[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-0cc5ZZ3tvAVJiCDqLV_mW2y3_-XXhgDruNUD6oy9ps":3,"$fewRXjaxGE55xXKfQLRSZWIcSeQ_Rp_fymNKhmMs1hk8":124,"$fNepIeWwXHWlnxd0GIAnWO16c1oFB1k3OO11NSouYXsk":129},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":26,"fingerprints":26},"holographic-login-shield","Holographic Login Shield","1.0.15","Holographic","https:\u002F\u002Fprofiles.wordpress.org\u002Fholo-alan\u002F","\u003Cp>Holographic Login Shield helps protect the WordPress login area from repeated failed logins, automated abuse and common account-discovery behaviour.\u003C\u002Fp>\n\u003Cp>The plugin is designed to stay focused. It adds practical login hardening without replacing the WordPress admin area, adding unnecessary front-end assets or sending free-plugin security logs to an external service.\u003C\u002Fp>\n\u003Cp>Free features include configurable failed-login lockouts, an automatic permanent IP block threshold, local allowed and blocked IP address lists, Cloudflare-aware visitor IP detection, a paginated recent activity log, CSV log export, log retention cleanup, generic login errors, XML-RPC control, Application Password control, optional author archive blocking, a hidden bot trap and optional throttled failed-login email alerts.\u003C\u002Fp>\n\u003Cp>Allowed IP addresses can be added manually or with the Add My IP button. Blocked IP addresses can be added manually and are also populated automatically when the permanent blocking threshold is reached. Both lists remain local to your WordPress site.\u003C\u002Fp>\n","Lightweight login protection, brute-force defence and safer admin access controls for WordPress.",0,115,"2026-06-01T17:27:00.000Z","7.0.2","6.4","8.1",[18,19,20,21,22],"admin","brute-force","login","security","xmlrpc","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fholographic-login-shield.1.0.15.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"holo-alan",6,30,94,"2026-08-29T04:32:14.235Z",[37,56,77,93,108],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":14,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":54,"download_link":55,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"wp-login-delay","Login Delay Shield","2.6.0","michael.damoiseau","https:\u002F\u002Fprofiles.wordpress.org\u002Fmichaeldamoiseau\u002F","\u003Cp>WordPress is one of the most widely used content management systems on the internet, making it a frequent target for bots and hackers attempting brute-force attacks.\u003C\u002Fp>\n\u003Cp>A brute-force attack works by systematically trying passwords until finding the correct one. Login Delay Shield defends against this by adding a configurable delay after each failed login attempt. Since successful logins are never delayed, legitimate users experience no slowdown. This approach is particularly effective against bots that send thousands of login requests, as each failed attempt forces the attacker to wait before trying the next password.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Distributed attack detection\u003C\u002Fstrong> — spot credential-stuffing that rotates IPs, which per-IP lockouts miss.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Setup Wizard\u003C\u002Fstrong> — Choose Conservative, Balanced, or Aggressive protection profiles from the settings page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login delay\u003C\u002Fstrong> — Fixed or random delay on failed login attempts (1-10 seconds)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Progressive delay\u003C\u002Fstrong> — Delay increases with each consecutive failed attempt from the same IP\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP lockout\u003C\u002Fstrong> — Temporarily block IP addresses after too many failed attempts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Username-aware lockout strategy\u003C\u002Fstrong> — Choose \u003Ccode>IP only\u003C\u002Fcode> or \u003Ccode>IP + username\u003C\u002Fcode> to reduce false positives on shared networks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login feedback\u003C\u002Fstrong> — Shows remaining attempts before lockout and a lockout countdown when blocked\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP whitelist\u003C\u002Fstrong> — Bypass all security measures for trusted IPs (supports CIDR notation)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email notifications\u003C\u002Fstrong> — Receive alerts when failed login thresholds are reached\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Failed login log\u003C\u002Fstrong> — Track all failed attempts with a dashboard widget showing recent activity, 7-day trends, and top targeted usernames\u003C\u002Fli>\n\u003Cli>\u003Cstrong>fail2ban logging (optional)\u003C\u002Fstrong> — Write fail2ban-compatible failed-login and lockout lines to a safe log file\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC protection\u003C\u002Fstrong> — Apply delays to XML-RPC authentication or block it entirely\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password reset protection\u003C\u002Fstrong> — Apply delays, lockouts, and logging to password reset submissions without revealing account