Login Armor
🇫🇷 Fully translated into French. Interface et documentation intégralement disponibles en français. Thirteen security modules. One lightweight plugin. No premium tier. Login Armor protects WordPress login, accounts and administration with thirteen independent modules. It is built for agencies, freelancers and site owners who want practical security, clear evidence and safe defaults without a remote dashboard, bundled telemetry or upsells. Why Login Armor Complete and free: every module is included under the GPL. Lightweight: modules load only when needed and normal login checks add less than 2 ms on a typical setup. Private by default: data stays on your site. Optional external calls are disabled until you enable the related feature. Ready for real sites: multisite support, reverse-proxy controls, WP-CLI commands and production-safe defaults. Thirteen security modules Hide Login: replace wp-login.php with a private slug and return a 404 or redirect blocked visitors to a chosen URL. Brute Force Protection: escalating lockouts, subnet blocking, trusted proxy headers and coverage for login, password recovery, registration, XML-RPC and REST users. Hardening: fifteen controls for XML-RPC, pingbacks, file editing, version exposure, application passwords, author enumeration, reserved usernames, honeypots and new-admin alerts. Two-Factor Authentication: TOTP, email codes, backup codes, trusted devices, per-role enforcement, grace periods and recovery. Detection and Incidents: group raw events into attack patterns with severity, timelines, source IPs, targeted users and one-click actions. Activity Log: tamper-evident admin audit trail with filters, CSV export, retention controls and optional signed SIEM forwarding. Security Headers: CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options for login and lockout pages, with optional site-wide baseline headers. Breach Check: privacy-preserving Have I Been Pwned password checks and an optional XposedOrNot email check. Password Policy: length and character rules, username exclusion, breached-password rejection and optional non-locking expiration reminders. Session Management: idle timeout, maximum lifetime, optional single-device access and one-click revocation of other sessions. IP Geolocation: cached country lookup for IPs shown in Incidents and Events, with private ranges excluded. Request Firewall: optional, monitor-first filtering of malicious paths, query strings and HTTP methods, with administrator exclusions and IP/path allowlists. Bot Challenge: an invisible proof-of-work the browser solves before the login form is accepted, an alternative to CAPTCHAs with no external service; monitor-first, then enforce. Additional tools Login Armor also includes guided onboarding, a 0-100 security score, conflict detection, email/Slack/Discord/webhook notifications, a dashboard widget and a complete WP-CLI suite. The optional AI Security Briefing uses your own WordPress AI connector to explain a thirty-day security snapshot or a single incident. It always starts with deterministic facts, works without AI and sends nothing until an administrator explicitly requests an analysis. GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies. Treize modules de sécurité. Une seule extension légère. Aucune version premium. Login Armor protège la connexion, les comptes et l’administration de WordPress grâce à treize modules indépendants. L’extension s’adresse aux agences, freelances et propriétaires de sites qui veulent une sécurité concrète, des preuves lisibles et des réglages sûrs, sans tableau de bord distant, télémétrie imposée ni upsell. Pourquoi Login Armor Complet et gratuit : tous les modules sont inclus sous licence GPL. Léger : les modules se chargent uniquement lorsque nécessaire et les contrôles ajoutent moins de 2 ms sur une connexion normale. Privé par défaut : les données restent sur votre site. Les appels externes optionnels sont désactivés tant que vous n’activez pas la fonction concernée. Prêt pour la production : multisite, reverse proxies, commandes WP-CLI et réglages par défaut sécurisés. Treize modules de sécurité Masquer la connexion : remplace wp-login.php par un slug privé et renvoie une 404 ou redirige les visiteurs bloqués vers l’URL choisie. Protection contre la force brute : verrouillages progressifs, blocage de sous-réseaux, proxies de confiance et protection de la connexion, récupération, inscription, XML-RPC et REST users. Renforcement : quinze contrôles pour XML-RPC, les pingbacks, l’éditeur de fichiers, la version, les mots de passe applicatifs, l’énumération d’auteurs, les identifiants réservés, le pot de miel et les alertes nouvel administrateur. Authentification à deux facteurs : TOTP, codes par e-mail, codes de secours, appareils de confiance, application par rôle, période de grâce et récupération. Détection et incidents : regroupe les événements en scénarios d’attaque avec sévérité, chronologie, IP sources, comptes ciblés et actions immédiates. Journal d’activité : piste d’audit admin infalsifiable avec filtres, export CSV, rétention et transfert SIEM signé optionnel. En-têtes de sécurité : CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy et X-Content-Type-Options pour les pages de connexion et de verrouillage, avec en-têtes de base optionnels sur tout le site. Détection de fuites : vérification