[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6twQGlBlpC3wGB5yeuQnyueg5yBzKwVEoTMyuu9dAiI":3,"$fqDpxmYZlOdPcIRIowQKbkQF0wpOd1jaKPn8lgdDvnbE":138,"$fxHY_9qWX5Ha7xRTfNe80GEJX2kuY_GFJI2f9Ct6cMpo":143},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":26,"fingerprints":26},"naveencodes-login-guard","NaveenCodes Login Guard","1.0.0","Naveen Goyal","https:\u002F\u002Fprofiles.wordpress.org\u002Fshinu1503\u002F","\u003Cp>\u003Cstrong>Login Guard\u003C\u002Fstrong> is a powerful, privacy-first login security plugin that runs entirely on your own server — no cloud service, no external API calls, no telemetry.\u003C\u002Fp>\n\u003Ch4>Core Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Brute-Force Protection\u003C\u002Fstrong>\u003Cbr \u002F>\nAutomatically detects repeated failed login attempts from the same IP address. When a configurable threshold is reached, the IP is locked out and can be automatically added to the block list.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Live Login Activity Log\u003C\u002Fstrong>\u003Cbr \u002F>\nEvery login attempt — successful, failed, or blocked — is recorded with IP address, username, user agent, and timestamp. Full filter, paginate, and export to CSV.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>IP Block List\u003C\u002Fstrong>\u003Cbr \u002F>\nManually block specific IP addresses, with permanent or time-limited expiry. Auto-blocked IPs are automatically pruned when their lockout period ends.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>IP Allow List\u003C\u002Fstrong>\u003Cbr \u002F>\nProtect your own IP or your developer’s IP from ever being blocked — even during testing.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Instant Email Alerts\u003C\u002Fstrong>\u003Cbr \u002F>\nGet notified when a suspicious number of failed attempts is detected from a single IP, or when a successful login occurs from a new location for any user.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Dashboard Overview\u003C\u002Fstrong>\u003Cbr \u002F>\nAt-a-glance stats with a 7-day bar chart (no external chart libraries), auto-refreshed every 30 seconds.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WP Admin Dashboard Widget\u003C\u002Fstrong>\u003Cbr \u002F>\nQuick stats and last 5 login attempts visible from the main WordPress dashboard.\u003C\u002Fp>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>Login Guard stores IP addresses and usernames in your own database. No data leaves your server.\u003C\u002Fp>\n\u003Ch4>Free, Forever\u003C\u002Fh4>\n\u003Cp>No upsells, no premium tier, no usage limits. Login Guard is completely free.\u003C\u002Fp>\n\u003Cp>❤️ \u003Cem>Dedicated in loving memory of Maa — 18 May.\u003C\u002Fem>\u003C\u002Fp>\n","Brute-force protection, live login-attempt log, IP block\u002Fallow lists, and instant email alerts — all on your server, zero external requests.",0,78,"2026-06-26T05:58:00.000Z","7.0.2","6.5","8.0",[18,19,20,21,22],"brute-force","ip-block","login-protection","login-security","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fnaveencodes-login-guard\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fnaveencodes-login-guard.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"shinu1503",9,30,94,"2026-08-29T07:27:52.918Z",[37,58,80,101,118],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":14,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":51,"download_link":55,"security_score":47,"vuln_count":56,"unpatched_count":11,"last_vuln_date":57,"fetched_at":27},"limit-login-attempts-reloaded","Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention","3.3.4","WPChef","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpchefgadget\u002F","\u003Cp>Protect your WordPress website against brute force attacks, bot attacks, and unauthorized login attempts with one of the most trusted login security plugins for WordPress.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\" rel=\"nofollow ugc\">Limit Login Attempts Security\u003C\u002Fa> strengthens your WordPress login security by limiting failed login attempts, blocking malicious IPs, securing wp-login.php, protecting XML-RPC, and adding powerful firewall and 2FA protection without slowing down your website.\u003C\u002Fp>\n\u003Cp>Trusted by 2 million WordPress websites, Limit Login Attempts Security is designed specifically to protect the most targeted part of your website: the login page.\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FS3nf8Zpbcfs?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>Why Use Limit Login Attempts Security?\u003C\u002Fh4>\n\u003Cp>By default, WordPress allows unlimited login attempts. This creates a major security vulnerability where bots and attackers can repeatedly guess usernames and passwords until they gain access. This is especially important in the age of AI, where attackers now have access to faster and more sophisticated tools than ever before.\u003C\u002Fp>\n\u003Cp>Limit Login Attempts Security helps stop:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Brute force attacks\u003C\u002Fli>\n\u003Cli>Bot login attacks\u003C\u002Fli>\n\u003Cli>Credential stuffing attacks\u003C\u002Fli>\n\u003Cli>XML-RPC attacks\u003C\u002Fli>\n\u003Cli>Unauthorized login attempts\u003C\u002Fli>\n\u003Cli>WooCommerce login abuse\u003C\u002Fli>\n\u003Cli>Malicious IP access attempts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin automatically blocks excessive login attempts and locks out suspicious IP addresses and usernames before attackers can gain access.\u003C\u002Fp>\n\u003Ch4>Features Included in the Free Version\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Login Security & Brute Force Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Limit login attempts by IP address and username\u003C\u002Fli>\n\u003Cli>Automatically lock out suspicious login activity\u003C\u002Fli>\n\u003Cli>Adjustable lockout duration and retry limits\u003C\u002Fli>\n\u003Cli>Protect wp-login.php from automated attacks\u003C\u002Fli>\n\u003Cli>Prevent brute force login attacks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>2FA \u002F Multi-Factor Authentication (MFA)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Built-in two-factor authentication (2FA)\u003C\u002Fli>\n\u003Cli>Add an additional layer of login protection\u003C\u002Fli>\n\u003Cli>Improve WordPress account security\u003C\u002Fli>\n\u003Cli>Secure administrator and user logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Firewall & Bot Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Block malicious login requests\u003C\u002Fli>\n\u003Cli>Detect suspicious login behavior\u003C\u002Fli>\n\u003Cli>Reduce bot-based login attacks\u003C\u002Fli>\n\u003Cli>Lightweight firewall-focused login protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>WooCommerce & Plugin Compatibility\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Protects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WooCommerce login pages\u003C\u002Fli>\n\u003Cli>XML-RPC login requests\u003C\u002Fli>\n\u003Cli>Custom login pages\u003C\u002Fli>\n\u003Cli>WordPress multisite installations\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Compatible With:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Wordfence\u003C\u002Fli>\n\u003Cli>Sucuri\u003C\u002Fli>\n\u003Cli>Ultimate Member\u003C\u002Fli>\n\u003Cli>MemberPress\u003C\u002Fli>\n\u003Cli>WPS Hide Login\u003C\u002Fli>\n\u003Cli>Cloudflare and reverse proxy setups\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Login Monitoring & Notifications\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Failed login attempt logs\u003C\u002Fli>\n\u003Cli>Lockout email notifications\u003C\u002Fli>\n\u003Cli>Denied attempt tracking\u003C\u002Fli>\n\u003Cli>Login retry visibility for users\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Access Controls\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>IP safelist and denylist support\u003C\u002Fli>\n\u003Cli>Username safelist and denylist support\u003C\u002Fli>\n\u003Cli>IPv6 range support\u003C\u002Fli>\n\u003Cli>Custom IP origin configuration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Premium Features (Start Your Free 14 Day Trial)\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fplans\u002F\" rel=\"nofollow ugc\">Upgrade to Limit Login Attempts Security Premium\u003C\u002Fa> to extend protection with cloud-based login security and advanced attack prevention.