Login Armor
🇫🇷 Fully translated into French. Interface et documentation intégralement disponibles en français. Thirteen security modules. One lightweight plugin. No premium tier. Login Armor protects WordPress login, accounts and administration with thirteen independent modules. It is built for agencies, freelancers and site owners who want practical security, clear evidence and safe defaults without a remote dashboard, bundled telemetry or upsells. Why Login Armor Complete and free: every module is included under the GPL. Lightweight: modules load only when needed and normal login checks add less than 2 ms on a typical setup. Private by default: data stays on your site. Optional external calls are disabled until you enable the related feature. Ready for real sites: multisite support, reverse-proxy controls, WP-CLI commands and production-safe defaults. Thirteen security modules Hide Login: replace wp-login.php with a private slug and return a 404 or redirect blocked visitors to a chosen URL. Brute Force Protection: escalating lockouts, subnet blocking, trusted proxy headers and coverage for login, password recovery, registration, XML-RPC and REST users. Hardening: fifteen controls for XML-RPC, pingbacks, file editing, version exposure, application passwords, author enumeration, reserved usernames, honeypots and new-admin alerts. Two-Factor Authentication: TOTP, email codes, backup codes, trusted devices, per-role enforcement, grace periods and recovery. Detection and Incidents: group raw events into attack patterns with severity, timelines, source IPs, targeted users and one-click actions. Activity Log: tamper-evident admin audit trail with filters, CSV export, retention controls and optional signed SIEM forwarding. Security Headers: CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options for login and lockout pages, with optional site-wide baseline headers. Breach Check: privacy-preserving Have I Been Pwned password checks and an optional XposedOrNot email check. Password Policy: length and character rules, username exclusion, breached-password rejection and optional non-locking expiration reminders. Session Management: idle timeout, maximum lifetime, optional single-device access and one-click revocation of other sessions. IP Geolocation: cached country lookup for IPs shown in Incidents and Events, with private ranges excluded. Request Firewall: optional, monitor-first filtering of malicious paths, query strings and HTTP methods, with administrator exclusions and IP/path allowlists. Bot Challenge: an invisible proof-of-work the browser solves before the login form is accepted, an alternative to CAPTCHAs with no external service; monitor-first, then enforce. Additional tools Login Armor also includes guided onboarding, a 0-100 security score, conflict detection, email/Slack/Discord/webhook notifications, a dashboard widget and a complete WP-CLI suite. The optional AI Security Briefing uses your own WordPress AI connector to explain a thirty-day security snapshot or a single incident. It always starts with deterministic facts, works without AI and sends nothing until an administrator explicitly requests an analysis. GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies. Treize modules de sécurité. Une seule extension légère. Aucune version premium. Login Armor protège la connexion, les comptes et l’administration de WordPress grâce à treize modules indépendants. L’extension s’adresse aux agences, freelances et propriétaires de sites qui veulent une sécurité concrète, des preuves lisibles et des réglages sûrs, sans tableau de bord distant, télémétrie imposée ni upsell. Pourquoi Login Armor Complet et gratuit : tous les modules sont inclus sous licence GPL. Léger : les modules se chargent uniquement lorsque nécessaire et les contrôles ajoutent moins de 2 ms sur une connexion normale. Privé par défaut : les données restent sur votre site. Les appels externes optionnels sont désactivés tant que vous n’activez pas la fonction concernée. Prêt pour la production : multisite, reverse proxies, commandes WP-CLI et réglages par défaut sécurisés. Treize modules de sécurité Masquer la connexion : remplace wp-login.php par un slug privé et renvoie une 404 ou redirige les visiteurs bloqués vers l’URL choisie. Protection contre la force brute : verrouillages progressifs, blocage de sous-réseaux, proxies de confiance et protection de la connexion, récupération, inscription, XML-RPC et REST users. Renforcement : quinze contrôles pour XML-RPC, les pingbacks, l’éditeur de fichiers, la version, les mots de passe applicatifs, l’énumération d’auteurs, les identifiants