confidentielle des mots de passe via Have I Been Pwned et contrôle optionnel des e-mails via XposedOrNot. Politique de mot de passe : longueur, classes de caractères, exclusion de l’identifiant, rejet des mots de passe compromis et rappels d’expiration non bloquants. Gestion des sessions : délai d’inactivité, durée maximale, accès limité à un appareil et révocation des autres sessions. Géolocalisation IP : pays des IP affichées dans Incidents et Événements, avec cache et exclusion des plages privées. Pare-feu de requêtes : filtrage optionnel, d’abord en surveillance, des chemins, requêtes et méthodes HTTP malveillants, avec exclusion des administrateurs et listes d’autorisation IP/chemins. Défi anti-bot : une preuve de calcul invisible résolue par le navigateur avant validation du formulaire de connexion, alternative aux CAPTCHA sans service externe ; d’abord en surveillance, puis en blocage. Outils complémentaires Login Armor inclut aussi un assistant de configuration, un score de sécurité de 0 à 100, la détection de conflits, les notifications par e-mail, Slack, Discord ou webhook, un widget de tableau de bord et une suite WP-CLI complète. Le briefing de sécurité IA optionnel utilise votre propre connecteur IA WordPress pour expliquer les trente derniers jours ou un incident précis. Il commence toujours par des faits déterministes, fonctionne sans IA et n’envoie rien tant qu’un administrateur ne demande pas explicitement une analyse. Conçu par Login Armor est conçu et maintenu par Fabrice Ducarme de WPFormation. Nous l’utilisons sur chaque site que nous livrons. Présentation et fonctionnement de Login Armor Guides de sécurité WordPress sur WPFormation Veille des vulnérabilités WordPress sur WPFormation GPL pour toujours. PHP 8.1+. WordPress 6.8+. Zéro dépendance. External Services Login Armor has no telemetry and requires no Login Armor account. The following services are contacted only when WordPress itself or an administrator enables the related feature. WordPress AI connector (optional) The AI Security Briefing sends a security prompt through the administrator’s own WordPress AI connector only after they click an analysis button. Minimised mode sends counts, categories, severities and role buckets without clear IP addresses or usernames. Explicit deep mode also sends IP addresses and event details. Login Armor stores no provider API key. The selected AI provider’s terms and privacy policy apply. Slack, Discord or custom webhook (optional) When an administrator enables an incident notification channel, Login Armor sends the incident type, severity, IP address, target username, event count and site URL to the configured endpoint. The separate signed Activity Log forwarding option sends the event, object, user ID/login/role, IP address, description, integrity hashes, site URL and plugin version to the administrator’s SIEM or custom webhook. Slack: Terms | Privacy Discord: Terms | Privacy Custom webhook: terms and privacy are controlled by the administrator’s chosen endpoint. Gravatar The Activity Log uses WordPress core’s get_avatar(). If avatars are enabled in WordPress, a hashed email address may be sent to Gravatar to retrieve the image. Gravatar: Terms | Privacy Have I Been Pwned (optional) Breach Check and the optional compromised-password policy send only the first 5 characters of a password’s SHA-1 hash to the Pwned Passwords API. The password and full hash never leave the site. Checks fail soft if the service is unavailable. Public registration and password-reset validation do not call the service; authenticated checks remain active. Have I Been Pwned: Privacy | Acceptable Use XposedOrNot (optional) The separate Email check, disabled by default, sends the user’s email address and a plugin-identifying User-Agent to XposedOrNot when a user is created or changes email. XposedOrNot: Service | Privacy ipwho.is (optional) IP Geolocation sends a displayed public IP address to ipwho.is when an administrator opens Incidents or Events. Results are cached for 30 days. Private and reserved ranges are never sent, and developers can replace the lookup through the login_armor_geoip_lookup filter. ipwho.is: Service | Documentation
Top keywords
- de39×2.66%
- et28×1.91%
- login20×1.36%
- les17×1.16%
- optional14×0.95%
- armor13×0.89%
- des13×0.89%
- login armor13×0.89%
- wordpress13×0.89%
- ip12×0.82%
- par10×0.68%
- modules9×0.61%
Activity Guard – Security Scanner, Activity Log with IP blocking
Activity Guard is a free WordPress plugin that covers four things most plugins charge separately for: a complete activity log, an IP-based security firewall, a plugin vulnerability scanner, and WooCommerce abandoned cart analytics. Alerts go out in real time to Slack, Telegram, or email, all from one dashboard. Most activity log plugins stop at logging. Most security plugins don’t touch WooCommerce. Plugins like WP Activity Log, Simple History, and Stream do logging well — Activity Guard adds real-time Slack and Telegram alerts, an IP firewall with emergency shutdown, CVE vulnerability scanning, and WooCommerce abandoned cart recovery analytics, all at no cost. No paid tier required for any of it. No other free plugin on WordPress.org combines these four in one place: a complete audit log, an IP security firewall, a multi-database vulnerability scanner, and WooCommerce analytics with cart recovery