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Cloud Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Real-time malicious IP intelligence\u003C\u002Fli>\n\u003Cli>Global denylist protection\u003C\u002Fli>\n\u003Cli>Synchronized lockouts across websites\u003C\u002Fli>\n\u003Cli>Auto IP denylist generation\u003C\u002Fli>\n\u003Cli>Cloud-based login attack mitigation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Enhanced Performance Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Offload excessive failed login requests from your server\u003C\u002Fli>\n\u003Cli>Reduce server strain during attacks\u003C\u002Fli>\n\u003Cli>Improve stability under heavy attack conditions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced Security Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Country-based login blocking\u003C\u002Fli>\n\u003Cli>Enhanced throttling and lockout escalation\u003C\u002Fli>\n\u003Cli>Registration page protection\u003C\u002Fli>\n\u003Cli>Successful login tracking\u003C\u002Fli>\n\u003Cli>Enhanced lockout analytics and geolocation data\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Multi-Site & Team Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Shared safelist and denylist syncing\u003C\u002Fli>\n\u003Cli>Shared lockout protection between domains\u003C\u002Fli>\n\u003Cli>Cloud backups of IP security data\u003C\u002Fli>\n\u003Cli>CSV exports of login and IP activity\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Premium Support\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Access to security-focused support specialists\u003C\u002Fli>\n\u003Cli>Faster troubleshooting and assistance\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Lightweight Security Built for WordPress\u003C\u002Fh4>\n\u003Cp>Unlike many large security suites, Limit Login Attempts Security focuses specifically on login security and brute force protection.\u003C\u002Fp>\n\u003Cp>This means:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Faster performance\u003C\u002Fli>\n\u003Cli>Less server overhead\u003C\u002Fli>\n\u003Cli>Easier configuration\u003C\u002Fli>\n\u003Cli>Strong protection without unnecessary bloat\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Protect More Than Just wp-login.php\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Security secures:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>wp-login.php\u003C\u002Fli>\n\u003Cli>XML-RPC\u003C\u002Fli>\n\u003Cli>WooCommerce logins\u003C\u002Fli>\n\u003Cli>Custom login forms\u003C\u002Fli>\n\u003Cli>Registration pages\u003C\u002Fli>\n\u003Cli>Multisite logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Trusted by Millions of WordPress Websites\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Security is one of the most widely used WordPress login security plugins and has helped protect millions of websites from brute force attacks and malicious login activity.\u003C\u002Fp>\n\u003Cp>Whether you run:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>A personal blog\u003C\u002Fli>\n\u003Cli>WooCommerce store\u003C\u002Fli>\n\u003Cli>Membership website\u003C\u002Fli>\n\u003Cli>Agency\u003C\u002Fli>\n\u003Cli>Business website\u003C\u002Fli>\n\u003Cli>Enterprise WordPress network\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Limit Login Attempts Security helps secure your login experience with modern WordPress login protection.\u003C\u002Fp>\n\u003Ch4>Upgrading from the Original Limit Login Attempts Plugin?\u003C\u002Fh4>\n\u003Cp>Switching is easy:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Remove the old Limit Login Attempts plugin\u003C\u002Fli>\n\u003Cli>Install Limit Login Attempts Security\u003C\u002Fli>\n\u003Cli>Your settings will remain intact\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Translation Support\u003C\u002Fh4>\n\u003Cp>Currently translated into multiple languages including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Dutch\u003C\u002Fli>\n\u003Cli>Turkish\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Romanian\u003C\u002Fli>\n\u003Cli>Chinese (Traditional)\u003C\u002Fli>\n\u003Cli>Brazilian Portuguese\u003C\u002Fli>\n\u003Cli>And more\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Secure Your WordPress Login Today\u003C\u002Fh4>\n\u003Cp>Install Limit Login Attempts Security and protect your WordPress website with:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Login security\u003C\u002Fli>\n\u003Cli>Two-Factor Authentication (2FA)\u003C\u002Fli>\n\u003Cli>Brute force protection\u003C\u002Fli>\n\u003Cli>Firewall security\u003C\u002Fli>\n\u003Cli>Bot protection\u003C\u002Fli>\n\u003Cli>XML-RPC protection\u003C\u002Fli>\n\u003Cli>WooCommerce login protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Without slowing down your website.\u003C\u002Fp>\n","WordPress login security with brute force protection, Two-factor authentication (2FA\u002FMFA), firewall, IP\u002Fcountry blocking, and login monitoring",1000000,91831747,98,1468,"2026-07-08T11:06:00.000Z","5.0","",[53,18,54,21,22],"2fa","firewall","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flimit-login-attempts-reloaded.3.3.4.zip",4,"2023-12-20 00:00:00",{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":66,"downloaded":67,"rating":68,"num_ratings":69,"last_updated":70,"tested_up_to":14,"requires_at_least":71,"requires_php":72,"tags":73,"homepage":77,"download_link":78,"security_score":34,"vuln_count":56,"unpatched_count":11,"last_vuln_date":79,"fetched_at":27},"melapress-login-security","Melapress Login Security","2.3.0","Melapress","https:\u002F\u002Fprofiles.wordpress.org\u002Fmelapress\u002F","\u003Cp>\u003Cstrong> COMPREHENSIVE WORDPRESS LOGIN SECURITY PLUGIN \u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Melapress Login Security\u003C\u002Fa> enables you to effortlessly set login security policies that put you firmly in the driver’s seat of your WordPress sites. Policies are highly customizable and granular and can be implemented by user role or site-wide for complete control over the security of your WordPress login processes.\u003C\u002Fp>\n\u003Cp>Use the free edition of Melapress Login Security to implement WordPress password requirements such as minimum length and complexity rules. The plugin also allows you to set password expiration policies, prevent password reuse, limit failed login attempts, and automatically disable inactive user accounts, among other things. This helps you:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Prevent unauthorized login attempts\u003C\u002Fli>\n\u003Cli>Protect against brute force attacks\u003C\u002Fli>\n\u003Cli>Comply with GDPR with a login consent notice\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔐 Features list\u003C\u002Fh3>\n\u003Cp>A secure WordPress login starts right here. Explore all of the features included with the free edition of \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\" rel=\"nofollow ugc\">Melapress Login Security\u003C\u002Fa>:\u003C\u002Fp>\n\u003Ch3>Set password policies\u003C\u002Fh3>\n\u003Cp>Strong passwords are your first line of defense against bad actors looking to gain access to your site. Set password requirement policies to make sure users set strong passwords. Set policies by user role or site-wide and define policy priority for users with multiple roles.