réservés, le pot de miel et les alertes nouvel administrateur. Authentification à deux facteurs : TOTP, codes par e-mail, codes de secours, appareils de confiance, application par rôle, période de grâce et récupération. Détection et incidents : regroupe les événements en scénarios d’attaque avec sévérité, chronologie, IP sources, comptes ciblés et actions immédiates. Journal d’activité : piste d’audit admin infalsifiable avec filtres, export CSV, rétention et transfert SIEM signé optionnel. En-têtes de sécurité : CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy et X-Content-Type-Options pour les pages de connexion et de verrouillage, avec en-têtes de base optionnels sur tout le site. Détection de fuites : vérification confidentielle des mots de passe via Have I Been Pwned et contrôle optionnel des e-mails via XposedOrNot. Politique de mot de passe : longueur, classes de caractères, exclusion de l’identifiant, rejet des mots de passe compromis et rappels d’expiration non bloquants. Gestion des sessions : délai d’inactivité, durée maximale, accès limité à un appareil et révocation des autres sessions. Géolocalisation IP : pays des IP affichées dans Incidents et Événements, avec cache et exclusion des plages privées. Pare-feu de requêtes : filtrage optionnel, d’abord en surveillance, des chemins, requêtes et méthodes HTTP malveillants, avec exclusion des administrateurs et listes d’autorisation IP/chemins. Défi anti-bot : une preuve de calcul invisible résolue par le navigateur avant validation du formulaire de connexion, alternative aux CAPTCHA sans service externe ; d’abord en surveillance, puis en blocage. Outils complémentaires Login Armor inclut aussi un assistant de configuration, un score de sécurité de 0 à 100, la détection de conflits, les notifications par e-mail, Slack, Discord ou webhook, un widget de tableau de bord et une suite WP-CLI complète. Le briefing de sécurité IA optionnel utilise votre propre connecteur IA WordPress pour expliquer les trente derniers jours ou un incident précis. Il commence toujours par des faits déterministes, fonctionne sans IA et n’envoie rien tant qu’un administrateur ne demande pas explicitement une analyse. Conçu par Login Armor est conçu et maintenu par Fabrice Ducarme de WPFormation. Nous l’utilisons sur chaque site que nous livrons. Présentation et fonctionnement de Login Armor Guides de sécurité WordPress sur WPFormation Veille des vulnérabilités WordPress sur WPFormation GPL pour toujours. PHP 8.1+. WordPress 6.8+. Zéro dépendance. External Services Login Armor has no telemetry and requires no Login Armor account. The following services are contacted only when WordPress itself or an administrator enables the related feature. WordPress AI connector (optional) The AI Security Briefing sends a security prompt through the administrator’s own WordPress AI connector only after they click an analysis button. Minimised mode sends counts, categories, severities and role buckets without clear IP addresses or usernames. Explicit deep mode also sends IP addresses and event details. Login Armor stores no provider API key. The selected AI provider’s terms and privacy policy apply. Slack, Discord or custom webhook (optional) When an administrator enables an incident notification channel, Login Armor sends the incident type, severity, IP address, target username, event count and site URL to the configured endpoint. The separate signed Activity Log forwarding option sends the event, object, user ID/login/role, IP address, description, integrity hashes, site URL and plugin version to the administrator’s SIEM or custom webhook. Slack: Terms | Privacy Discord: Terms | Privacy Custom webhook: terms and privacy are controlled by the administrator’s chosen endpoint. Gravatar The Activity Log uses WordPress core’s get_avatar(). If avatars are enabled in WordPress, a hashed email address may be sent to Gravatar to retrieve the image. Gravatar: Terms | Privacy Have I Been Pwned (optional) Breach Check and the optional compromised-password policy send only the first 5 characters of a password’s SHA-1 hash to the Pwned Passwords API. The password and full hash never leave the site. Checks fail soft if the service is unavailable. Public registration and password-reset validation do not call the service; authenticated checks remain active. Have I Been Pwned: Privacy | Acceptable Use XposedOrNot (optional) The separate Email check, disabled by default, sends the user’s email address and a plugin-identifying User-Agent to XposedOrNot when a user is created or changes email. XposedOrNot: Service | Privacy ipwho.is (optional) IP Geolocation sends a displayed public IP address to ipwho.is when an administrator opens Incidents or Events. Results are cached for 30 days. Private and reserved ranges are never sent, and developers can replace the lookup through the login_armor_geoip_lookup filter. ipwho.is: Service | Documentation
