Melapress Login Security
COMPREHENSIVE WORDPRESS LOGIN SECURITY PLUGIN Melapress Login Security enables you to effortlessly set login security policies that put you firmly in the driver’s seat of your WordPress sites. Policies are highly customizable and granular and can be implemented by user role or site-wide for complete control over the security of your WordPress login processes. Use the free edition of Melapress Login Security to implement WordPress password requirements such as minimum length and complexity rules. The plugin also allows you to set password expiration policies, prevent password reuse, limit failed login attempts, and automatically disable inactive user accounts, among other things. This helps you: Prevent unauthorized login attempts Protect against brute force attacks Comply with GDPR with a login consent notice 🔐 Features list A secure WordPress login starts right here. Explore all of the features included with the free edition of Melapress Login Security: Set password policies Strong passwords are your first line of defense against bad actors looking to gain access to your site. Set password requirement policies to make sure users set strong passwords. Set policies by user role or site-wide and define policy priority for users with multiple roles. Set minimum password length Require uppercase and lowercase characters, numbers, and special characters Set an automatic password expiration policy and advise users when their password is about to expire Disallow users from reusing passwords Provide users with helpful instructions during the password configuration stage Disable password reset links Mandate WordPress password reset on the first login Limit login attempts Limit failed login attempts and put an end to brute force attacks. Protect your login form by automatically disabling user accounts after a number of failed login attempts. Choose between manual unlocking by an admin or automatic unlocking after a cooldown period. Temporary login without password Provide temporary and secure login access to third parties, like developers, editors, employees or others, without a password. It works by providing the user with a temporary login link that expires after a certain amount of time, or after a number of uses. This prevents you from having to create new user accounts manually, while simultaneously reducing the security risks associated with old, unused user accounts. Change WordPress login URL Easily deploy security-by-obscurity tactics and change your WordPress login page URL using a plugin! Hiding the default login page from hackers makes it more difficult to find, potentially reducing brute force attacks and other unauthorized access attempts. After you change the default wp-admin URL, you can set a 404 for the old login page or redirect it to any page of your choosing. Limit login page access by IP address(es) Limit access to the WordPress login page by IP address(es) for additional security. GDPR login page consent notice Easily meet GDPR requirements by adding a GDPR consent notice to the login page. This is required for GDPR and PCI DSS compliance, thus ensuring your WordPress site login page is in compliance. Emergency password reset Discovered suspicious behavior? Reset all users’ passwords with just one click and regain instant control. Upgrade to Melapress Login Security Premium and get even more benefits. The premium edition of Melapress Login Security comes bundled with even more features, which enable you to take your WordPress website login security to the next level. Disable inactive WordPress user accounts and force passwords to be reset once accounts have been unlocked. Inactive accounts can be managed within a single dashboard for increased efficiency and faster response times. Moreover, you can set accounts to be locked out after a number of failed login attempts and customize the duration and method of unlocking them. Premium features list Everything included in the free edition Manually lock user accounts to immediately prevent login access for rarely used accounts or users on extended leave Add an extra security layer with security questions users must answer when performing sensitive actions such as password resets and account unlocks Receive email alerts for unrecognized device logins, with the option to remotely terminate the session Control user session duration by extending or shortening session timeouts to balance security and convenience One-click integration with third-party plugins such as WooCommerce, LearnDash, MemberPress, and many others Automatically disable inactive WordPress users after a configurable period of inactivity Apply Geo-blocking rules to allow or block login access based on specific countries Restrict users’ login to specific IP addresses, including support for multiple allowed IPs Restrict WordPress user login times by day and/or hours Limit login credentials to email address, username, or both Add a GDPR consent notice to the WordPress login page View detailed user security reports, including last activity, password age, and expired passwords Receive weekly email summary reports covering password resets, password changes, user account lockouts, and more |💎 UPGRADE TO PREMIUM | Why you should use Melapress Login Security Melapress Login Security is a WordPress plugin built from the ground up to help you improve the security of your user accounts and secure your WordPress login. Supercharge login credentials for maximum effectiveness and put a stop to unlimited login attempts, weak passwords, and inactive users. Set up policies to reduce your attack surface area such as login times restrictions, change the WordPress login URL, and much more. Free and premium support Support for the free edition of Melapress Login Security is free on the WordPress support forums. Premium world-class