existence\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom login URL\u003C\u002Fstrong> — Move the login page to a custom URL to reduce automated bot traffic targeting \u003Ccode>\u002Fwp-login.php\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Country blocking (optional, developer integration)\u003C\u002Fstrong> — Block login authentication from selected country codes. Ships no GeoIP database; requires a resolver hooked to the \u003Ccode>wldelay_resolve_country_code\u003C\u002Fcode> filter to supply the visitor country\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Emergency recovery URL (optional)\u003C\u002Fstrong> — Generate a secret link that clears the lockout for your own IP, so you can get back in even with no admin, shell, or file access\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Log retention\u003C\u002Fstrong> — Automatic cleanup of old log entries (configurable retention period)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Accessible admin interface\u003C\u002Fstrong> — WCAG 2.1 compliant with keyboard navigation and screen reader support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multilingual\u003C\u002Fstrong> — Translated into 18 languages including French, German, Spanish, Japanese, Chinese, Arabic, and more\u003C\u002Fli>\n\u003Cli>Lightweight and compatible with other security plugins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Free means free\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Login Delay Shield has no ads, no upsells, no premium tier, and no account or API key requirement. Every admin notice is dismissible, and the plugin never nags you to upgrade — there is nothing to upgrade to.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>You can always get back in\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A security plugin that locks out its own administrator is worse than no security at all. Login Delay Shield is built so an admin can always recover access:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Whitelisted IPs (including CIDR ranges) bypass every delay and lockout\u003C\u002Fli>\n\u003Cli>The Active Lockouts manager on the settings page lists current lockouts with a one-click Unlock for each, plus an “Unlock Current IP” action\u003C\u002Fli>\n\u003Cli>The optional Emergency Recovery URL — a secret link you save in advance — clears your own IP lockout even when you have no admin, shell, or file access\u003C\u002Fli>\n\u003Cli>WP-CLI recovery commands: \u003Ccode>wp wp-login-delay unlock-ip \u003Cip>\u003C\u002Fcode> and \u003Ccode>wp wp-login-delay flush-lockouts\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Lockouts are always temporary (24 hours maximum) — there are no permanent bans\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>This plugin is not a complete security solution — dedicated security plugins offer more comprehensive protection.\u003C\u002Fem> However, Login Delay Shield adds an effective layer of defense that works alongside your existing security measures without conflict.\u003C\u002Fp>\n\u003Cp>\u003Cem>Note: This plugin was formerly known as “WP Login Delay”.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch3>Contribute\u003C\u002Fh3>\n\u003Cp>Found a bug or want to suggest an improvement? Open a thread in the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fwp-login-delay\u002F\" rel=\"ugc\">support forum\u003C\u002Fa> on WordPress.org.\u003C\u002Fp>\n\u003Cp>Want to help translate the plugin into your language? Visit \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Fprojects\u002Fwp-plugins\u002Fwp-login-delay\u002F\" rel=\"nofollow ugc\">translate.wordpress.org\u003C\u002Fa>.\u003C\u002Fp>\n","Login Delay Shield slows down brute-force attacks by adding a configurable delay to failed login attempts while keeping successful logins instant.",60,5340,88,5,"2026-07-15T02:04:00.000Z","3.5.1","7.4",[19,53,20,21,22],"lockout","https:\u002F\u002Fdamoiseau.me","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-login-delay.2.6.0.zip",{"slug":57,"name":58,"version":59,"author":60,"author_profile":61,"description":62,"short_description":63,"active_installs":64,"downloaded":65,"rating":11,"num_ratings":11,"last_updated":66,"tested_up_to":67,"requires_at_least":68,"requires_php":69,"tags":70,"homepage":23,"download_link":75,"security_score":76,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"fortress-login-pro","Fortress Login Pro – Secure, Hide & Rename Login URL","1.1.3","Hamdi Saidani","https:\u002F\u002Fprofiles.wordpress.org\u002Fhamdisaidani\u002F","\u003Cp>\u003Cstrong>Fortress Login Pro\u003C\u002Fstrong> is a battle-ready security plugin that replaces your WordPress login page (\u003Ccode>wp-login.php\u003C\u002Fcode>) with a private, rotating URL that only you control.\u003C\u002Fp>\n\u003Cp>🛡️ It doesn’t just hide the login—it lets you track, rotate, and control it.\u003C\u002Fp>\n\u003Cp>Perfect for freelancers, agencies, eCommerce owners, and anyone tired of blind brute-force attacks.