Captchinoo, admin login page protection with Google recaptcha
Your login page is the single most attacked page on any WordPress site. Bots hit wp-login.php around the clock, guessing username and password combinations thousands of times a day. Captchinoo puts a human verification step in front of that form, so automated scripts are stopped before they ever reach your password check. Install it, pick the captcha style you like, and you are protected. There is nothing else to configure. Three captcha styles, one click apart Slide to unlock — a lightweight swipe slider, just like unlocking a phone. No external service, no API keys, works on desktop and touch devices. Icon captcha — the visitor picks the one icon that does not belong in the row. Friendly, image based, and no typing required. Google reCAPTCHA v2 — the familiar “I’m not a robot” checkbox, backed by Google’s own bot detection. Why site owners choose Captchinoo No puzzles to read. No distorted letters and no math questions. Your users are not punished for logging in. Genuinely lightweight. Only the assets for the captcha you actually selected are loaded, and only on the login page. Nothing is queued on the front end of your site. Works with caching. The login page is never cached by page caching plugins, so Captchinoo stays reliable where other captcha plugins break. Translation ready. Every string is translatable and the plugin ships with full text domain support. Zero configuration required. The slide captcha works the moment you activate the plugin — no account, no keys, no signup. Captchinoo Pro — three more ways to lock down your login The free plugin gives you three captcha styles for your WordPress login form. Captchinoo Pro adds three stronger layers on top: Two factor authentication (2FA) — the most powerful protection in the plugin. 2FA adds a second identity check on top of the password: the user confirms the login from their mobile device, so a stolen, leaked, or guessed password on its own is no longer enough to get into your site. Google reCAPTCHA v3 — invisible protection that never interrupts your users. Instead of asking anyone to click a box or solve a challenge, reCAPTCHA v3 scores each visitor silently in the background from their interactions with your site. You can run it everywhere without affecting your conversion rate, and it works best when it has the most context about how people use your site. hCaptcha — an independent alternative to Google’s service. hCaptcha blocks automated bots, spam, and abuse by asking visitors to complete a simple verification challenge, and it is the popular choice for site owners who would rather not route their traffic through Google. Pro includes everything in the free version, so you can switch between all six captcha styles at any time. External services This plugin can optionally use Google reCAPTCHA, a third party service, and only when you explicitly select “Google reCAPTCHA” as your captcha type and enter your own API keys. When that option is active, the visitor’s browser loads Google’s reCAPTCHA script from https://www.google.com/recaptcha/api.js, and your server sends the captcha response token together with the visitor’s IP address to https://www.google.com/recaptcha/api/siteverify in order to confirm the challenge was solved. No data is transmitted to Google when the Slide or Icon captcha is selected, and the plugin never sends data anywhere else. Google’s terms and privacy policy apply to that service: Terms of Service — Privacy Policy. Support If you have a problem, a question, or a feature request, please open a thread in the support forum. We answer every one. If Captchinoo helps keep your site safe, a review would mean a lot to us.
Top keywords
- google12×1.95%
- captcha11×1.79%
- recaptcha8×1.30%
- site8×1.30%
- captchinoo6×0.98%
- login6×0.98%
- page5×0.81%
- service5×0.81%
- api4×0.65%
- google recaptcha4×0.65%
- password4×0.65%
- three4×0.65%
SAR One Click Security
There’s a lot of WordPress security plugins with many many options and pages to setup. And that is fine if you know what to do. But most of the times, you don’t need so much or simply you’re not sure about what to set or not. This plugin adds some extra security to your WordPress with only one click. No options page, just activate it! Features Like many other security plugins SAR One Click Security adds well known .htaccess rules, but only the ones probed to be safe to use in almost any type of site (including WooCommerce stores), to protect your WordPress from common attacks. This allows you to have a safer WordPress without worries about what protection you should be using. Turn off ServerSignature directive, that may leak information about your web server. Turn off directory listing, avoiding bad configured hostings to leak your files. Blocks public access (from web) to following files that may leak information about your WordPress install: .htaccess, license.txt, readme.html, wp-config.php, wp-config-sample.php, install.php Blocks access to wp-login.php to dummy bots trying to register in WordPress sites that have registration disabled. Blocks requests looking for timthumb.php, reducing server load caused by bots trying to find it. (*) Blocks TRACE and TRACK request methods, preventing XST attacks. Blocks direct posting to wp-comments-post.php (most spammers do this) and access with blank User Agent, reducing spam comments a lot and also server load. Blocks direct access to PHP files in wp-content directory (this includes subdirectories like plugins or themes). Protecting you from a huge number of 0day exploits. Blocks direct POST to wp-login.php and access with blank User Agent, preventing most brute-force attacks and reducing server load. Blocks access to .txt files under any plugin/theme directory to prevent scans for installed plugins/themes. Blocks any query string trying to get a copy of the wp-config.php file. Blocks gf_page=upload query string argument, this was deprecated in Gravity Forms on May 2015, if your copy of Gravity Forms still uses it, update now! Removes version information from page headers. This includes not only the page header (html or xhtml) but also feed headers (rss, rss2, atom, rdf) and opml comments. Only the version number is removed, not the entire generator information. (*) If your theme uses TimThumb, you can disable that blocking rule, check FAQ before installing the plugin to see how. Requirements WordPress 3.9.2 or higher. (Works with WordPress network/multisite installation). Apache 2.4.x web server It has been tested in many servers including large providers like HostGator, Godaddy and 1&1 with optimal results, and it will work fine in any decent hosting service (that allows you to set options from .htaccess files). Anyway, if you get any problem after activating the plugin, check FAQ for instructions on how to manually uninstall it. If you’re not sure of which server is your hosting company using or if they allow to use custom .htaccess rules, I would recommend you to contact with your host support before installing the plugin. Usage To apply above mentioned security rules simply install and activate the plugin, no options page, no user setup! If you need to remove the security rules for some reason, simply deactivate the plugin. If you want to add them again, activate the plugin again, that easy 😉 And remember, if your theme uses TimThumb, check FAQ before installing the plugin.