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Set minimum password length\u003C\u002Fli>\n\u003Cli>Require uppercase and lowercase characters, numbers, and special characters\u003C\u002Fli>\n\u003Cli>Set an automatic password expiration policy and advise users when their password is about to expire\u003C\u002Fli>\n\u003Cli>Disallow users from reusing passwords\u003C\u002Fli>\n\u003Cli>Provide users with helpful instructions during the password configuration stage\u003C\u002Fli>\n\u003Cli>Disable password reset links\u003C\u002Fli>\n\u003Cli>Mandate WordPress password reset on the first login\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Limit login attempts\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fsupport\u002Fkb\u002Fmelapress-login-security-failed-logins-policy-wordpress\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Limit failed login attempts\u003C\u002Fa> and put an end to brute force attacks. Protect your login form by automatically disabling user accounts after a number of failed login attempts. Choose between manual unlocking by an admin or automatic unlocking after a cooldown period.\u003C\u002Fp>\n\u003Ch3>Temporary login without password\u003C\u002Fh3>\n\u003Cp>Provide temporary and secure login access to third parties, like developers, editors, employees or others, without a password. It works by providing the user with a temporary login link that expires after a certain amount of time, or after a number of uses. This prevents you from having to create new user accounts manually, while simultaneously reducing the security risks associated with old, unused user accounts.\u003C\u002Fp>\n\u003Ch3>Change WordPress login URL\u003C\u002Fh3>\n\u003Cp>Easily deploy security-by-obscurity tactics and change your WordPress login page URL using a plugin! Hiding the default login page from hackers makes it more difficult to find, potentially reducing brute force attacks and other unauthorized access attempts. After you change the default wp-admin URL, you can set a 404 for the old login page or redirect it to any page of your choosing.\u003C\u002Fp>\n\u003Ch3>Limit login page access by IP address(es)\u003C\u002Fh3>\n\u003Cp>Limit access to the WordPress login page by IP address(es) for additional security.\u003C\u002Fp>\n\u003Ch3>GDPR login page consent notice\u003C\u002Fh3>\n\u003Cp>Easily meet GDPR requirements by adding a GDPR consent notice to the login page. This is required for GDPR and PCI DSS compliance, thus ensuring your WordPress site login page is in compliance.\u003C\u002Fp>\n\u003Ch3>Emergency password reset\u003C\u002Fh3>\n\u003Cp>Discovered suspicious behavior? Reset all users’ passwords with just one click and regain instant control.\u003C\u002Fp>\n\u003Ch3>Upgrade to Melapress Login Security Premium and get even more benefits.\u003C\u002Fh3>\n\u003Cp>The premium edition of Melapress Login Security comes bundled with even more features, which enable you to take your WordPress website login security to the next level. Disable inactive WordPress user accounts and force passwords to be reset once accounts have been unlocked. Inactive accounts can be managed within a single dashboard for increased efficiency and faster response times. Moreover, you can set accounts to be locked out after a number of failed login attempts and customize the duration and method of unlocking them.\u003C\u002Fp>\n\u003Ch3>Premium features list\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Everything included in the free edition\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manually lock user accounts\u003C\u002Fstrong> to immediately prevent login access for rarely used accounts or users on extended leave\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Add an extra security layer with security questions\u003C\u002Fstrong> users must answer when performing sensitive actions such as password resets and account unlocks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Receive email alerts for unrecognized device logins\u003C\u002Fstrong>, with the option to remotely terminate the session\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Control user session duration\u003C\u002Fstrong> by extending or shortening session timeouts to balance security and convenience\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-click integration with third-party plugins\u003C\u002Fstrong> such as WooCommerce, LearnDash, MemberPress, and many others\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatically \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Finactive-users-wordpress\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">disable inactive WordPress users\u003C\u002Fa>\u003C\u002Fstrong> after a configurable period of inactivity\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Apply Geo-blocking rules\u003C\u002Fstrong> to allow or block login access based on specific countries\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fsupport\u002Fkb\u002Fmelapress-login-security-limit-login-ips\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Restrict users’ login to specific IP addresses\u003C\u002Fa>\u003C\u002Fstrong>, including support for multiple allowed IPs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fsupport\u002Fkb\u002Frestrict-users-log-in-time-wordpress-website\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Restrict WordPress user login times\u003C\u002Fa>\u003C\u002Fstrong> by day and\u002For hours\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Limit login credentials\u003C\u002Fstrong> to email address, username, or both\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Add a GDPR consent notice\u003C\u002Fstrong> to the WordPress login page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>View detailed user security reports\u003C\u002Fstrong>, including last activity, password age, and expired passwords\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Receive weekly email summary reports\u003C\u002Fstrong> covering password resets, password changes, user account lockouts, and more\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>|💎 \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\u002Fpricing\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">UPGRADE TO PREMIUM\u003C\u002Fa> |\u003C\u002Fp>\n\u003Ch3>Why you should use Melapress Login Security\u003C\u002Fh3>\n\u003Cp>Melapress Login Security is a WordPress plugin built from the ground up to help you improve the security of your user accounts and secure your WordPress login. Supercharge login credentials for maximum effectiveness and put a stop to unlimited login attempts, weak passwords, and inactive users. Set up policies to reduce your attack surface area such as login times restrictions, change the WordPress login URL, and much more.\u003C\u002Fp>\n\u003Ch3>Free and premium support\u003C\u002Fh3>\n\u003Cp>Support for the free edition of Melapress Login Security is free on the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fmelapress-login-security\u002F\" rel=\"ugc\">WordPress support forums\u003C\u002Fa>. Premium world-class support via one-to-one email is available to the Premium users – \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\u002Fpricing\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">upgrade to premium\u003C\u002Fa> to benefit from priority support.\u003C\u002Fp>\n\u003Cp>For any other queries, feedback, or if you simply want to get in touch with us, please use our \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fcontact\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">contact form\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>MAINTAINED & SUPPORTED BY MELAPRESS\u003C\u002Fh4>\n\u003Cp>Melapress builds high-quality WordPress security & admin plugins such as \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-2fa\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">WP 2FA\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-user-roles-editor\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Melapress Role Editor\u003C\u002Fa>,and \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-activity-log\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">WP Activity Log\u003C\u002Fa>, the #1 user-rated activity log plugin for WordPress.