\u003C\u002Fp>\n\u003Ch3>🔐 Key Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Custom Login URL:\u003C\u002Fstrong> Hide \u003Ccode>wp-login.php\u003C\u002Fcode> and set your own private login path  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Rotate Slugs:\u003C\u002Fstrong> Automatically change your login URL on a custom schedule  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dual-Slug Rotation Safety:\u003C\u002Fstrong> Keep the old URL live until the new one is used (fail-safe)  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Slug Generator:\u003C\u002Fstrong> Choose readable word combos or full-random slugs (with number support)  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Access Logs & Charts:\u003C\u002Fstrong> See IPs, timestamps, referrers, and user-agents by login attempt  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Export Logs:\u003C\u002Fstrong> Download access history or slug changes in CSV or JSON  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Slug History Panel:\u003C\u002Fstrong> Restore, archive, or delete old slugs anytime  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>SMTP Configuration:\u003C\u002Fstrong> Set up outgoing email for login slug alerts and rotation notices  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Test Email & Rotation:\u003C\u002Fstrong> Built-in checks before activating rotation so you don’t get locked out  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>System File Protection:\u003C\u002Fstrong> Optional toggle to block access to \u003Ccode>install.php\u003C\u002Fcode> and \u003Ccode>setup-config.php\u003C\u002Fcode> via \u003Ccode>.htaccess\u003C\u002Fcode>  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean UI:\u003C\u002Fstrong> Fast, modern dashboard with zero bloat or upsell traps  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>✅ Works With\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>WooCommerce, Easy Digital Downloads, and major eCommerce plugins  \u003C\u002Fli>\n\u003Cli>Membership systems like MemberPress, Paid Memberships Pro  \u003C\u002Fli>\n\u003Cli>Popular security plugins: Wordfence, iThemes, Sucuri  \u003C\u002Fli>\n\u003Cli>Caching tools like WP Rocket, Cloudflare, W3 Total Cache  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🚀 Why Fortress (vs limit login or captcha plugins)?\u003C\u002Fh3>\n\u003Cp>Most plugins try to \u003Cstrong>respond\u003C\u002Fstrong> to brute-force.\u003Cbr \u002F>\nFortress prevents it by removing the login form from public view.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>No login page = no attack surface.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>Final Word\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Fortress Login Pro\u003C\u002Fstrong> doesn’t just hide your login—it makes you smarter about who’s trying to reach it.\u003C\u002Fp>\n\u003Cp>Real logs. Real control. No BS.\u003Cbr \u002F>\nReady to lock down WordPress the way it should’ve shipped.\u003C\u002Fp>\n\u003Cp>Try our companion plugin: \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fnotification-blocker\u002F\" rel=\"ugc\">Notification Blocker\u003C\u002Fa> — hide noisy dashboard alerts with one click.\u003C\u002Fp>\n","Hide and rotate your WordPress login URL. Track access, export logs, and prevent brute-force attacks with real-time visibility.",10,789,"2025-05-09T10:19:00.000Z","6.8.6","5.0","7.2",[71,72,73,21,74],"brute-force-protection","custom-login-url","login-security","wp-admin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffortress-login-pro.1.1.3.zip",92,{"slug":78,"name":79,"version":80,"author":81,"author_profile":82,"description":83,"short_description":84,"active_installs":64,"downloaded":85,"rating":11,"num_ratings":11,"last_updated":86,"tested_up_to":87,"requires_at_least":68,"requires_php":69,"tags":88,"homepage":91,"download_link":92,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"webdoktoru-security","WebDoktoru Security","1.0.2","WebDoktoru","https:\u002F\u002Fprofiles.wordpress.org\u002Fwebdoktoru\u002F","\u003Cp>WebDoktoru Security provides comprehensive security protection for your WordPress website with an easy-to-use interface. This plugin offers multiple security features that can be activated or deactivated with a single click, making it perfect for both beginners and advanced users.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable XML-RPC\u003C\u002Fstrong> – Prevents XML-RPC attacks and increases security\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide WordPress Version\u003C\u002Fstrong> – Hides WordPress version information from potential attackers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable File Editing\u003C\u002Fstrong> – Disables file editing from admin panel for enhanced security\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove WordPress Generator\u003C\u002Fstrong> – Removes WordPress information from HTML source code\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable User Enumeration\u003C\u002Fstrong> – Prevents user ID discovery attempts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block Bad Bots\u003C\u002Fstrong> – Blocks known malicious bots and crawlers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Directory Browsing\u003C\u002Fstrong> – Prevents directory listing on