractères, interdiction de l’identifiant, rejet optionnel des mots de passe fuités), avec expiration optionnelle qui ne verrouille jamais personne dehors.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gestion des sessions\u003C\u002Fstrong> : déconnexion sur inactivité mesurée sur les vrais chargements, durée de vie maximale indépendante de « se souvenir de moi », limitation optionnelle à un seul appareil actif, et « déconnecter tous les autres appareils » en un clic.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Géolocalisation IP\u003C\u002Fstrong> : affiche le pays des IP attaquantes dans Incidents et Événements ; recherches paresseuses, cache 30 jours, plafonnées par page, plages privées jamais envoyées. ipwho.is sans clé par défaut, base hors ligne possible via un filtre.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pare-feu de requêtes\u003C\u002Fstrong> : filtre PHP optionnel inspiré du 8G qui bloque chaînes de requête, chemins, méthodes HTTP et (en option) user-agents\u002Freferrers malveillants avant le chargement de WordPress, sur Apache\u002FNginx\u002FLiteSpeed ; désactivé par défaut, démarre en mode surveillance, ne filtre jamais les admins, ignore REST\u002Fcron\u002FWP-CLI, allowlist IP\u002Fchemins (CIDR). Non noté.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Briefing de sécurité IA (optionnel)\u003C\u002Fh4>\n\u003Cp>Bâti sur le client IA natif de WordPress 7, un clic transforme vos trente derniers jours d’activité en un verdict en langage clair, un panorama des IP et une courte liste d’actions prioritaires ; « Expliquer avec l’IA » fait de même sur un incident. Le mode minimisé (signaux anonymisés) est par défaut, le mode approfondi est un opt-in explicite. Aucune clé API stockée : il utilise votre propre connecteur IA WordPress, le coût et le fournisseur restent les vôtres. Il s’ouvre toujours sur un instantané de faits déterministes, utile avec ou sans IA.\u003C\u002Fp>\n\u003Ch4>En plus\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Assistant de configuration\u003C\u002Fstrong> : un assistant à la première activation propose une base sûre en un clic (Simple) ou une voie manuelle (Avancée) ; le bouton « Appliquer la base sûre » reste disponible, et les sites en mise à jour ne le voient jamais.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Score de sécurité\u003C\u002Fstrong> : lecture pondérée 0-100 de votre posture avec une action prioritaire en un clic ; les fonctions d’observabilité (géolocalisation, notifications, assistant IA) ne sont pas notées.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Détection de conflits\u003C\u002Fstrong> : alerte quand une autre extension de sécurité axée connexion (Wordfence, Solid Security, Sucuri, All-In-One Security, SecuPress et d’autres) ou un plugin de cache (avec Hide Login actif) peut entrer en conflit.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notifications\u003C\u002Fstrong> : e-mail, Slack, Discord ou webhook, avec validation d’URL anti-SSRF, seuil de sévérité et rate limiting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Suite WP-CLI\u003C\u002Fstrong> et \u003Cstrong>widget Tableau de bord\u003C\u002Fstrong> (sparkline 14 jours, six métriques clés).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Conçu par\u003C\u002Fh4>\n\u003Cp>Login Armor est conçu et maintenu par Fabrice Ducarme de \u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Flogin-armor\u002F\" rel=\"nofollow ugc\">WPFormation\u003C\u002Fa>, expert WordPress français obsédé par les sites propres, rapides et prêts pour l’audit. On l’utilise sur chaque site qu’on livre.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Flogin-armor\u002F\" rel=\"nofollow ugc\">Présentation et fonctionnement de Login Armor\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Fsecurite-wordpress\u002F\" rel=\"nofollow ugc\">Guides de sécurité WordPress\u003C\u002Fa> sur WPFormation\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Foutils\u002Fveille-securite\u002F\" rel=\"nofollow ugc\">Veille des vulnérabilités WordPress\u003C\u002Fa> : l’outil de veille sécurité de WPFormation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>GPL pour toujours. PHP 8.1+. WordPress 6.8+. Zéro dépendance.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Ch4>AI Security Briefing (optional)\u003C\u002Fh4>\n\u003Cp>The AI Security Briefing and the “Explain with AI” incident analysis are powered by the \u003Cstrong>WordPress 7 native AI Client\u003C\u002Fstrong> (\u003Ccode>wp_ai_client_prompt()\u003C\u002Fcode>). When the administrator clicks the analysis button, LoginArmor asks WordPress to send a prompt to the \u003Cstrong>AI connector that the administrator configured in their own WordPress\u003C\u002Fstrong> (for example OpenAI, Anthropic or Google, depending on the connector). LoginArmor itself stores no API key and contacts no endpoint directly: the request, the provider and the cost are owned by the site’s own AI connector.