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Visit our website\u003C\u002Fa> to see how our plugins can help you better manage and improve the security and administration of your WordPress websites and users.\u003C\u002Fp>\n\u003Ch3>Install the plugin from within WordPress\u003C\u002Fh3>\n\u003Cp>Keeping a secure WordPress login page is easy with \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\" rel=\"nofollow ugc\">Melapress Login Security\u003C\u002Fa>. Simply:\u003C\u002Fp>\n\u003Col>\n\u003Cli>From your WordPress dashboard, navigate to Plugins > Add New\u003C\u002Fli>\n\u003Cli>Search for “\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\" rel=\"nofollow ugc\">Melapress Login Security\u003C\u002Fa>”\u003C\u002Fli>\n\u003Cli>Install & activate \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\" rel=\"nofollow ugc\">Melapress Login Security\u003C\u002Fa> from your Plugins page\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Install the plugin manually (via file upload)\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Download the plugin from the WordPress plugins repository\u003C\u002Fli>\n\u003Cli>Unzip the zip file and upload the folder to the \u003Ccode>\u002Fwp-content\u002Fplugins\u002F\u003C\u002Fcode> directory\u003C\u002Fli>\n\u003Cli>Activate the Melapress Login Security plugin through the Plugins page in WordPress\u003C\u002Fli>\n\u003C\u002Fol>\n","Enforce WordPress login and password security policies to protect user accounts and prevent unauthorized logins.",2000,27376,96,19,"2026-05-20T18:29:00.000Z","5.5","7.3",[18,74,75,76,21],"limit-login-attempts","limit-logins","login","https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmelapress-login-security.2.3.0.zip","2025-07-25 16:23:06",{"slug":81,"name":82,"version":83,"author":84,"author_profile":85,"description":86,"short_description":87,"active_installs":88,"downloaded":89,"rating":25,"num_ratings":90,"last_updated":91,"tested_up_to":92,"requires_at_least":93,"requires_php":94,"tags":95,"homepage":51,"download_link":100,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"ip-blocker-lite","IP & Country Blocker Lite","3.0.0","Nurul Islam","https:\u002F\u002Fprofiles.wordpress.org\u002Ffaqnurul\u002F","\u003Cp>IP & Country Blocker Lite is a comprehensive WordPress security plugin that provides multiple layers of protection for your website. Block unwanted visitors based on IP addresses or countries, and add an extra layer of security with two-factor authentication (2FA).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Features:\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>IP Address Blocking\u003C\u002Fstrong>: Block or allow specific IP addresses, IP ranges, or subnets\u003Cbr \u002F>\n* \u003Cstrong>Country-Based Blocking\u003C\u002Fstrong>: Restrict access based on visitors’ countries\u003Cbr \u002F>\n* \u003Cstrong>Two-Factor Authentication\u003C\u002Fstrong>: Secure admin logins with email-based 2FA or authenticator apps\u003Cbr \u002F>\n* \u003Cstrong>Recovery Codes\u003C\u002Fstrong>: Backup access codes for account recovery\u003Cbr \u002F>\n* \u003Cstrong>Emergency Recovery\u003C\u002Fstrong>: Generate secure recovery URLs to disable the plugin if locked out\u003Cbr \u002F>\n* \u003Cstrong>Advanced Security Dashboard\u003C\u002Fstrong>: Monitor blocked attempts and security events\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Benefits:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Protect against spam, bots, and malicious traffic\u003Cbr \u002F>\n* Prevent brute force attacks on admin login\u003Cbr \u002F>\n* Block entire countries or regions\u003Cbr \u002F>\n* Easy-to-use admin interface with real-time monitoring\u003Cbr \u002F>\n* Lightweight and fast performance\u003Cbr \u002F>\n* No external dependencies for core functionality\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Easy Management:\u003C\u002Fstrong>\u003Cbr \u002F>\n* One-click blocking\u002Funblocking\u003Cbr \u002F>\n* Intuitive admin panel with tabbed interface\u003Cbr \u002F>\n* Real-time activity logs\u003Cbr \u002F>\n* Bulk operations support\u003Cbr \u002F>\n* Custom blocked page templates\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Monitoring & Analytics:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Track blocked IP attempts\u003Cbr \u002F>\n* View country-wise access statistics\u003Cbr \u002F>\n* Monitor security events\u003Cbr \u002F>\n* Export blocking rules\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy & Compliance:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Uses free IP-API.com service for geolocation\u003Cbr \u002F>\n* No personal data storage\u003Cbr \u002F>\n* GDPR compliant\u003Cbr \u002F>\n* Respects user privacy\u003C\u002Fp>\n\u003Ch3>Data Collection & Privacy\u003C\u002Fh3>\n\u003Cp>For transparency, here’s what data the plugin collects and why:\u003C\u002Fp>\n\u003Ch3>\u003Cstrong>Essential Data Collection (Always Required for Functionality):\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>IP Addresses\u003C\u002Fstrong>: Collected for security blocking and geolocation features\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Enable IP\u002Fcountry blocking, security monitoring, and access control\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage\u003C\u002Fstrong>: Temporary (not stored in database, only processed in memory)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Third Parties\u003C\u002Fstrong>: Sent to IP-API.com for country lookup (free service)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Country Information\u003C\u002Fstrong>: Derived from IP addresses via geolocation\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Enable country-based blocking and access statistics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage\u003C\u002Fstrong>: Not stored permanently (only used for blocking decisions)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Third Parties\u003C\u002Fstrong>: Retrieved from IP-API.com (free geolocation service)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>\u003Cstrong>Optional Data Collection (Only with User Consent):\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Plugin Usage Statistics\u003C\u002Fstrong>: Anonymous plugin performance data\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Improve plugin quality and fix bugs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Collected\u003C\u002Fstrong>: Plugin version, WordPress version, PHP version, activation date\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage\u003C\u002Fstrong>: Remote server (only if user consents)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy\u003C\u002Fstrong>: Completely anonymous, no personal identifiers\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>User Feedback\u003C\u002Fstrong>: Plugin reviews and feedback submissions\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Understand user needs and improve features\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Collected\u003C\u002Fstrong>: Feedback text, rating, plugin version, PHP version\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage\u003C\u002Fstrong>: Remote server (only if user consents)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy\u003C\u002Fstrong>: Anonymous feedback, no personal data required\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: http:\u002F\u002Fcodecanvasbd\u002Fprivacy-policy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>\u003Cstrong>Data Collection Controls:\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Consent Required\u003C\u002Fstrong>: Optional data collection requires explicit user consent\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Easy Opt-out\u003C\u002Fstrong>: Users can decline consent at any time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No Automatic Collection\u003C\u002Fstrong>: No data sent without user permission\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Transparent Process\u003C\u002Fstrong>: Clear consent modal explains