support via one-to-one email is available to the Premium users – upgrade to premium to benefit from priority support. For any other queries, feedback, or if you simply want to get in touch with us, please use our contact form. MAINTAINED & SUPPORTED BY MELAPRESS Melapress builds high-quality WordPress security & admin plugins such as WP 2FA, Melapress Role Editor,and WP Activity Log, the #1 user-rated activity log plugin for WordPress. Visit our website to see how our plugins can help you better manage and improve the security and administration of your WordPress websites and users. Install the plugin from within WordPress Keeping a secure WordPress login page is easy with Melapress Login Security. Simply: From your WordPress dashboard, navigate to Plugins > Add New Search for “Melapress Login Security” Install & activate Melapress Login Security from your Plugins page Install the plugin manually (via file upload) Download the plugin from the WordPress plugins repository Unzip the zip file and upload the folder to the /wp-content/plugins/ directory Activate the Melapress Login Security plugin through the Plugins page in WordPress
Top keywords
- login50×4.69%
- wordpress27×2.54%
- security25×2.35%
- password18×1.69%
- login security15×1.41%
- melapress15×1.41%
- user14×1.31%
- page13×1.22%
- users13×1.22%
- melapress login12×1.13%
- melapress login security12×1.13%
- accounts11×1.03%
Web-Art Login Shield with reCAPTCHA
Web-Art Login Shield with reCAPTCHA protects WordPress authentication, Elementor Login widgets and Elementor Forms. It provides optional Google reCAPTCHA v2/v3, IP lockouts, Advanced login URL protection, IP blocking and REST/XML-RPC protection. It preserves WordPress core authentication logic. No ads, author telemetry or external dashboard. All modules are opt-in and disabled by default. Key Features reCAPTCHA v2/v3 selectable v2 checkbox or v3 score-based verification protection for wp-login.php, Elementor Login and Elementor Forms server-side token, action, score and hostname validation where applicable configurable v3 score threshold one active type at a time configuration verification before activation Elementor support protection for Elementor Login and Elementor Pro Forms native Elementor reCAPTCHA fields are skipped to avoid duplication v2 alignment controls login errors and lockouts remain inside the Login widget dynamic content and Elementor popup support Login Protect per-IP failed-attempt counting and temporary lockouts safe concurrent-request handling active-lockout countdown local security event log with bounded retention optional REST API, Application Password and XML-RPC protection independent operation with or without reCAPTCHA Advanced login URL optional custom login endpoint protection of default login routes while preserving required public actions logout and password-link compatibility emergency wp-config.php recovery constant IP allowlists and blocking separate reCAPTCHA allowlist and Login Protect trusted IP list permanent IP blocking for public site requests with HTTP 403 optional IP | reason notes XML-RPC hardening Optional blocking of: pingback.ping pingback.extensions.getPingbacks system.multicall Security Model Protected flows use fail-closed handling. If an enabled check cannot be completed safely, the request is rejected instead of bypassing protection. Login Protect preserves active lockouts and safely handles concurrent requests. Setting Maximum login attempts or Lockout duration to 0 disables lockout enforcement. All modules remain disabled until enabled. Recovery constants are available in wp-config.php for selected modules. External Services This plugin integrates with Google reCAPTCHA v2 and v3, services provided by Google LLC. reCAPTCHA is disabled by default. Google scripts or verification requests are used only after an administrator enables reCAPTCHA or runs a settings-page verification test. Google’s reCAPTCHA JavaScript (https://www.google.com/recaptcha/api.js) may load on protected wp-login.php requests, pages containing protected Elementor widgets or forms, and the settings page during a verification test. Allowlisted visitors bypass frontend loading where applicable. When reCAPTCHA runs, the visitor’s browser connects directly to Google. Google may process browser, device and interaction information and may set the necessary _GRECAPTCHA cookie under its policies. For server-side verification, the plugin sends the token, configured Secret Key and visitor IP address when available to Google’s siteverify endpoint. It does not include usernames, passwords, email addresses or form contents in that request. The plugin sends no telemetry, analytics or usage data to its author. Google policies: https://policies.google.com/privacy https://policies.google.com/terms Privacy Locally stored security data may include: IP addresses, failed-attempt counts and lockout timestamps a username or email associated with an IP lockout recent events containing an IP address, username or email, source, type and timestamp the latest reCAPTCHA configuration or transport error used for diagnostics permanent IP blocklist entries and optional notes Inactive Login Protect entries become eligible for deletion after seven days. Active lockouts remain until expiry. The event log is limited to 30 entries and 30 days. WordPress privacy tools export or erase records matched to the requested email address or associated account. Unmatched IP-only records remain subject to retention and administrator cleanup. Permanent blocklist entries remain until removed by an administrator. Plugin data can be removed during uninstall when uninstall cleanup is enabled. Legal reCAPTCHA is a trademark of Google LLC. Elementor is a trademark of Elementor Ltd. This plugin is not affiliated with, endorsed by, or sponsored by Google LLC or Elementor Ltd.