\u003C\u002Fp>\n\u003Cp>Data sent: a text prompt describing the security situation. In \u003Cstrong>minimised mode (the default)\u003C\u002Fstrong>, only anonymised, non-identifying signals are included (counts, categories, severities, role buckets) – no IP address and no username in clear. In \u003Cstrong>deep mode\u003C\u002Fstrong> (an explicit, off-by-default opt-in), the prompt additionally includes real IP addresses and event details so the analysis can name specific sources. No data is ever sent unless the administrator clicks the analysis button.\u003C\u002Fp>\n\u003Cp>This feature is inactive unless WordPress 7 (or the AI Building Blocks feature plugin) is present with a configured, approved AI connector. The applicable terms and privacy policy are those of the AI provider the administrator chose for their connector; please refer to that provider’s documentation.\u003C\u002Fp>\n\u003Ch4>Webhook Notifications (optional)\u003C\u002Fh4>\n\u003Cp>When explicitly enabled and configured by the administrator in LoginArmor > Settings > Notifications, the plugin sends incident data to third-party services via webhooks.\u003C\u002Fp>\n\u003Cp>Data sent: incident type, severity level, IP address, target username, event count, and site URL.\u003C\u002Fp>\n\u003Cp>No data is sent unless the administrator actively enables and configures a notification channel.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Slack\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fslack.com\u002Fterms-of-service\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fslack.com\u002Fprivacy-policy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Discord\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fdiscord.com\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fdiscord.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Webhook URL\u003C\u002Fstrong> – User-configured endpoint (administrator’s responsibility)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Gravatar (Automattic)\u003C\u002Fh4>\n\u003Cp>The Activity Log tab uses WordPress core’s \u003Ccode>get_avatar()\u003C\u002Fcode> function to display user avatars. WordPress may send a hashed email address to \u003Ca href=\"https:\u002F\u002Fgravatar.com\u002F\" rel=\"nofollow ugc\">Gravatar\u003C\u002Fa> servers to retrieve avatar images. This is controlled by Settings > Discussion > Avatars.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Gravatar\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fautomattic.com\u002Ftos\u002F\" rel=\"nofollow ugc\">Automattic Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fautomattic.com\u002Fprivacy\u002F\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Breach Check – Have I Been Pwned (optional)\u003C\u002Fh4>\n\u003Cp>When the administrator explicitly enables the \u003Cstrong>Breach Check\u003C\u002Fstrong> module (LoginArmor > Settings > Breach  &hellip;\u003C\u002Fp>\n","Twelve security modules + AI briefing: hide login, request firewall, brute force, 2FA, password policy, sessions, hardening, audit log. No upsells.",200,2619,3,"2026-07-22T03:46:00.000Z","6.8","8.1",[74,19,20,75,76],"activity-log","limit-login","login-security","https:\u002F\u002Fwpformation.com\u002Flogin-armor","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flogin-armor.2.4.5.zip",{"slug":80,"name":81,"version":82,"author":83,"author_profile":84,"description":85,"short_description":86,"active_installs":26,"downloaded":87,"rating":26,"num_ratings":88,"last_updated":89,"tested_up_to":90,"requires_at_least":91,"requires_php":92,"tags":93,"homepage":99,"download_link":100,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"wphhsecure","WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login","1.1.10","WPHackedHelp","https:\u002F\u002Fprofiles.wordpress.org\u002Fpluginsupportwphackedhelp\u002F","\u003Cp>Secure your WordPress site with one-click file locking, login path hiding, role-based access, and smart dashboard visibility. Built for speed, security, and control.\u003C\u002Fp>\n\u003Ch3>Full Description\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>WPHH SECURE\u003C\u002Fstrong> by \u003Ca href=\"https:\u002F\u002Fsecure.wphackedhelp.com\" rel=\"nofollow ugc\">WP Hacked Help\u003C\u002Fa> is a comprehensive WordPress security plugin that integrates advanced file protection and login URL obfuscation. It blocks brute-force attacks, unauthorized access, and file tampering by allowing you to easily lock or unlock your WordPress files and folders with a single click.