what data is collected\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>\u003Cstrong>Third-Party Services:\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>IP-API.com\u003C\u002Fstrong>: Free geolocation service for country detection\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Data sent: Visitor IP addresses\u003C\u002Fli>\n\u003Cli>Purpose: Determine visitor country for blocking features\u003C\u002Fli>\n\u003Cli>Privacy: IP-API.com privacy policy applies\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Remote Analytics Server\u003C\u002Fstrong> (optional, consent required):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Data sent: Anonymous usage statistics\u003C\u002Fli>\n\u003Cli>Purpose: Plugin improvement and support\u003C\u002Fli>\n\u003Cli>Privacy: No personal data, fully anonymous\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>\u003Cstrong>GDPR Compliance:\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>✅ No personal data storage without consent\u003C\u002Fli>\n\u003Cli>✅ Clear consent mechanisms\u003C\u002Fli>\n\u003Cli>✅ Easy opt-out options\u003C\u002Fli>\n\u003Cli>✅ Transparent data practices\u003C\u002Fli>\n\u003Cli>✅ Data minimization principles\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Main Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>IP & Country Blocking:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Block specific IP addresses or ranges (CIDR notation supported)\u003Cbr \u002F>\n* Block entire countries or allow only specific countries\u003Cbr \u002F>\n* Whitelist important IPs for access\u003Cbr \u002F>\n* Real-time blocking with immediate effect\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Two-Factor Authentication (2FA):\u003C\u002Fstrong>\u003Cbr \u002F>\n* Email-based 2FA for easy setup\u003Cbr \u002F>\n* Authenticator app support (Google Authenticator, Authy, etc.)\u003Cbr \u002F>\n* Recovery codes for account access\u003Cbr \u002F>\n* Secure code generation and validation\u003Cbr \u002F>\n* Admin email verification\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Emergency Recovery System:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Generate secure recovery URLs to disable plugin if locked out\u003Cbr \u002F>\n* Time-limited recovery hashes (24 hours expiration)\u003Cbr \u002F>\n* One-click plugin deactivation via recovery URL\u003Cbr \u002F>\n* Secure hash verification to prevent unauthorized access\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Admin Interface:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Modern, responsive dashboard\u003Cbr \u002F>\n* Tabbed navigation for easy access\u003Cbr \u002F>\n* Real-time statistics and charts\u003Cbr \u002F>\n* Activity logs with filtering\u003Cbr \u002F>\n* Bulk operations for efficiency\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Monitoring:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Track blocked access attempts\u003Cbr \u002F>\n* Country-wise visitor statistics\u003Cbr \u002F>\n* Failed login monitoring\u003Cbr \u002F>\n* Security event logging\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Performance Optimized:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Lightweight codebase\u003Cbr \u002F>\n* Minimal database queries\u003Cbr \u002F>\n* Fast IP lookups\u003Cbr \u002F>\n* Caching support\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin uses the IP-API.com service to detect the user’s location based on their IP address.\u003Cbr \u002F>\n– \u003Cstrong>Service\u003C\u002Fstrong>: IP-API.com (http:\u002F\u002Fip-api.com)\u003Cbr \u002F>\n– \u003Cstrong>Purpose\u003C\u002Fstrong>: IP geolocation for country-based blocking\u003Cbr \u002F>\n– \u003Cstrong>Data Sent\u003C\u002Fstrong>: User’s IP address only\u003Cbr \u002F>\n– \u003Cstrong>Privacy Policy\u003C\u002Fstrong>: http:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\u003Cbr \u002F>\n– \u003Cstrong>Data Storage\u003C\u002Fstrong>: No personal data is stored by this plugin\u003C\u002Fp>\n\u003Cp>The plugin works without this service but country blocking features will be limited.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support, bug reports, or feature requests:\u003Cbr \u002F>\n– \u003Cstrong>WordPress.org Support Forum\u003C\u002Fstrong>: https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fip-blocker-lite\u002F\u003Cbr \u002F>\n– \u003Cstrong>GitHub Issues\u003C\u002Fstrong>: Report bugs and request features\u003Cbr \u002F>\n– \u003Cstrong>Email\u003C\u002Fstrong>: Contact through WordPress.org profile\u003C\u002Fp>\n\u003Ch3>Contributing\u003C\u002Fh3>\n\u003Cp>Contributions are welcome! Please feel free to submit pull requests or open issues on GitHub.\u003C\u002Fp>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Developer\u003C\u002Fstrong>: Nurul Islam (faqnurul)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Icons\u003C\u002Fstrong>: Dashicons (WordPress)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geolocation\u003C\u002Fstrong>: IP-API.com (free tier)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Charts\u003C\u002Fstrong>: Chart.js library\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GPLv2 or later.\u003Cbr \u002F>\nLicense URI: http:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-2.0.html\u003C\u002Fp>\n\u003Cp>Take control of your website’s security and protect it from unwanted visitors with IP & Country Blocker Lite!\u003C\u002Fp>\n","Advanced WordPress security plugin with IP\u002Fcountry blocking and two-factor authentication for comprehensive website protection.",300,2622,1,"2026-01-05T16:17:00.000Z","6.9.5","4.0","7.0",[96,97,21,98,99],"country-blocker","ip-blocker","two-factor-authentication","website-security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fip-blocker-lite.zip",{"slug":102,"name":103,"version":104,"author":105,"author_profile":106,"description":107,"short_description":108,"active_installs":88,"downloaded":109,"rating":25,"num_ratings":90,"last_updated":110,"tested_up_to":14,"requires_at_least":111,"requires_php":112,"tags":113,"homepage":51,"download_link":117,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"kaya-login-captcha","Kaya Login Captcha","1.0.2","Kaya Studio","https:\u002F\u002Fprofiles.wordpress.org\u002Fkayastudio\u002F","\u003Cp>\u003Cstrong>Why use “Kaya Login Captcha”?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin Adds a simple captcha on login form, register form and lost-password form.\u003C\u002Fp>\n\u003Cp>Easy install and use, captcha settings are fully customizable and you can choose the forms on which to display it. The blocked request HTTP status can be customized and the XML-RPC feature can be disabled.\u003C\u002Fp>\n\u003Cp>Captcha statistics are also available on the settings page, with the count of passed and blocked requests sorted by year and month.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Captcha available on the login form (Dashboard and WooCommerce).\u003C\u002Fli>\n\u003Cli>Captcha available on the lost-password form (Dashboard and WooCommerce).\u003C\u002Fli>\n\u003Cli>Captcha available on the register form (Dashboard and WooCommerce).\u003C\u002Fli>\n\u003Cli>Editable Captcha code length.\u003C\u002Fli>\n\u003Cli>Editable Captcha code format: numeric, alphabetic or alphanumeric.\u003C\u002Fli>\n\u003Cli>Random lines available in the background of the Captcha.\u003C\u002Fli>\n\u003Cli>Editable blocked request HTTP status.\u003C\u002Fli>\n\u003Cli>XML-RPC WordPress API deactivatable.\u003C\u002Fli>\n\u003Cli>Captcha statistics of passed and blocked requests sorted by year and month.\u003C\u002Fli>\n\u003Cli>Compatible with WordPress MultiSite and WooCommerce.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>“Kaya Login Captcha” is a professional login captcha system with fully customizable settings.\u003C\u002Fp>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>This plugin does not collect or store any user data. It does not set any cookies and does not connect to any third-party applications. This plugin only generate a captcha code to verify human action for selected forms on your settings.