your server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Limit Login Attempts\u003C\u002Fstrong> – Protects against brute force attacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Author Scans\u003C\u002Fstrong> – Hides author pages from potential attackers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure HTTP Headers\u003C\u002Fstrong> – Adds important security headers to your site\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Multi-Language Support\u003C\u002Fh4>\n\u003Cp>This plugin supports multiple languages:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English (Default)\u003C\u002Fli>\n\u003Cli>Turkish (Türkçe)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>To add support for a new language:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Copy the \u003Ccode>languages\u002Fwebdoktoru-security.pot\u003C\u002Fcode> file\u003C\u002Fli>\n\u003Cli>Rename it to \u003Ccode>webdoktoru-security-{locale}.po\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Translate the strings in the PO file\u003C\u002Fli>\n\u003Cli>Compile it to MO format using: \u003Ccode>msgfmt webdoktoru-security-{locale}.po -o webdoktoru-security-{locale}.mo\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Place both files in the \u003Ccode>languages\u002F\u003C\u002Fcode> directory\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Security Status Monitoring\u003C\u002Fh4>\n\u003Cp>The plugin evaluates your security status based on active security measures:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Excellent (80%+):\u003C\u002Fstrong> Green status\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Good (60%+):\u003C\u002Fstrong> Yellow status\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Weak (\u003C60%):\u003C\u002Fstrong> Red status\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ch4>Technical Requirements\u003C\u002Fh4>\n\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP Version: 7.0 or higher\u003C\u002Fli>\n\u003Cli>WordPress Version: 5.0 or higher\u003C\u002Fli>\n\u003Cli>Modern web browser for admin interface\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Version History\u003C\u002Fh3>\n\u003Ch4>1.0.2\u003C\u002Fh4>\n\u003Cp>– Fixed inline JavaScript to use wp_add_inline_script() for WordPress standards compliance\u003Cbr \u002F>\n– Updated all function names with unique prefixes to prevent conflicts\u003Cbr \u002F>\n– Enhanced transient key naming with webdoktoru_security_ prefix\u003Cbr \u002F>\n– Improved AJAX action names for better uniqueness\u003Cbr \u002F>\n– WordPress.org repository compliance improvements\u003C\u002Fp>\n\u003Ch4>1.0.1\u003C\u002Fh4>\n\u003Cp>– Added multi-language support\u003Cbr \u002F>\n– English as default language\u003Cbr \u002F>\n– Turkish translation included\u003Cbr \u002F>\n– Improved code structure and caching\u003C\u002Fp>\n\u003Ch4>1.0.0\u003C\u002Fh4>\n\u003Cp>– Initial release\u003Cbr \u002F>\n– 10 basic security features\u003Cbr \u002F>\n– Modern admin interface\u003Cbr \u002F>\n– AJAX-based setting changes\u003C\u002Fp>\n","Simple and effective security measures for your WordPress site. Many security features you can activate with a single click.",1118,"2026-01-10T09:04:00.000Z","6.9.5",[19,89,90,21,22],"headers","login-attempts","https:\u002F\u002Fdoc.webdoktoru.com.tr","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwebdoktoru-security.1.0.3.zip",{"slug":94,"name":95,"version":96,"author":97,"author_profile":98,"description":99,"short_description":100,"active_installs":11,"downloaded":101,"rating":11,"num_ratings":11,"last_updated":102,"tested_up_to":14,"requires_at_least":68,"requires_php":69,"tags":103,"homepage":23,"download_link":107,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"authyo-passwordless-login","Authyo Passwordless Login","1.0.8","Konceptwise Digital Media Pvt Ltd","https:\u002F\u002Fprofiles.wordpress.org\u002Fkonceptwise\u002F","\u003Cp>Authyo Passwordless Login is a WordPress login security plugin that protects your site with brute-force protection, IP blacklisting, security activity logs, XML-RPC blocking, REST API protection, and a custom login URL. All security features work immediately after activation — no API keys or account registration needed.\u003C\u002Fp>\n\u003Cp>Optionally, add Authyo API credentials to enable passwordless OTP login where users log in with a one-time password sent to their email instead of a traditional password.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security features that work without API keys:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Brute-force protection\u003C\u002Fstrong> — Limit login attempts per IP and username with progressive lockout durations. Repeat offenders are automatically blacklisted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Manager\u003C\u002Fstrong> — Whitelist trusted IPs and blacklist attackers. Includes search, filter, pagination, and per-page selector for large lists.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security activity logs\u003C\u002Fstrong> — Track every login, logout, failed attempt, lockout, and blocked access. Includes request URL tracking, date filters, search, and CSV export.