\u003C\u002Fp>\n\u003Cp>The plugin comes with a user-friendly interface and real-time feedback, ensuring secure operations without any technical knowledge required. WPHH SECURE is built to work seamlessly with the native WordPress functions, ensuring compatibility and safety for all sites, including blogs, business sites, and WooCommerce stores.\u003C\u002Fp>\n\u003Cp>With automatic exclusions for sensitive folders and the ability to manage folder exceptions, WPHH SECURE ensures that critical areas like uploads, cache, and backups are not locked accidentally. It also features login URL hiding to prevent unauthorized access to your site’s backend.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>✅ \u003Cstrong>One-Click Lock\u002FUnlock\u003C\u002Fstrong> – Lock or unlock all WordPress files and folders with a single click.\u003Cbr \u002F>\n✅ \u003Cstrong>Smart Dashboard\u003C\u002Fstrong> – Access real-time status updates and track lock activities in the dashboard.\u003Cbr \u002F>\n✅ \u003Cstrong>Role-Based Access\u003C\u002Fstrong> – Configure permissions to restrict access to the lock\u002Funlock feature based on user roles.\u003Cbr \u002F>\n✅ \u003Cstrong>Login URL Hiding\u003C\u002Fstrong> – Prevent brute-force login attempts by hiding or changing your default WordPress login URL.\u003Cbr \u002F>\n✅ \u003Cstrong>Safe File Handling\u003C\u002Fstrong> – Built on WP_Filesystem for secure file handling using AJAX for smooth background execution.\u003Cbr \u002F>\n✅ \u003Cstrong>Auto Exclusions\u003C\u002Fstrong> – Automatically exclude high-priority folders (e.g., uploads, cache, backups) from being locked.\u003Cbr \u002F>\n✅ \u003Cstrong>Visual Progress Feedback\u003C\u002Fstrong> – Watch real-time updates with progress bars and completion messages.\u003Cbr \u002F>\n✅ \u003Cstrong>Folder Exclusion Manager\u003C\u002Fstrong> – Easily add or remove folders from the exclusion list to keep them safe.\u003C\u002Fp>\n","Secure your WordPress site with one-click file locking, login path hiding, role-based access, and smart dashboard visibility.",2947,7,"2026-06-12T15:38:00.000Z","6.9.5","5.0","",[94,95,96,97,98],"brute-force-protection","file-locking","hide-login-url","wordpress-security","wp-filesystem","https:\u002F\u002Fsecure.wphackedhelp.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwphhsecure.1.1.10.zip",{"slug":102,"name":103,"version":104,"author":105,"author_profile":106,"description":107,"short_description":108,"active_installs":34,"downloaded":109,"rating":26,"num_ratings":110,"last_updated":111,"tested_up_to":90,"requires_at_least":16,"requires_php":112,"tags":113,"homepage":117,"download_link":118,"security_score":119,"vuln_count":57,"unpatched_count":13,"last_vuln_date":120,"fetched_at":28},"admin-safety-guard","Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection","1.3.0","Themepaste","https:\u002F\u002Fprofiles.wordpress.org\u002Fthemepaste\u002F","\u003Cp>\u003Cstrong>Admin Safety Guard\u003C\u002Fstrong> is a powerful yet lightweight WordPress security plugin that protects your login page and admin dashboard from hackers, bots, and brute-force attacks. It is built for anyone — from first-time bloggers to experienced developers — with a clean interface, clear settings, and features that work from the moment you activate it.\u003C\u002Fp>\n\u003Cp>WordPress is the most popular website platform in the world, which also makes it the most targeted. Every day, thousands of automated bots scan WordPress sites looking for weak passwords, exposed login pages, and unpatched vulnerabilities. Admin Safety Guard closes those doors quickly and reliably, without slowing down your site or requiring any technical expertise.\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FKFNUmTHtODE?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch3>Why WordPress Sites Get Hacked — And How Admin Safety Guard Stops It\u003C\u002Fh3>\n\u003Cp>Most successful WordPress attacks follow the same pattern:\u003C\u002Fp>\n\u003Col>\n\u003Cli>A bot finds your login page at the default \u003Ccode>wp-login.php\u003C\u002Fcode> address.\u003C\u002Fli>\n\u003Cli>It tries thousands of username and password combinations (brute-force attack).\u003C\u002Fli>\n\u003Cli>Once inside, it installs malware, steals data, or takes over your site.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Admin Safety Guard blocks every step of this attack chain — for free.