Top keywords
- de39×2.66%
- et28×1.91%
- login20×1.36%
- les17×1.16%
- optional14×0.95%
- armor13×0.89%
- des13×0.89%
- login armor13×0.89%
- wordpress13×0.89%
- ip12×0.82%
- par10×0.68%
- modules9×0.61%
WP Activity Log
Monitor activity on your WordPress sites and get clear insights into what’s happening with detailed user and event logging. Keep WordPress logs of everything that happens on your sites and multisite networks with WP Activity Log instantly, without writing a line of code. Easily detect suspicious activity on your WordPress site before it escalates Record failed login attempts to detect potential security breaches and strengthen site protection Track user logins and logouts to ensure SLAs are consistently met Monitor user activity and productivity to boost accountability Know exactly what all your users are doing in real time Know what happened before an outage for faster, easier troubleshooting Ensure compliance with regulations and standards like GDPR and PCI DSS Better manage & organize your site and users for smoother operations Simple setup ensures you start benefiting quickly and easily WP Activity Log is a complete logging solution, helping hundreds of thousands of administrators and security professionals track changes on their websites thanks to real-time user activity monitoring. 💎 Need more extensive features? Unlock advanced reporting, exports/mirroring, session management, and real-time alerts with WP Activity Log premium or enterprise. What WordPress changes WP Activity Log tracks A website activity log is important for improving troubleshooting, compliance, user management, and security. Get WP Activity Log and keep track of events on your site. The log not only tells you that a post, a user profile, or an object was updated, it also lets you know exactly what changed, when, and includes a user log (by whom), so you always have the information you need. Below is a summary of the changes that the plugin can keep a record of: Post, page, and custom post type changes: Status, content changes, title, URL, custom field, and other metadata changes Tags and category changes: Creating, modifying, deleting, and adding/removing them from posts Widget and menu changes: Creating, modifying, or deleting them User changes: User created or registered, deleted, or added to a site on multisite network User profile changes: Password, email, display name, and role changes Access logging: User login, logout, failed logins, and terminating other sessions WordPress core and settings changes: Installed updates, permalinks, default role, URL, and other site-wide changes WordPress multisite network changes: Adding, deleting, or archiving sites, adding or removing users from sites, etc. Plugin and Theme changes: Installing, activating, deactivating, uninstalling, and updating WordPress database changes: When a plugin adds or removes a table Third-party plugin changes: WooCommerce Stores & products, Yoast SEO, RankMath, Termly, WPForms, Gravity Forms, Advanced Custom Fields (ACF), MainWP, ManageWP, WP Umbrella, and other popular WordPress plugins WordPress site file changes: New files added, or existing files modified or deleted. Event details recorded Detailed event logging ensures that for every event that the plugin records, it reports the: Date & time (and milliseconds) of when it happened User & role of the user who did the change Source IP address from where the change happened The object on which the change has taken place Refer to WordPress activity log event IDs for a complete list of all the changes WP Activity Log can keep a record of and a detailed explanation of what change every event ID represents. 💎 Upgrade to WP Activity Log Premium and get even more The premium edition of WP Activity Log takes WordPress user activity tracking to the next level. It comes bundled with even more features, including log mirroring, enterprise-grade support, user session management, and much more! Premium features list See who is logged in and monitor their current activities in real-time Log off any user at the click of a button Generate fully-configurable HTML and CSV reports for easy data analysis Receive email, SMS, and Slack notifications for important changes (fully configurable) Use search filters to fine-tune results and find what you need in seconds Store the activity logs in an external database to enhance security and scalability Mirror the activity log to log management systems such as AWS CloudWatch, Loggly, Papertrail, and others in real-time Mirror the logs to business communication systems like Slack Send a copy of your website’s activity log to a log file on your web server Archive old activity log data to another database for improved storage and log management Add notes to activity log entries for better context and internal documentation Refer to the WP Activity Log plugin features and benefits page to learn more about the benefits of upgrading to WP Activity Log Premium. 