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable XML-RPC\u003C\u002Fstrong> — Block xmlrpc.php requests at the server level using .htaccess rules. Removes X-Pingback headers and XML-RPC discovery links. Falls back to PHP blocking on Nginx.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Protection\u003C\u002Fstrong> — Restrict access to WordPress REST API endpoints for unauthenticated users. Prevents data enumeration and unauthorized access while keeping essential endpoints functional.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom login URL\u003C\u002Fstrong> — Hide wp-login.php behind a custom URL slug to prevent automated attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocked IP logging\u003C\u002Fstrong> — Every access attempt from blacklisted or locked-out IPs is logged with IP address, user agent, and request URL.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Passwordless login features (requires free Authyo API keys):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Email OTP login\u003C\u002Fstrong> — Users receive a one-time password via email and log in without a traditional password.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Authenticator fallback\u003C\u002Fstrong> — Server-side verified 2FA as a backup method after multiple OTP attempts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure login tokens\u003C\u002Fstrong> — Cryptographically generated, single-use, browser-bound tokens that expire after 5 minutes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AJAX-powered login\u003C\u002Fstrong> — Smooth login experience with no page reloads.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Video Tutorial\u003C\u002Fh3>\n\u003Cp>Learn how Authyo Passwordless Login works:\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FcStBvoHTzro?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Security (works immediately after activation):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Activate the plugin — brute-force protection and security logs start automatically\u003C\u002Fli>\n\u003Cli>Go to Settings > Authyo Passwordless Login > Security tab\u003C\u002Fli>\n\u003Cli>Enable XML-RPC Protection, REST API Protection, and Custom Login URL as needed\u003C\u002Fli>\n\u003Cli>Visit Authyo Logs to monitor activity and manage IPs\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Passwordless login (requires API keys):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>User enters their email on the WordPress login page\u003C\u002Fli>\n\u003Cli>A one-time password (OTP) is sent to their email\u003C\u002Fli>\n\u003Cli>User enters the OTP code\u003C\u002Fli>\n\u003Cli>WordPress logs the user in automatically — no password required\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to Authyo’s external API only for passwordless login and Google Authenticator features. All security features (brute-force protection, IP manager, security logs, XML-RPC protection, REST API protection, custom login URL) work locally without any external service.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>OTP Authentication:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>User email address is sent to Authyo API when requesting an OTP\u003C\u002Fli>\n\u003Cli>OTP code and Mask ID are sent to Authyo API for verification\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Google Authenticator Verification:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Verification token is sent to Authyo API for server-side validation\u003C\u002Fli>\n\u003Cli>The Authyo 2FA SDK script is loaded from \u003Ca href=\"https:\u002F\u002Fapp.authyo.io\u002Fjs\u002Fv1\u002Fauth-2fasdk.js\" rel=\"nofollow ugc\">https:\u002F\u002Fapp.authyo.io\u002Fjs\u002Fv1\u002Fauth-2fasdk.js\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Usage Tracking (Opt-In Only):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If the user explicitly opts in, plugin version, WordPress version, and site URL are sent when settings are saved. Deactivation feedback is sent when the plugin is deactivated. No tracking data is sent without user consent.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Authentication Flow:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>After OTP verification, the plugin generates a secure single-use token using WordPress core functions\u003C\u002Fli>\n\u003Cli>Token is browser-bound using a hashed User-Agent signature to prevent session hijacking\u003C\u002Fli>\n\u003Cli>Token is stored temporarily in WordPress transients (5-minute expiry) and deleted immediately after use\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Data Storage:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>OTP session data stored temporarily in WordPress transients (10-minute expiry)\u003C\u002Fli>\n\u003Cli>Login tokens stored temporarily in WordPress transients (5-minute expiry, single-use)\u003C\u002Fli>\n\u003Cli>Security logs stored in a custom database table with configurable retention\u003C\u002Fli>\n\u003Cli>IP whitelist and blacklist stored in a custom database table\u003C\u002Fli>\n\u003Cli>No user data is permanently stored