\u003C\u002Fp>\n\u003Ch3>Free Features\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Limit Login Attempts (Active by Default)\u003C\u002Fstrong>\u003Cbr \u002F>\nAutomatically block any IP address that fails too many login attempts. You control the number of allowed attempts, the lockout duration, and the message shown to blocked users. Brute-force attacks become impossible when attackers are locked out after 3 failed tries. Login Limit Attempts is the only feature enabled by default on fresh install, so your site is protected the moment you activate the plugin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Custom Login URL\u003C\u002Fstrong>\u003Cbr \u002F>\nMove your login page away from the default \u003Ccode>wp-login.php\u003C\u002Fcode> address. Bots and automated scanners will never find your login page because it simply does not exist at the expected location. You can set any slug you like, and the plugin handles redirect rules automatically. You can also set a custom redirect URL for after login and after logout.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Two-Factor Authentication (2FA) via Email OTP\u003C\u002Fstrong>\u003Cbr \u002F>\nAfter a user enters their correct password, a one-time passcode (OTP) is sent to their email address. They must enter that code to complete the login. Even if a hacker steals a password, they cannot get in without also accessing the user’s email inbox. You can customise the OTP email subject and body to match your brand.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Google reCAPTCHA (v2 & v3)\u003C\u002Fstrong>\u003Cbr \u002F>\nAdd Google reCAPTCHA to your login form to block automated bots in real time. Both reCAPTCHA v2 (the familiar checkbox) and v3 (invisible, score-based) are supported. Simply enter your site key and secret key from Google, choose your version, and reCAPTCHA will handle the rest silently in the background.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>IP Blocking\u003C\u002Fstrong>\u003Cbr \u002F>\nManually block specific IP addresses from accessing your login page entirely. If you notice a suspicious IP in your activity log or receive repeated failed login alerts, add that IP to the block list and it will be turned away immediately. Perfect for stopping known bad actors before they become a problem.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login Logs & Activity Tracking\u003C\u002Fstrong>\u003Cbr \u002F>\nSee exactly who is logging in to your site and when. The activity dashboard shows successful logins, failed login attempts, IP addresses, user agents, and timestamps in a clear, searchable table. You will always know if something unusual is happening on your site, and you have the evidence to act on it.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Analytics Dashboard\u003C\u002Fstrong>\u003Cbr \u002F>\nThe built-in analytics dashboard gives you a real-time overview of your site’s security health. It shows your overall Security Score (based on how many features you have enabled), recent login activity, failed login trends, and a breakdown of which security features are active versus inactive. It is the first page you see when you open the plugin, giving you immediate situational awareness.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hide Admin Bar (by Role)\u003C\u002Fstrong>\u003Cbr \u002F>\nChoose which user roles see the WordPress admin bar on the front end of your site. For example, you can hide the admin bar from subscribers and customers while keeping it visible for editors and administrators. This reduces information leakage and gives non-admin users a cleaner experience.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Password Protection (Site-Wide)\u003C\u002Fstrong>\u003Cbr \u002F>\nLock your entire website behind a password. Visitors must enter the correct password before they can view any content. This is ideal for staging sites, coming-soon pages, client previews, or any situation where you want to restrict public access temporarily. You can set the access duration and exclude specific user roles from the password requirement.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy Hardening — Disable XML-RPC\u003C\u002Fstrong>\u003Cbr \u002F>\nThe WordPress XML-RPC interface is a common target for brute-force and DDoS amplification attacks. With one toggle, you can disable it completely. Unless you rely on XML-RPC for mobile app publishing or specific third-party integrations, disabling it is a safe and recommended step for almost every WordPress site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login Page Customisation & Branding\u003C\u002Fstrong>\u003Cbr \u002F>\nReplace the default WordPress logo on the login page with your own logo. Set the logo width, height, and URL. Choose from pre-built login page templates to give your login form a professional, branded appearance. This is especially useful for agencies delivering client sites and for anyone who wants a polished, consistent look.