🔌 WP Activity Log third-party plugin support All WP Activity Log editions include activity tracking for third-party plugins, including (in alphabetical order): Advanced Custom Fields (ACF) – Log changes to post types, taxonomies, and taxonomy terms bbPress – Track changes to forums, topics, and bbPress settings Gravity Forms – Track changes to Gravity Forms settings, forms, and entries (leads) LearnDash – Track changes to courses, lessons, and other system changes, as well as student activity such as course, lesson, and quiz enrollments and completions. MemberPress – Log changes to plugin settings, memberships, payments, subscriptions, and other actions Multisite & management tools – Track changes across your network for MainWP, ManageWP, Modular DS, Infinite WP, WP Umbrella, WP Remote, and other multisite management plugins Paid Membership Pro – Log changes to membership levels, user assignments, and more. Premium users can also track order and checkout activity, and access a Members Activity panel inside each member’s profile for instant visibility into recent actions. RankMath – Log changes to RankMath settings, SEO configurations, and on-page SEO edits Redirection – Keep a log of changes to redirections and redirection groups Termly – Log changes to Termly settings and configurations WooCommerce – Keep a log of changes to store settings, orders, products, coupons, and more WPForms – Log changes to WPForms settings, forms, form files, and entries (leads) Yoast SEO – Track changes to Yoast SEO settings and on-page SEO in the Yoast SEO meta box Extra Features for Enhanced Monitoring and Management Both free and premium editions of WP Activity Log include a number of non-logging specific features that make the plugin a complete WordPress monitoring solution. Here is what is included: Free Built-in support for reverse proxies and web application firewalls Integration with WhatIsMyIpAddress.com – get all information about an IP address with a single click Limit who can view the WordPress activity log by users or roles Enable or disable individual event IDs from the activity log Configurable dashboard widget highlighting the most recent critical activity Configurable WordPress activity log retention policies Display user avatars in events for better recognizability And much more! Premium Everything that’s included in the Free edition, plus: Full WordPress multisite support Create custom alerts & notifications to monitor additional functionality Import and export plugin settings Real-time activity log visible in the WordPress admin toolbar And much more! 🛠️ Free and premium plugin support If you encounter any issues with the free edition of WP Activity Log, you can post and get help on the WordPress.org support forums. You can also find more technical information and plugin documentation on the Melapress knowledge base. Premium plugins include a full year of free updates and dedicated one-to-one premium email support. This means you get direct access to our support team who will assist you with any questions or issues related to the plugins. As featured on: Kinsta Pagely Shout Me Loud The Dev Couple WPKube Techwibe Tidy Repo KitPloit and many others. MAINTAINED & SUPPORTED BY MELAPRESS Melapress develops high-quality WordPress management and security plugins such as Melapress Login Security, WP 2FA, and Melapress Role Editor. Browse our list of WordPress security and administration plugins to see how our plugins can help you better manage and improve the security and administration of your WordPress websites and users. Installing WP Activity Log Install WP Activity Log from within WordPress Visit ‘Plugins > Add New’ Search for ‘WP Activity Log’ Install and activate the WP Activity Log plugin Allow or skip diagnostic tracking Install WP Activity Log manually Extract the plugin ZIP file and upload it to the /wp-content/plugins/ directory Activate the WP Activity Log plugin from the ‘Plugins’ menu in WordPress Allow or skip diagnostic tracking