\u003C\u002Fp>\n\u003Ch4>Available Languages\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>English.\u003C\u002Fli>\n\u003Cli>French.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Feedback\u003C\u002Fh4>\n\u003Cp>Any suggestions or feedback is welcome, thank you for using or trying one of my plugins. Please take the time to let me know about your experiences and rate this plugin.\u003C\u002Fp>\n","Adds a simple captcha on login form, register form and lost-password form.",3036,"2026-05-17T14:14:00.000Z","4.6.0","5.3",[114,115,76,21,116],"brute-force-protection","captcha","spam","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fkaya-login-captcha.1.0.2.zip",{"slug":119,"name":120,"version":121,"author":122,"author_profile":123,"description":124,"short_description":125,"active_installs":126,"downloaded":127,"rating":25,"num_ratings":128,"last_updated":129,"tested_up_to":14,"requires_at_least":130,"requires_php":131,"tags":132,"homepage":136,"download_link":137,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"login-armor","Login Armor","2.4.5","wpformation","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpformation\u002F","\u003Cp>\u003Cstrong>Twelve security modules. One lightweight plugin. Zero compromise.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Login Armor is a complete WordPress security stack built for agencies, freelancers and pros who deliver audit-ready sites. No premium tier, no bundled marketing dashboard, no telemetry. Every module runs locally, ships with safe defaults, and stays out of your way.\u003C\u002Fp>\n\u003Cp>Stop juggling Wordfence’s bloat, Solid Security’s upsells, and Limit Login Attempts’ gaps — Login Armor delivers twelve independent modules in about one megabyte.\u003C\u002Fp>\n\u003Ch4>New in 2.4.0\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Request Firewall\u003C\u002Fstrong> — an optional, 8G-inspired PHP filter that blocks malicious requests (SQL injection, code execution, traversal, XSS, disallowed HTTP methods) before WordPress finishes loading, on Apache, Nginx and LiteSpeed alike. Off by default, it starts in monitor mode and never filters logged-in administrators; every block is logged, aggregated to one incident per IP per hour.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Guided onboarding\u003C\u002Fstrong> — a first-run wizard offers a one-click “safe baseline” that turns on the no-risk essentials, so a beginner is protected in seconds. The same “Apply safe baseline” button stays available any time.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Login Armor\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>No upsells, ever.\u003C\u002Fstrong> No “premium” tier, no greyed-out “Pro” buttons. Every feature is GPL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No external services to sign up for.\u003C\u002Fstrong> No API keys, no remote dashboards, no telemetry. The only outbound calls are opt-in: Have I Been Pwned (breach\u002Fpassword checks), Slack\u002FDiscord\u002Fwebhook (notifications), the keyless ipwho.is API (geolocation), and your own WordPress 7 AI connector.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built to be invisible.\u003C\u002Fstrong> Sub-megabyte ZIP, lazy-loaded modules, indexed queries — under 2 ms on a normal login flow.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multisite-aware, PHP 8.1-native, production-grade defaults.\u003C\u002Fstrong> Network-activate a fleet, configure per-site, manage from a complete WP-CLI suite; zero-config gets you 80 percent of the protection.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Twelve independent modules\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Hide Login\u003C\u002Fstrong> — Replace wp-login.php with a custom slug; the old URL returns a 404, and a branded pre-activation modal lets you pick or generate the slug and emails it to you so you can’t lock yourself out. Compatible with multisite, reverse proxies and password-recovery flows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute Force Protection\u003C\u002Fstrong> — Cascading lockouts escalating to a 24-hour ban, with subnet blocking and trusted X-Forwarded-For; lostpassword, register, XML-RPC and the REST users endpoint are all gated when an IP is locked, and every lockout surfaces as an incident.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hardening\u003C\u002Fstrong> — Fifteen one-click toggles across surface reduction, credential hardening, request filtering and account monitoring: disable XML-RPC\u002Fpingbacks, the file editor, version exposure, application passwords and author enumeration; block reserved usernames (Unicode-confusable detection); add a login honeypot; get alerted on new administrators.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Factor Authentication\u003C\u002Fstrong> — TOTP, one-time codes by email and printable backup codes, with trusted devices for thirty days, per-role enforcement, a configurable grace period and an email recovery flow when the authenticator is lost.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Detection and Incidents\u003C\u002Fstrong> — A real-time engine groups raw events into six attack patterns, each with a drill-down (timeline, source IPs, target users, severity, UA fingerprint) and one-click actions (reset password, block subnet, mark resolved).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity Log\u003C\u002Fstrong> — A compliance-ready, tamper-evident (hash-chained) audit trail of admin actions across seven logger domains, with filtering, CSV export, configurable retention and optional signed webhook forwarding to a SIEM.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Page Security Headers\u003C\u002Fstrong> — Content-Security-Policy, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options on wp-login.php and the lockout page, in two presets with an optional CSP report-uri; baseline headers can optionally extend site-wide.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Breach Check\u003C\u002Fstrong> — Detect logins using a breached password via privacy-preserving k-anonymity against Have I Been Pwned (only a 5-character SHA-1 prefix leaves the server); optional XposedOrNot email lookup, fail-soft so an outage never blocks login.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password Policy\u003C\u002Fstrong> — Enforce strong, unique passwords at registration, profile update and reset: minimum length and character classes, forbid the username inside the password, optionally reject breached passwords, with optional non-locking expiration nudges.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Management\u003C\u002Fstrong> — Idle-timeout logout measured on real page loads, a maximum session lifetime regardless of “remember me”, an optional single-active-device restriction, and a one-click “sign out all other devices”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Geolocation\u003C\u002Fstrong> — Show the attacker’s country on the Incidents and Events tabs; lazy, cached thirty days, capped per page load, private ranges never sent. Keyless ipwho.is by default, swappable for an offline database via a filter.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Request Firewall\u003C\u002Fstrong> — An optional, 8G-inspired PHP filter that blocks malicious query strings, paths, HTTP methods and (opt-in) user-agents\u002Freferrers before WordPress loads, on Apache\u002FNginx\u002FLiteSpeed alike; off by default, starts in monitor mode, never filters admins, skips REST\u002Fcron\u002FWP-CLI, with an IP\u002Fpath allowlist (CIDR). Not scored.