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Firewall & Malware Overview\u003C\u002Fstrong>\u003Cbr \u002F>\nThe Firewall & Malware section gives you a central view of your site’s firewall and malware protection status. It shows all related features in one place so you can see what is active and what still needs attention, making it easy to build up your security layer by layer.\u003C\u002Fp>\n\u003Ch3>Pro Features\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fadmin-safety-guard-pro\" rel=\"nofollow ugc\">Admin Safety Guard Pro\u003C\u002Fa> extends the plugin with advanced security tools designed for agencies, developers, and high-traffic sites.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Passwordless Login (Magic Links)\u003C\u002Fstrong>\u003Cbr \u002F>\nLet users log in with a secure, one-time link sent to their email — no password needed. Magic links expire after a single use, making them more secure than passwords for many workflows.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>2FA via Mobile Authenticator App\u003C\u002Fstrong>\u003Cbr \u002F>\nAdd Google Authenticator or Authy-compatible two-factor authentication to your login flow. Users scan a QR code once, then generate time-based OTP codes from their phone app. This is the same method used by banks and enterprise software.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Social Login\u003C\u002Fstrong>\u003Cbr \u002F>\nAllow users to log in with their existing Google, Facebook, or other social media accounts. Reduce friction at sign-up and login, while keeping full control over which providers are allowed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Database Table Prefix Check\u003C\u002Fstrong>\u003Cbr \u002F>\nThe default WordPress database prefix \u003Ccode>wp_\u003C\u002Fcode> is well-known to attackers and makes SQL injection easier. This Pro tool detects your current prefix and guides you through changing it to a unique, random value to close that vulnerability.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Strong Password Enforcement\u003C\u002Fstrong>\u003Cbr \u002F>\nSet a minimum password strength policy for your users. When they update their password, it must meet your requirements — rejecting weak, guessable passwords before they become a security risk.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Firewall & Malware Scanner\u003C\u002Fstrong>\u003Cbr \u002F>\nScan your WordPress files and database for known malware signatures, suspicious code injections, and modified core files. Get alerts when threats are detected and take action directly from the plugin dashboard.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fadmin-safety-guard-pro\" rel=\"nofollow ugc\">Upgrade to Pro\u003C\u002Fa>\u003C\u002Fstrong> to unlock all Pro features.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>Who Is Admin Safety Guard For?\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Bloggers & Content Creators\u003C\u002Fstrong>\u003Cbr \u002F>\nYou focus on writing — not on managing server security. Admin Safety Guard protects your login page and admin area quietly in the background with zero ongoing maintenance required.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Small Business Owners\u003C\u002Fstrong>\u003Cbr \u002F>\nYour website is your business. A hack can bring it down, damage your reputation, and cost you money. Admin Safety Guard gives you enterprise-level login protection without the enterprise price tag.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WooCommerce Store Owners\u003C\u002Fstrong>\u003Cbr \u002F>\nAn online store holds customer data, payment details, and order history. Limit login attempts, add 2FA, and lock down your admin area so only you and your trusted team can get in.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Freelancers & Web Designers\u003C\u002Fstrong>\u003Cbr \u002F>\nDeliver more secure sites to clients out of the box. Customise the login page with the client’s branding, lock down the admin bar by role, and hand over a professional, secure WordPress installation every time.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Agencies & Development Teams\u003C\u002Fstrong>\u003Cbr \u002F>\nManage security across multiple client sites with a consistent, repeatable setup. All features are toggle-based and clearly documented, making it easy to onboard new team members and maintain a security standard across your portfolio.