Loginizer
Loginizer is a WordPress plugin which helps you fight against bruteforce attack by blocking login for the IP after it reaches maximum retries allowed. You can blacklist or whitelist IPs for login using Loginizer. You can use various other features like Two Factor Auth, reCAPTCHA, PasswordLess Login, etc. to improve security of your website. Loginizer is actively used by more than 1000000+ WordPress websites. You can find our official documentation at https://loginizer.com/docs. We are also active in our community support forums on wordpress.org if you are one of our free users. Our Premium Support Ticket System is at https://loginizer.deskuss.com Free Features : Brute force protection. IPs trying to brute force your website will be blocked for 15 minutes after 3 failed login attempts. After multiple lockouts the IP is blocked for 24 hours. This is the default configuration and can be changed from Loginizer -> Brute force page in WordPress admin panel. Failed login attempts logs. Blacklist IPs Whitelist IPs Custom error messages on failed login. Permission check for important files and folders. Allow only Trusted IP. Blocked Screen in place of the Login page. Email Notification on successful login. Let users login with LinkedIn Get Support and Pro Features Get professional support from our experts and pro features to take your site’s security to the next level with Loginizer-Security. Pro Features : MD5 Checksum – of Core WordPress Files. The admin can check and ignore files as well. PasswordLess Login – At the time of Login, the username / email address will be asked and an email will be sent to the email address of that account with a temporary link to login. Two Factor Auth via Email – On login, an email will be sent to the email address of that account with a temporary 6 digit code to complete the login. Two Factor Auth via App – The user can configure the account with a 2FA App like Google Authenticator, Authy, etc. Login Challenge Question – The user can setup a Challenge Question and Answer as an additional security layer. After Login, the user will need to answer the question to complete the login. reCAPTCHA – Google’s reCAPTCHA v3/v2, Cloudflare Turnstile, hCAPTCHA can be configured for the Login screen, Comments Section, Registration Form, etc. to prevent automated brute force attacks. Supports WooCommerce as well. Rename Login Page – The Admin can rename the login URL (slug) to something different from wp-login.php to prevent automated brute force attacks. Rename WP-Admin URL – The Admin area in WordPress is accessed via wp-admin. With loginizer you can change it to anything e.g. site-admin CSRF Protection – This helps in preventing CSRF attacks as it updates the admin URL with a session string which makes it difficult and nearly impossible for the attacker to predict the URL. Rename Login with Secrecy – If set, then all Login URL’s will still point to wp-login.php and users will have to access the New Login Slug by typing it in the browser. Disable XML-RPC – An option to simply disable XML-RPC in WordPress. Most of the WordPress users don’t need XML-RPC and can disable it to prevent automated brute force attacks. Rename XML-RPC – The Admin can rename the XML-RPC to something different from xmlrpc.php to prevent automated brute force attacks. Username Auto Blacklist – Attackers generally use common usernames like admin, administrator, or variations of your domain name / business name. You can specify such username here and Loginizer will auto-blacklist the IP Address(s) of clients who try to use such username(s). New Registration Domain Blacklist – If you would like to ban new registrations from a particular domain, you can use this utility to do so. Change the Admin Username – The Admin can rename the admin username to something more difficult. Auto Blacklist IPs – IPs will be auto blacklisted, if certain usernames saved by the Admin are used to login by malicious bots / users. Disable Pingbacks – Simple way to disable PingBacks. SSO – Single Sign-on, let any user access to your WordPress Dashboard without the need to share username or password. Limit Concurrent Logins – It prevents user to login from different devices concurrently, you can define how many devices you want to allow, and how you want to restrict the user when concurrent limit is reached. Social Login – Users can login or register with their Google, Github, Facebook, X (Twitter), Discord, Twitch, LinkedIn, Microsoft with support for WooCommerce and Ultimate Member. Key Less Social Login – Use Loginizer’s Social Auth for easy key less Social login configuration, now supports Google, GitHub, X, LinkedIn more to be added later Country Blocking – Block IPs from specific countries to restrict access to your website. User enumeration – Helps prevent attackers from knowing usernames, by blocking unauthenticated access to common username list/access paths. Features in Loginizer include: Blocks IP after maximum retries allowed Extended Lockout after maximum lockouts allowed Email notification to admin after max lockouts Blacklist IP/IP range Whitelist IP/IP range Check logs of failed attempts Create IP ranges Delete IP ranges Licensed under LGPLv2.1 Safe & Secure
