Web-Art Login Shield with reCAPTCHA
Web-Art Login Shield with reCAPTCHA protects WordPress authentication, Elementor Login widgets and Elementor Forms. It provides optional Google reCAPTCHA v2/v3, IP lockouts, Advanced login URL protection, IP blocking and REST/XML-RPC protection. It preserves WordPress core authentication logic. No ads, author telemetry or external dashboard. All modules are opt-in and disabled by default. Key Features reCAPTCHA v2/v3 selectable v2 checkbox or v3 score-based verification protection for wp-login.php, Elementor Login and Elementor Forms server-side token, action, score and hostname validation where applicable configurable v3 score threshold one active type at a time configuration verification before activation Elementor support protection for Elementor Login and Elementor Pro Forms native Elementor reCAPTCHA fields are skipped to avoid duplication v2 alignment controls login errors and lockouts remain inside the Login widget dynamic content and Elementor popup support Login Protect per-IP failed-attempt counting and temporary lockouts safe concurrent-request handling active-lockout countdown local security event log with bounded retention optional REST API, Application Password and XML-RPC protection independent operation with or without reCAPTCHA Advanced login URL optional custom login endpoint protection of default login routes while preserving required public actions logout and password-link compatibility emergency wp-config.php recovery constant IP allowlists and blocking separate reCAPTCHA allowlist and Login Protect trusted IP list permanent IP blocking for public site requests with HTTP 403 optional IP | reason notes XML-RPC hardening Optional blocking of: pingback.ping pingback.extensions.getPingbacks system.multicall Security Model Protected flows use fail-closed handling. If an enabled check cannot be completed safely, the request is rejected instead of bypassing protection. Login Protect preserves active lockouts and safely handles concurrent requests. Setting Maximum login attempts or Lockout duration to 0 disables lockout enforcement. All modules remain disabled until enabled. Recovery constants are available in wp-config.php for selected modules. External Services This plugin integrates with Google reCAPTCHA v2 and v3, services provided by Google LLC. reCAPTCHA is disabled by default. Google scripts or verification requests are used only after an administrator enables reCAPTCHA or runs a settings-page verification test. Google’s reCAPTCHA JavaScript (https://www.google.com/recaptcha/api.js) may load on protected wp-login.php requests, pages containing protected Elementor widgets or forms, and the settings page during a verification test. Allowlisted visitors bypass frontend loading where applicable. When reCAPTCHA runs, the visitor’s browser connects directly to Google. Google may process browser, device and interaction information and may set the necessary _GRECAPTCHA cookie under its policies. For server-side verification, the plugin sends the token, configured Secret Key and visitor IP address when available to Google’s siteverify endpoint. It does not include usernames, passwords, email addresses or form contents in that request. The plugin sends no telemetry, analytics or usage data to its author. Google policies: https://policies.google.com/privacy https://policies.google.com/terms Privacy Locally stored security data may include: IP addresses, failed-attempt counts and lockout timestamps a username or email associated with an IP lockout recent events containing an IP address, username or email, source, type and timestamp the latest reCAPTCHA configuration or transport error used for diagnostics permanent IP blocklist entries and optional notes Inactive Login Protect entries become eligible for deletion after seven days. Active lockouts remain until expiry. The event log is limited to 30 entries and 30 days. WordPress privacy tools export or erase records matched to the requested email address or associated account. Unmatched IP-only records remain subject to retention and administrator cleanup. Permanent blocklist entries remain until removed by an administrator. Plugin data can be removed during uninstall when uninstall cleanup is enabled. Legal reCAPTCHA is a trademark of Google LLC. Elementor is a trademark of Elementor Ltd. This plugin is not affiliated with, endorsed by, or sponsored by Google LLC or Elementor Ltd.
Top keywords
- login15×2.41%
- google14×2.25%
- recaptcha14×2.25%
- elementor13×2.09%
- ip11×1.77%
- protection7×1.13%
- optional6×0.96%
- verification6×0.96%
- lockouts5×0.80%
- remain5×0.80%
- v25×0.80%
- v35×0.80%
Protector – Malware Removal, Firewall & Core Repair
Every day, thousands of WordPress sites are hacked. Most security plugins offer protection, but they come with a massive cost: they slow down your server with bloated features and complex settings. Protector is different. It is a lightweight, AI-ready security layer that turns your WordPress site into a digital fortress without compromising speed. Whether you are trying to recover a hacked site or proactively defend your business, Protector delivers enterprise-grade security that anyone can configure. With our new 1-Click Security Overview Dashboard, you can activate all recommended protections and block 98% of automated attacks in under 8 seconds. 📖 Read the Official Documentation here 🦠 Malware Threat Scanner & Auto-Repair Don’t just find malware; destroy it. Our deep, recursive local scanner verifies your WordPress integrity without crashing your server: * Core Integrity Verification: Cross-references all Core files against the official WordPress.org checksums. * Advanced Pattern Detection: Detects suspicious code patterns (like eval, base64_decode, shell_exec) hidden in your files. * 1-Click Auto-Repair: Found a modified core file? Click “Repair” and Protector will automatically fetch a clean, original version directly from the official WP SVN and overwrite the infected file. 🛡️ Login Fortress (Brute-Force Protection) Hackers relentlessly target the wp-login.php page. We make it disappear. * Secret Login URL: Hide wp-login.php completely. Any unauthorized attempt will be instantly redirected to a custom URL of your choice. * Smart Honeypots: Inject invisible fields into your login and comment forms to trap and block spam/brute-force bots automatically. * Block Username Scanning: Prevent attackers from discovering your admin usernames via ?author=1 enumeration. 🔒 1-Click Site Hardening Lock down common vulnerabilities instantly: * Security Headers: Protect against XSS, Clickjacking, and MIME-Sniffing attacks with a single toggle. * XML-RPC Control: Disable XML-RPC completely to eliminate one of the biggest brute-force attack vectors on WordPress. * Version Obfuscation: Hide your WordPress version from the source code so hackers can’t target known exploits. * Restrict REST API: Block public access to endpoints that expose sensitive user data. 📊 Live Attack Log Peace of mind you can actually see. Monitor every blocked attack, triggered honeypot, and deleted malware in real-time straight from your dashboard. 🚀 Upgrade to KloxStudios Pro Need absolute maximum power? Protector integrates seamlessly with the KloxStudios Cloud AI. Pro users unlock Cloud AI Malware Verification for 3rd-party plugins/themes, Automatic IP Lockouts, Instant Admin Login Alerts (Email & Webhook), and 2FA.
Top keywords