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Developers & Site Administrators\u003C\u002Fstrong>\u003Cbr \u002F>\nFine-tune every setting — login attempt limits, lockout durations, OTP email templates, reCAPTCHA version, redirect URLs, IP block lists, and more. Admin Safety Guard is built on WordPress hooks and filters, so it plays well with the rest of your stack.\u003C\u002Fp>\n\u003Ch3>What Makes Admin Safety Guard Different?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Lightweight by design.\u003C\u002Fstrong> Assets are loaded only on the pages that need them. The plugin has no impact on your site’s front-end load time.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No configuration required to get started.\u003C\u002Fstrong> Limit Login Attempts is enabled automatically on install. Your site is more secure the moment you activate the plugin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>All features are clearly labelled Free or Pro.\u003C\u002Fstrong> You can see exactly what is available and what requires the Pro version before making any decisions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean, modern dashboard.\u003C\u002Fstrong> The settings UI is built with React for a fast, app-like experience. Finding and configuring features takes seconds, not minutes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built to WordPress standards.\u003C\u002Fstrong> Every input is sanitised, every output is escaped, all AJAX requests use nonce verification, and every database query uses prepared statements.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For any issues, questions, or feature requests, please reach out via \u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fcontact\" rel=\"nofollow ugc\">Support\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin uses the following third-party and external services:\u003C\u002Fp>\n\u003Cp>1) Google reCAPTCHA (Google LLC)\u003C\u002Fp>\n\u003Cp>Purpose:\u003Cbr \u002F>\nUsed to protect forms from spam and automated abuse.\u003C\u002Fp>\n\u003Cp>When it is used:\u003Cbr \u002F>\n– When reCAPTCHA is enabled in plugin settings\u003Cbr \u002F>\n– On login forms and support forms protected by reCAPTCHA\u003C\u002Fp>\n\u003Cp>What data is sent:\u003Cbr \u002F>\n– User IP address\u003Cbr \u002F>\n– reCAPTCHA response token generated by Google\u003Cbr \u002F>\n– Browser information as required by Google reCAPTCHA\u003C\u002Fp>\n\u003Cp>Service provider:\u003Cbr \u002F>\nGoogle LLC\u003C\u002Fp>\n\u003Cp>Terms of Service:\u003Cbr \u002F>\nhttps:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fp>\n\u003Cp>Privacy Policy:\u003Cbr \u002F>\nhttps:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fp>\n\u003Cp>2) ThemePaste API (Plugin Author Service)\u003C\u002Fp>\n\u003Cp>Purpose:\u003Cbr \u002F>\nUsed for:\u003Cbr \u002F>\n– Collecting optional admin email addresses for plugin updates and notifications\u003Cbr \u002F>\n– Sending support requests from the plugin support form\u003Cbr \u002F>\n– Collecting optional feedback when a user attempts to deactivate the plugin\u003Cbr \u002F>\n– Managing plugin-related notifications (only if the user provides contact details)\u003C\u002Fp>\n\u003Cp>When it is used:\u003Cbr \u002F>\n– When a user submits the built-in support form\u003Cbr \u002F>\n– When a user opts to send diagnostic information\u003Cbr \u002F>\n– Submitting the optional deactivation feedback form\u003C\u002Fp>\n\u003Cp>What data is sent:\u003Cbr \u002F>\n– Name\u003Cbr \u002F>\n– Email address\u003Cbr \u002F>\n– Phone number (if provided)\u003Cbr \u002F>\n– Message content\u003Cbr \u002F>\n– Site URL\u003Cbr \u002F>\n– Plugin name\u003Cbr \u002F>\n– Feedback text (if provided)\u003Cbr \u002F>\n– Support message content\u003Cbr \u002F>\n– Deactivation reason (if provided)\u003C\u002Fp>\n\u003Cp>No data is sent without user action.\u003C\u002Fp>\n\u003Cp>Service provider:\u003Cbr \u002F>\nThemePaste.com\u003C\u002Fp>\n\u003Cp>Terms of Service:\u003Cbr \u002F>\nhttps:\u002F\u002Fthemepaste.com\u002Fterms-condition\u003C\u002Fp>\n\u003Cp>Privacy Policy:\u003Cbr \u002F>\nhttps:\u002F\u002Fthemepaste.com\u002Fprivacy-policy\u003C\u002Fp>\n\u003Ch3>Development \u002F Source Code\u003C\u002Fh3>\n\u003Cp>This plugin includes compiled JavaScript bundles in:\u003Cbr \u002F>\n– assets\u002Fadmin\u002Fbuild\u002F*.bundle.js\u003C\u002Fp>\n\u003Cp>The original (human-readable) source files are included in this plugin under:\u003Cbr \u002F>\n– spa\u002Fadmin\u002F\u003C\u002Fp>\n\u003Cp>Build Tools\u003Cbr \u002F>\n– Node.js (LTS recommended)\u003Cbr \u002F>\n– npm\u003Cbr \u002F>\n– Webpack + Babel\u003C\u002Fp>\n\u003Cp>Source Entry Points\u003Cbr \u002F>\nThe admin SPA bundles are built from the following entry points:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>spa\u002Fadmin\u002Flogin-template\u002FMain.jsx            -> assets\u002Fadmin\u002Fbuild\u002FloginTemplate.