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>AI Security Briefing (optional)\u003C\u002Fh4>\n\u003Cp>Built on the WordPress 7 native AI Client, one click turns your last thirty days of activity into a plain-language verdict, an IP picture and a short list of prioritised actions; “Explain with AI” does the same on a single incident. Minimised mode (anonymised signals) is the default and deep mode is an explicit opt-in. No API key is stored — it uses your own WordPress AI connector, so provider and cost stay yours. It always leads with a deterministic facts snapshot that works with or without AI.\u003C\u002Fp>\n\u003Ch4>Plus\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Guided onboarding\u003C\u002Fstrong> — a first-run wizard with a one-click safe baseline (Simple) or manual setup (Advanced); the “Apply safe baseline” button stays available, and upgrading sites never see the wizard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security score\u003C\u002Fstrong> — a weighted 0-100 read of your posture with a one-click “next best action”; observability features (geolocation, notifications, the AI assistant) are deliberately not scored.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conflict detection\u003C\u002Fstrong> — warns when another login-security plugin (Wordfence, Solid Security, Sucuri, All-In-One Security, SecuPress and more) or a cache plugin (with Hide Login on) could clash.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notifications\u003C\u002Fstrong> — email, Slack, Discord or webhook with SSRF-safe URL validation, severity threshold and rate limiting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-CLI suite\u003C\u002Fstrong> and a \u003Cstrong>dashboard widget\u003C\u002Fstrong> (14-day sparkline, six headline metrics).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Douze modules de sécurité. Une seule extension légère. Zéro compromis.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Login Armor est une stack complète de sécurité WordPress conçue pour les agences, les freelances et les pros qui livrent des sites prêts à passer un audit. Pas de version premium, pas de tableau de bord marketing intégré, pas de télémétrie. Chaque module tourne en local, embarque des réglages par défaut sécurisés, et reste discret.\u003C\u002Fp>\n\u003Cp>Fini de jongler entre la lourdeur de Wordfence, les fenêtres d’upsell de Solid Security et les angles morts de Limit Login Attempts — Login Armor regroupe douze modules indépendants en environ un méga-octet.\u003C\u002Fp>\n\u003Ch4>Nouveau en 2.4.0\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Pare-feu de requêtes\u003C\u002Fstrong> : un filtre PHP optionnel, inspiré du pare-feu 8G, qui bloque les requêtes malveillantes (injection SQL, exécution de code, traversée de répertoires, XSS, méthodes HTTP non autorisées) avant même que WordPress ait fini de charger, aussi bien sur Apache que Nginx ou LiteSpeed. Désactivé par défaut, il démarre en mode surveillance et ne filtre jamais les administrateurs connectés ; chaque blocage est journalisé, agrégé en un incident par IP et par heure.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Assistant de configuration\u003C\u002Fstrong> : à la première activation, un assistant propose une « base sûre » en un clic qui active les essentiels sans risque — un débutant est protégé en quelques secondes. Le même bouton « Appliquer la base sûre » reste disponible à tout moment.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pourquoi Login Armor\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Aucun upsell, jamais.\u003C\u002Fstrong> Pas de niveau « premium », pas de boutons « Pro » grisés. Tout est en GPL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Aucun service externe à activer.\u003C\u002Fstrong> Pas de clé API, pas de tableau distant, pas de télémétrie. Les seuls appels sortants sont opt-in : Have I Been Pwned (fuites\u002Fmots de passe), Slack\u002FDiscord\u002Fwebhook (notifications), l’API sans clé ipwho.is (géolocalisation) et votre propre connecteur IA WordPress 7.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conçu pour être invisible.\u003C\u002Fstrong> ZIP de moins d’un méga, modules chargés à la demande, requêtes indexées — sous 2 ms sur un flux de connexion normal.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compatible multisite, natif PHP 8.1, réglages prêts pour la production.\u003C\u002Fstrong> Activation réseau d’une flotte, configuration par site, pilotage via une suite WP-CLI complète ; sans configuration, vous avez déjà 80 % de la protection.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Douze modules indépendants\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Masquer la connexion\u003C\u002Fstrong> : remplace wp-login.php par une URL personnalisée (l’ancienne renvoie une 404) ; une modale de pré-activation choisit ou génère le slug et vous l’envoie par e-mail pour éviter tout verrouillage. Compatible multisite, reverse proxies et récupération de mot de passe.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Protection contre la force brute\u003C\u002Fstrong> : verrouillages en cascade montant à un bannissement de 24 h, blocage de sous-réseaux et support X-Forwarded-For ; lostpassword, register, XML-RPC et l’endpoint REST users sont bloqués pour une IP verrouillée, et chaque verrouillage devient un incident.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Renforcement\u003C\u002Fstrong> : quinze bascules en un clic (réduction de surface, identifiants, filtrage des requêtes, surveillance des comptes) — désactiver XML-RPC\u002Fpingbacks, l’éditeur de fichiers, l’exposition de version, les mots de passe applicatifs et l’énumération d’auteurs ; bloquer les identifiants réservés (homoglyphes Unicode) ; ajouter un pot de miel ; être alerté à la création d’un administrateur.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Authentification à deux facteurs\u003C\u002Fstrong> : TOTP, codes à usage unique par e-mail et codes de secours imprimables, avec appareils de confiance 30 jours, application par rôle, période de grâce configurable et récupération par e-mail en cas de perte.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Détection et incidents\u003C\u002Fstrong> : un moteur en temps réel regroupe les événements en six patterns d’attaque, chacun avec une vue détaillée (chronologie, IP sources, comptes cibles, sévérité, empreinte UA) et des actions en un clic.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Journal d’activité\u003C\u002Fstrong> : piste d’audit conforme et inviolable (chaîne de hachage) des actions admin sur sept domaines, avec filtrage, export CSV, rétention configurable et transfert webhook signé optionnel vers un SIEM.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>En-têtes de sécurité\u003C\u002Fstrong> : CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy et X-Content-Type-Options sur wp-login.php et la page de verrouillage, en deux préréglages avec CSP report-uri optionnel ; les en-têtes de base peuvent s’étendre à tout le site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Détection de fuites\u003C\u002Fstrong> : repère les connexions avec un mot de passe fuité via k-anonymat sur Have I Been Pwned (seul un préfixe SHA-1 de 5 caractères sort) ; vérification e-mail XposedOrNot optionnelle, fail-soft.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Politique de mot de passe\u003C\u002Fstrong> : impose des mots de passe forts à l’inscription, au profil et à la réinitialisation (longueur, classes de caractères, interdiction de l’identifiant, rejet optionnel des mots de passe fuités), avec expiration optionnelle qui ne verrouille jamais personne dehors.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gestion des sessions\u003C\u002Fstrong> : déconnexion sur inactivité mesurée sur les vrais chargements, durée de vie maximale indépendante de « se souvenir de moi », limitation optionnelle à un seul appareil actif, et « déconnecter tous les autres appareils » en un clic.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Géolocalisation IP\u003C\u002Fstrong> : affiche le pays des IP attaquantes dans Incidents et Événements ; recherches paresseuses, cache 30 jours, plafonnées par page, plages privées jamais envoyées. ipwho.is sans clé par défaut, base hors ligne possible via un filtre.