tracking. Activity Guard Website | Documentation | Pro Support WordPress Activity Log Activity Guard records every meaningful change on your site, including the IP address, username, timestamp, and the exact change made. The audit log covers: User logins, logouts, and failed login attempts User registrations, role changes, and profile edits Pages, posts, and custom post types: create, edit, delete, status changes Plugin and theme activations, deactivations, updates, and deletions WordPress core settings and configuration changes Menu, widget, and sidebar modifications Email delivery tracking via a full email log Form submissions from Contact Form 7, SimpleForm, and others Admin settings changes and debug log events Cron job scheduling and background process tracking Script modification and file change detection Visitor traffic monitoring with an on/off toggle Visual charts summarize your audit log at a glance. No need to scroll through raw log tables to understand what’s happening on your site. Security Firewall and IP Blocking Activity Guard actively blocks threats rather than just recording them. IP blocking by manual entry, CIDR range, or conditional rule Emergency Shutdown: force-logout every active session on your site with one click Cloudflare Turnstile login protection against bots and brute force attacks Login rate limiting to stop credential-stuffing Bot detection and automatic IP blocking Restrict or fully disable XML-RPC access Core file integrity scanner to detect unauthorized file changes File integrity monitoring across plugins and themes Block TOR network access Block vulnerability scanner user agents HTTP security headers: custom, logged, and enforced WordPress version hiding 404 error tracking and suspicious HTTP request alerts Admin dashboard visitor tracking Cron job failure and site downtime monitoring The Emergency Shutdown feature is specific to Activity Guard: one click and every logged-in session on your site ends immediately — useful when you detect a breach in progress and need everyone out now. Plugin Vulnerability Scanner Activity Guard scans every installed plugin and theme against multiple vulnerability databases before problems develop: Detect plugins with known CVEs across NVD, WPVulnerability.net, and the WPAzleen private API Flag outdated plugins not compatible with your WordPress version Identify abandoned plugins not updated in over a year Warn about plugins with low install counts or poor ratings No other free activity log plugin on WordPress.org includes a built-in multi-database vulnerability scanner. WooCommerce Activity Log and Analytics Activity Guard logs every WooCommerce event and adds analytics built specifically for store owners. Order tracking covers status changes, payments, refunds, and cancellations. You also get stock level changes and low-stock events, coupon creation and usage, product pricing edits, billing and shipping address updates, customer registration changes, and real-time shipping status updates. The abandoned cart and incomplete-order analytics go further than basic logging. The dashboard shows checkout drop-off rates, recovery potential, recovery rate, and how customers interact with their carts before leaving. This tells you where revenue is being lost, not just that it was lost. WooCommerce abandoned cart analytics with recovery rate tracking is included free. No competing free activity log plugin on WordPress.org provides this. Slack and Telegram Notifications Activity Guard sends alerts the moment a critical event occurs, across four channels: Slack: route alerts to any channel, tag specific users or groups with @mentions Telegram: real-time activity and security alerts direct to your Telegram chat Email: configurable per event type Admin dashboard: in-panel notification view Events that trigger alerts include core file changes, plugin and theme updates (with the username that triggered the update), WooCommerce orders, payments, coupon usage, incomplete order follow-ups, product edits, stock changes, login and registration events, page and post changes, form submissions, and admin settings changes. A daily digest and weekly plugin download summary are also available. You can schedule notifications for specific times and control exactly which events send alerts. Admin and Developer Tools Maintenance mode toggle from the dashboard Menu and widget change tracking Plugin and theme activation and deactivation logs Script modification detection HTTP security header change logging Debug log and fatal error detection Email log: full delivery history for all outgoing WordPress emails Contact Form 7 and SimpleForm integration alerts Who Uses Activity Guard WooCommerce store owners use it to track every order, coupon, product change, and shipping event, and to recover revenue with abandoned cart analytics. Site administrators use it to know exactly who changed what, instantly log out suspicious users, and maintain a clean audit trail. Agencies and developers use it to monitor plugin updates, configuration changes, fatal errors, and debug logs across client sites. Security-focused admins use it to block IPs, scan for CVEs, monitor file integrity, and trigger emergency shutdowns. Multi-author sites use it to hold contributors accountable with full user activity logging and role-change tracking. Join us: Facebook | YouTube | X / Twitter Competitor Analysis Search the WordPress plugin directory for an activity log plugin and a handful of names come up again and again, so it is worth being clear about where Activity Guard actually fits among them. WP Activity Log is the biggest name in the category, with the broadest event coverage of any activity log plugin and support for tracking third-party plugins like ACF, Gravity Forms, and LearnDash. It is a genuine alternative to Activity Guard for pure logging depth, but Slack and SMS alerts sit behind WP Activity Log Premium, and there is no IP firewall, no vulnerability scanner, and no WooCommerce analytics at any tier. Activity Guard includes Slack and Telegram alerts, an IP firewall, vulnerability scanning, and WooCommerce abandoned cart analytics in the free version, with a narrower focus on the WordPress admin rather than enterprise SIEM exports. Activity Log Pro is the closest match on structure. Its free tier also adds real security-adjacent value beyond plain logging, with Login Flood Guard and severity-tagged events, so anyone comparing the two is comparing like for like on ambition. Where Activity Guard pulls ahead is in what ships free versus what is gated: Activity Log Pro’s Slack and webhook routing live behind its Premium “Log Channels” feature, while Activity Guard’s Slack and Telegram alerts, IP blocking, vulnerability scanning, and WooCommerce cart recovery analytics are all included at no cost. Beyond those two, most of the other names that show up nearby are lighter tools solving a narrower slice of the same problem, or a different problem entirely. Activity Log – Monitor & Record User Changes (Aryo) is a lightweight, beginner-friendly logger with email-only notifications and no Slack, Telegram, IP firewall, or vulnerability scanning. Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity is built for agencies managing many client sites and does send Slack alerts, but it works by connecting each site to Logtivity’s hosted service with an API key rather than running standalone, and it has no IP firewall, no vulnerability scanner, and no WooCommerce analytics. Security Plugin, Firewall & Malware Scanner with Auto Removal is a genuinely strong free WAF and malware scanner, but it is not an activity log at all: it does not track content edits, role changes, or WooCommerce events, and its alerts are email-only through the CleanTalk cloud account it requires. Error Log Viewer by BestWebSoft has nothing to do with user activity either, it is a PHP and WordPress error log reader with email notifications, useful for debugging but unrelated to security monitoring or audit trails. So of the plugins that show up in a “wordpress activity log” or “wp activity log alternative” search, only WP Activity Log, Activity Log Pro, Aryo Activity Log, and Logtivity are actually built for the same job as Activity Guard: tracking what changed on a WordPress site and who changed it. Among those four, Activity Guard’s combination of free Slack and Telegram alerts, an IP firewall with emergency shutdown, a CVE vulnerability scanner, and WooCommerce abandoned cart analytics, all in the free version with no external account required, is what sets it apart. External Services Slack Webhook Integration Activity Guard sends notifications to your Slack workspace using a Slack incoming webhook URL that you provide. To set one up: Create a Slack app or use an existing one Enable Incoming Webhooks in the app settings Add a webhook to your workspace Paste the webhook URL into Activity Guard settings No data is stored by Slack beyond what you configure in your own Slack workspace. See Slack’s privacy policy for details. Cloudflare Turnstile Activity Guard uses Cloudflare Turnstile for login bot protection. When Turnstile is enabled, your login page communicates with Cloudflare’s verification servers. See Cloudflare’s privacy policy for details. Plugin Vulnerability Scanner – Data Sources WordPress.org Plugin API: retrieves plugin metadata including latest version, last updated date, rating, and active install count. Privacy Policy WPAzleen API: private endpoint for known vulnerabilities by plugin and version. No sensitive data is transmitted. Privacy Policy WPVulnerability.net: public API for CVE-based vulnerability data. Privacy Policy National Vulnerability Database (NVD): official CVE data from NIST. Privacy Policy All scans run locally using public metadata and vulnerability feeds. Activity Guard does not collect, store, or transmit any personal information during scans. Freemius Activity Guard uses the Freemius SDK for optional telemetry. No data is collected by default. Data collection only starts after you explicitly confirm in the admin notice. See the Freemius privacy policy for details. WPAzleen Settings API Loads display settings for the Pro upgrade modal in the plugin admin area. No personal data is transmitted. WPAzleen Privacy Policy Source Code The source files for all compiled/minified JavaScript and CSS in this plugin are publicly available at: https://github.com/wpazleen/activity-guard Build instructions: Clone the repository or visit the src directory directly. Run npm install in the root to install dependencies. Run npm run build to compile JavaScript and CSS assets. Compiled files output to build/. Contributions, bug reports, and pull requests are welcome.