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Flogin-logs-activity\u002FMain.jsx       -> assets\u002Fadmin\u002Fbuild\u002FloginLogActivity.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fanalytics\u002FMain.jsx                 -> assets\u002Fadmin\u002Fbuild\u002Fanalytics.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fsecurity-core\u002FMain.jsx             -> assets\u002Fadmin\u002Fbuild\u002FsecurityCore.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Ffirewall-malware\u002FMain.jsx          -> assets\u002Fadmin\u002Fbuild\u002FfirewallMalware.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fprivacy-hardening\u002FMain.jsx         -> assets\u002Fadmin\u002Fbuild\u002FprivacyHardening.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fmonitoring-analytics\u002FMain.jsx      -> assets\u002Fadmin\u002Fbuild\u002FmonitoringAnalytics.bundle.js\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Install Dependencies\u003Cbr \u002F>\nFrom the plugin root directory (or the directory where package.json exists):\u003C\u002Fp>\n\u003Cp>1) Install dependencies:\u003Cbr \u002F>\n   npm install\u003C\u002Fp>\n\u003Cp>Build (Production)\u003Cbr \u002F>\nTo generate the production bundles:\u003C\u002Fp>\n\u003Cp>npm run build\u003C\u002Fp>\n\u003Cp>Output Location\u003Cbr \u002F>\nWebpack outputs the compiled bundles to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>assets\u002Fadmin\u002Fbuild\u002F[name].bundle.js\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Important Notes\u003Cbr \u002F>\n– Do not edit files in assets\u002Fadmin\u002Fbuild\u002F directly. They are generated files.\u003Cbr \u002F>\n– Edit the source files under spa\u002Fadmin\u002F and re-run the build command.\u003Cbr \u002F>\n– For WordPress.org distribution, production builds should be used (mode=production).\u003C\u002Fp>\n\u003Ch3>Links\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fthemepaste.com\" rel=\"nofollow ugc\">Website\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct-doc\u002Fhide-admin-bar-pro\u002F?doc_id=389\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fadmin-safety-guard-pro\" rel=\"nofollow ugc\">Pro Version\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fthemepaste\" rel=\"nofollow ugc\">Facebook\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fuk.pinterest.com\u002Fthemepaste\u002F\" rel=\"nofollow ugc\">Pinterest\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Fthemepaste\" rel=\"nofollow ugc\">LinkedIn\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.instagram.com\u002Fthemepasteuk\" rel=\"nofollow ugc\">Instagram\u003C\u002Fa>\u003C\u002Fp>\n","Protect your WP site from hackers for free. Limit logins, add 2FA, reCAPTCHA, block IPs, hide wp-login.php & track activity logs.",2435,4,"2026-06-17T08:54:00.000Z","7.0",[94,114,115,76,116],"custom-login-url","limit-login-attempts","two-factor-authentication","http:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fthemepaste-secure-admin-pro\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadmin-safety-guard.1.3.0.zip",99,"2026-03-16 00:00:00",{"slug":122,"name":123,"version":124,"author":125,"author_profile":126,"description":127,"short_description":128,"active_installs":129,"downloaded":130,"rating":13,"num_ratings":13,"last_updated":131,"tested_up_to":132,"requires_at_least":16,"requires_php":72,"tags":133,"homepage":135,"download_link":136,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":137},"ultimate-security","Ultimate Security – Login Protection, 2FA, CAPTCHA & Hardening","1.0.17","WP Ultimate Security","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpultimatesecurity\u002F","\u003Cp>Ultimate Security protects your WordPress site from brute force attacks, unauthorized access, and bots. Lightweight, modular, and privacy-focused.