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pare-feu de requêtes\u003C\u002Fstrong> : filtre PHP optionnel inspiré du 8G qui bloque chaînes de requête, chemins, méthodes HTTP et (en option) user-agents\u002Freferrers malveillants avant le chargement de WordPress, sur Apache\u002FNginx\u002FLiteSpeed ; désactivé par défaut, démarre en mode surveillance, ne filtre jamais les admins, ignore REST\u002Fcron\u002FWP-CLI, allowlist IP\u002Fchemins (CIDR). Non noté.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Briefing de sécurité IA (optionnel)\u003C\u002Fh4>\n\u003Cp>Bâti sur le client IA natif de WordPress 7, un clic transforme vos trente derniers jours d’activité en un verdict en langage clair, un panorama des IP et une courte liste d’actions prioritaires ; « Expliquer avec l’IA » fait de même sur un incident. Le mode minimisé (signaux anonymisés) est par défaut, le mode approfondi est un opt-in explicite. Aucune clé API stockée : il utilise votre propre connecteur IA WordPress, le coût et le fournisseur restent les vôtres. Il s’ouvre toujours sur un instantané de faits déterministes, utile avec ou sans IA.\u003C\u002Fp>\n\u003Ch4>En plus\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Assistant de configuration\u003C\u002Fstrong> : un assistant à la première activation propose une base sûre en un clic (Simple) ou une voie manuelle (Avancée) ; le bouton « Appliquer la base sûre » reste disponible, et les sites en mise à jour ne le voient jamais.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Score de sécurité\u003C\u002Fstrong> : lecture pondérée 0-100 de votre posture avec une action prioritaire en un clic ; les fonctions d’observabilité (géolocalisation, notifications, assistant IA) ne sont pas notées.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Détection de conflits\u003C\u002Fstrong> : alerte quand une autre extension de sécurité axée connexion (Wordfence, Solid Security, Sucuri, All-In-One Security, SecuPress et d’autres) ou un plugin de cache (avec Hide Login actif) peut entrer en conflit.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notifications\u003C\u002Fstrong> : e-mail, Slack, Discord ou webhook, avec validation d’URL anti-SSRF, seuil de sévérité et rate limiting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Suite WP-CLI\u003C\u002Fstrong> et \u003Cstrong>widget Tableau de bord\u003C\u002Fstrong> (sparkline 14 jours, six métriques clés).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Conçu par\u003C\u002Fh4>\n\u003Cp>Login Armor est conçu et maintenu par Fabrice Ducarme de \u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Flogin-armor\u002F\" rel=\"nofollow ugc\">WPFormation\u003C\u002Fa>, expert WordPress français obsédé par les sites propres, rapides et prêts pour l’audit. On l’utilise sur chaque site qu’on livre.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Flogin-armor\u002F\" rel=\"nofollow ugc\">Présentation et fonctionnement de Login Armor\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Fsecurite-wordpress\u002F\" rel=\"nofollow ugc\">Guides de sécurité WordPress\u003C\u002Fa> sur WPFormation\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Foutils\u002Fveille-securite\u002F\" rel=\"nofollow ugc\">Veille des vulnérabilités WordPress\u003C\u002Fa> : l’outil de veille sécurité de WPFormation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>GPL pour toujours. PHP 8.1+. WordPress 6.8+. Zéro dépendance.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Ch4>AI Security Briefing (optional)\u003C\u002Fh4>\n\u003Cp>The AI Security Briefing and the “Explain with AI” incident analysis are powered by the \u003Cstrong>WordPress 7 native AI Client\u003C\u002Fstrong> (\u003Ccode>wp_ai_client_prompt()\u003C\u002Fcode>). When the administrator clicks the analysis button, LoginArmor asks WordPress to send a prompt to the \u003Cstrong>AI connector that the administrator configured in their own WordPress\u003C\u002Fstrong> (for example OpenAI, Anthropic or Google, depending on the connector). LoginArmor itself stores no API key and contacts no endpoint directly: the request, the provider and the cost are owned by the site’s own AI connector.\u003C\u002Fp>\n\u003Cp>Data sent: a text prompt describing the security situation. In \u003Cstrong>minimised mode (the default)\u003C\u002Fstrong>, only anonymised, non-identifying signals are included (counts, categories, severities, role buckets) – no IP address and no username in clear. In \u003Cstrong>deep mode\u003C\u002Fstrong> (an explicit, off-by-default opt-in), the prompt additionally includes real IP addresses and event details so the analysis can name specific sources. No data is ever sent unless the administrator clicks the analysis button.\u003C\u002Fp>\n\u003Cp>This feature is inactive unless WordPress 7 (or the AI Building Blocks feature plugin) is present with a configured, approved AI connector. The applicable terms and privacy policy are those of the AI provider the administrator chose for their connector; please refer to that provider’s documentation.\u003C\u002Fp>\n\u003Ch4>Webhook Notifications (optional)\u003C\u002Fh4>\n\u003Cp>When explicitly enabled and configured by the administrator in LoginArmor > Settings > Notifications, the plugin sends incident data to third-party services via webhooks.\u003C\u002Fp>\n\u003Cp>Data sent: incident type, severity level, IP address, target username, event count, and site URL.\u003C\u002Fp>\n\u003Cp>No data is sent unless the administrator actively enables and configures a notification channel.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Slack\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fslack.com\u002Fterms-of-service\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fslack.com\u002Fprivacy-policy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Discord\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fdiscord.com\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fdiscord.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Webhook URL\u003C\u002Fstrong> – User-configured endpoint (administrator’s responsibility)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Gravatar (Automattic)\u003C\u002Fh4>\n\u003Cp>The Activity Log tab uses WordPress core’s \u003Ccode>get_avatar()\u003C\u002Fcode> function to display user avatars. WordPress may send a hashed email address to \u003Ca href=\"https:\u002F\u002Fgravatar.com\u002F\" rel=\"nofollow ugc\">Gravatar\u003C\u002Fa> servers to retrieve avatar images. This is controlled by Settings > Discussion > Avatars.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Gravatar\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fautomattic.com\u002Ftos\u002F\" rel=\"nofollow ugc\">Automattic Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fautomattic.com\u002Fprivacy\u002F\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Breach Check – Have I Been Pwned (optional)\u003C\u002Fh4>\n\u003Cp>When the administrator explicitly enables the \u003Cstrong>Breach Check\u003C\u002Fstrong> module (LoginArmor > Settings > Breach  &hellip;\u003C\u002Fp>\n","Twelve security modules + AI briefing: hide login, request firewall, brute force, 2FA, password policy, sessions, hardening, audit log. No upsells.",200,2619,3,"2026-07-22T03:46:00.000Z","6.8","8.1",[133,18,134,135,21],"activity-log","hide-login","limit-login","https:\u002F\u002Fwpformation.com\u002Flogin-armor","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flogin-armor.2.4.5.zip",{"error":139,"url":140,"statusCode":141,"statusMessage":142,"message":142},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fnaveencodes-login-guard\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":90,"versions":144},[145],{"version":6,"download_url":24,"svn_tag_url":146,"released_at":26,"has_diff":147,"diff_files_changed":148,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":149,"is_current":139},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fnaveencodes-login-guard\u002Ftags\u002F1.0.0\u002F",false,[],[]]