beyond security logs\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Service URLs:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>API: \u003Ca href=\"https:\u002F\u002Fapp.authyo.io\u002Fapi\u002Fv1\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fapp.authyo.io\u002Fapi\u002Fv1\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>2FA SDK: \u003Ca href=\"https:\u002F\u002Fapp.authyo.io\u002Fjs\u002Fv1\u002Fauth-2fasdk.js\" rel=\"nofollow ugc\">https:\u002F\u002Fapp.authyo.io\u002Fjs\u002Fv1\u002Fauth-2fasdk.js\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fauthyo.io\u002Fterms-service\" rel=\"nofollow ugc\">https:\u002F\u002Fauthyo.io\u002Fterms-service\u003C\u002Fa>\u003Cbr \u002F>\n\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fauthyo.io\u002Fprivacy-policy\" rel=\"nofollow ugc\">https:\u002F\u002Fauthyo.io\u002Fprivacy-policy\u003C\u002Fa>\u003C\u002Fp>\n","WordPress login security with brute-force protection, IP manager, security logs, XML-RPC protection, REST API protection, and passwordless OTP login.",791,"2026-07-08T09:07:00.000Z",[71,104,73,105,106],"disable-xmlrpc","passwordless-login","rest-api-security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fauthyo-passwordless-login.1.0.8.zip",{"slug":109,"name":110,"version":111,"author":112,"author_profile":113,"description":114,"short_description":115,"active_installs":11,"downloaded":116,"rating":11,"num_ratings":11,"last_updated":117,"tested_up_to":14,"requires_at_least":118,"requires_php":69,"tags":119,"homepage":122,"download_link":123,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"brute-force-protector","Brute Force Protector","1.0.0","Kanhaiya Yaduwanshi","https:\u002F\u002Fprofiles.wordpress.org\u002Fkanhayaduwanshi\u002F","\u003Cp>Brute Force Protector is your site’s first line of defense against automated login attacks. Malicious bots constantly try to guess your password using brute force attacks, credential stuffing, and dictionary attacks — this plugin puts a complete stop to it.\u003C\u002Fp>\n\u003Cp>It works by tracking failed login attempts from each IP address. If an IP exceeds the configured number of failures in a short period, it gets temporarily blocked, preventing the attacker from making further attempts. This simple but effective method secures your login page, protects your wp-admin area, and strengthens your overall WordPress security without adding complexity.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Who needs this plugin?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If you are looking for a way to secure WordPress login, limit login attempts, block bots from wp-login.php, stop brute force password attacks, prevent unauthorized access to your WordPress dashboard, or simply improve your WordPress site security — this plugin is built for you. It is the ideal WordPress security plugin for beginners and professionals alike.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How it helps:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>By acting as a login-level firewall, Brute Force Protector reduces the risk of hacked WordPress sites, compromised admin accounts, and malware injections that often start with a brute force attack. It is a lightweight, zero-configuration WordPress protection tool that starts working the moment it is activated.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Limit Login Attempts:\u003C\u002Fstrong> Set a maximum number of failed login attempts before an IP is blocked.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable Lockout Duration:\u003C\u002Fstrong> Define how long a blocked IP should be denied access.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Simple Settings Page:\u003C\u002Fstrong> Easily configure the plugin from the WordPress admin dashboard under “Settings” > “Brute Force Protector”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight and Efficient:\u003C\u002Fstrong> Designed to be fast and have a minimal impact on your site’s performance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clears on Successful Login:\u003C\u002Fstrong> The failed attempt counter is reset when a user successfully logs in.\u003C\u002Fli>\n\u003C\u002Ful>\n","Protect your WordPress site from brute force attacks, login security threats, and unauthorized access. Limit login attempts, block malicious IPs, and  &hellip;",149,"2026-05-25T06:57:00.000Z","5.2",[19,120,73,21,121],"limit-login-attempts","wp-admin-protection","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbrute-force-protector","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbrute-force-protector.1.0.0.zip",{"error":125,"url":126,"statusCode":127,"statusMessage":128,"message":128},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fholographic-login-shield\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":130,"versions":131},1,[132],{"version":6,"download_url":24,"svn_tag_url":133,"released_at":26,"has_diff":134,"diff_files_changed":135,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":136,"is_current":125},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fholographic-login-shield\u002Ftags\u002F1.0.15\u002F",false,[],[]]