\u003C\u002Fp>\n\u003Cp>Check out the documentation for this plugin from here\u003C\u002Fp>\n\u003Cp>Link: \u003Ca href=\"https:\u002F\u002Fdocs.wpultimatesecurity.com\u002Fdocs\u002F\" rel=\"nofollow ugc\">Visit Documentation Site\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-Factor Authentication\u003C\u002Fstrong>\u003Cbr \u002F>\n* Email OTP verification\u003Cbr \u002F>\n* Google Authenticator, Authy, Microsoft Authenticator (TOTP\u002FHOTP)\u003Cbr \u002F>\n* 2FA status dashboard\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login Protection\u003C\u002Fstrong>\u003Cbr \u002F>\n* Custom login URL (hide wp-admin)\u003Cbr \u002F>\n* Login attempt limits\u003Cbr \u002F>\n* Password policy enforcement\u003Cbr \u002F>\n* Session management\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Bot Protection\u003C\u002Fstrong>\u003Cbr \u002F>\n* Google reCAPTCHA v2\u002Fv3\u003Cbr \u002F>\n* Cloudflare Turnstile\u003Cbr \u002F>\n* Protect login, registration, comments, WooCommerce\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Hardening\u003C\u002Fstrong>\u003Cbr \u002F>\n* Security keys rotation\u003Cbr \u002F>\n* Auto-update controls\u003Cbr \u002F>\n* Site health monitoring\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Content Protection\u003C\u002Fstrong>\u003Cbr \u002F>\n* Right-click disable\u003Cbr \u002F>\n* Text selection control\u003Cbr \u002F>\n* Image drag prevention\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Tools\u003C\u002Fstrong>\u003Cbr \u002F>\n* Security Score dashboard\u003Cbr \u002F>\n* Settings backup\u002Frestore\u003Cbr \u002F>\n* Test mode for previewing rules\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to external services:\u003C\u002Fp>\n\u003Ch4>Cloudflare Turnstile\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>When: Turnstile CAPTCHA enabled\u003C\u002Fli>\n\u003Cli>Sends: Response token, site secret key\u003C\u002Fli>\n\u003Cli>URL: https:\u002F\u002Fchallenges.cloudflare.com\u002Fturnstile\u002Fv0\u002Fsiteverify\u003C\u002Fli>\n\u003Cli>Privacy: https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Google reCAPTCHA\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>When: reCAPTCHA enabled\u003C\u002Fli>\n\u003Cli>Sends: Response token, site secret key\u003C\u002Fli>\n\u003Cli>URL: https:\u002F\u002Fwww.google.com\u002Frecaptcha\u002Fapi\u002Fsiteverify\u003C\u002Fli>\n\u003Cli>Privacy: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WordPress.org Salt API\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>When: Security keys rotation requested\u003C\u002Fli>\n\u003Cli>Sends: Request for random salt strings\u003C\u002Fli>\n\u003Cli>URL: https:\u002F\u002Fapi.wordpress.org\u002Fsecret-key\u002F1.1\u002Fsalt\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n","Protect your WordPress site with 2FA, brute force protection, CAPTCHA, custom login URL, and security hardening.",10,1485,"2026-02-18T10:05:00.000Z","6.8.5",[19,134,76,22,116],"firewall","https:\u002F\u002Fwww.wpultimatesecurity.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fultimate-security.1.0.17.zip","2026-04-16T10:56:18.058Z",{"error":139,"url":140,"statusCode":141,"statusMessage":142,"message":142},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fdefyn-security-manager\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":110,"versions":144},[145,151,158,165],{"version":6,"download_url":25,"svn_tag_url":146,"released_at":27,"has_diff":147,"diff_files_changed":148,"diff_lines":27,"trac_diff_url":149,"vulnerabilities":150,"is_current":139},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fdefyn-security-manager\u002Ftags\u002F1.2.1\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fdefyn-security-manager%2Ftags%2F1.2.0&new_path=%2Fdefyn-security-manager%2Ftags%2F1.2.1",[],{"version":152,"download_url":153,"svn_tag_url":154,"released_at":27,"has_diff":147,"diff_files_changed":155,"diff_lines":27,"trac_diff_url":156,"vulnerabilities":157,"is_current":147},"1.2.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdefyn-security-manager.1.2.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fdefyn-security-manager\u002Ftags\u002F1.2.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fdefyn-security-manager%2Ftags%2F1.1.1&new_path=%2Fdefyn-security-manager%2Ftags%2F1.2.0",[],{"version":159,"download_url":160,"svn_tag_url":161,"released_at":27,"has_diff":147,"diff_files_changed":162,"diff_lines":27,"trac_diff_url":163,"vulnerabilities":164,"is_current":147},"1.1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdefyn-security-manager.1.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fdefyn-security-manager\u002Ftags\u002F1.1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fdefyn-security-manager%2Ftags%2F1.1.0&new_path=%2Fdefyn-security-manager%2Ftags%2F1.1.1",[],{"version":166,"download_url":167,"svn_tag_url":168,"released_at":27,"has_diff":147,"diff_files_changed":169,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":170,"is_current":147},"1.1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdefyn-security-manager.1.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fdefyn-security-manager\u002Ftags\u002F1.1.0\u002F",[],[]]