Top keywords
- login29×3.44%
- admin12×1.42%
- ip11×1.30%
- loginizer10×1.18%
- wordpress9×1.07%
- email8×0.95%
- username8×0.95%
- brute7×0.83%
- brute force7×0.83%
- force7×0.83%
- ips7×0.83%
- rename7×0.83%
Members – Membership & User Role Editor Plugin
Members is a roles and capabilities based WordPress membership plugin. It gives your users the ultimate member experience by giving you powerful tools to add roles and capabilities and assign them to your users. Members allows you to set permissions to restrict content on your site by providing a simple user interface (UI) for WordPress’ powerful roles and capabilities system, which has traditionally only been available to developers who know how to code this by hand. Plugin Features Role Editor: Allows you to edit, create, and delete roles as well as capabilities for these roles. Multiple User Roles: Give one, two, or even more roles to any user. Explicitly Deny Capabilities: Deny specific capabilities to specific user roles. Clone Roles: Build a new role by cloning an existing role. Role Import / Export: Export all roles and Members settings to a JSON file, export selected roles from the roles table, and preview imported roles before choosing whether to import, skip, overwrite, or rename each one. Content Permissions / Restricted Content: Protect content to determine which users (by role) have access to post content. Shortcodes: Shortcodes to control who has access to content. Widgets: A login form widget and users widget to show in your theme’s sidebars. Private Site: You can make your site and its feed completely private if you want. Administrator Rescue (Magic Link): If you lose access to the WordPress admin (e.g. after editing roles), you can request a secure, time-limited link by email to restore your Administrator role and Members capabilities—no support ticket or database access required. Plugin Integration: Members is highly recommended by other WordPress developers. Many existing plugins integrate their custom roles and capabilities directly into it. Seamless MemberPress Integration If you’re looking to build a business out of your membership site by creating paid memberships there’s no better way than to use MemberPress. Members and MemberPress work together to provide the ultimate member experience and will help you start and profit from your amazing WordPress membership sites! All Add-ons are now included Members now includes ALL of it’s add-ons completely free of charge! Here are some of the awesome features they add to Members: Block Permissions: Allows site owners to hide or show blocks based on user logged-in status, user role, or capability. Privacy Caps: Creates additional capabilities for control over WordPress’ privacy and personal data features (GDPR). Admin Access: Allows site administrators to control which users have access to the WordPress admin via role. Core Create Caps: Adds the create_posts and create_pages caps to posts/pages to separate them from their edit_* counterparts, providing more flexible editing capabilities. Categories and Tag Caps: The Category and Tag Caps add-on creates custom capabilities for the core category and post tag taxonomies. This allows site owners to have precise control over who can manage, edit, delete, or assign categories/tags. Role Levels: Exposes the old user levels system, which fixes the WordPress author drop-down bug when users don’t have a role with one of the assigned levels. Role Hierarchy: Creates a hierarchical roles system. ACF Integration: Creates custom capabilities for the Advanced Custom Fields (ACF) plugin for managing with the Members plugin. EDD Integration: Integrates the Easy Digital Downloads plugin capabilities into the Members plugin’s role manager. GiveWP Integration: Integrates the GiveWP and GiveWP Recurring Donations plugin capabilities into the Members plugin’s role manager. Meta Box Integration: Integrates the Meta Box plugin capabilities into the Members plugin’s role manager. WooCommerce Integration: Integrates the WooCommerce plugin capabilities into the Members plugin’s role manager. For more info, visit the Members plugin home page. Like this plugin? The Members plugin is a massive project with 1,000s of lines of code to maintain. A major update can take weeks or months of work. We don’t make any money directly from this plugin while other, similar plugins charge substantial fees to even download them or get updates. Please consider helping the cause by: Adding MemberPress. Rating the plugin. Documentation Read the full documentation Support If you need plugin support from us, you can visit our support page. Plugin Development If you’re a theme author, plugin author, or just a code hobbyist, you can follow the development of this plugin on it’s GitHub repository.