{"id":301525,"date":"2026-04-27T13:04:38","date_gmt":"2026-04-27T13:04:38","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/login-armor\/"},"modified":"2026-09-24T03:52:17","modified_gmt":"2026-09-24T03:52:17","slug":"login-armor","status":"publish","type":"plugin","link":"https:\/\/en-gb.wordpress.org\/plugins\/login-armor\/","author":11816818,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.7.5","stable_tag":"2.7.5","tested":"7.1.2","requires":"6.8","requires_php":"8.1","requires_plugins":null,"header_name":"Login Armor","header_author":"Fabrice Ducarme","header_description":"Hide your login URL, block brute force attacks, harden WordPress, and monitor all admin activity.","assets_banners_color":"fafafa","last_updated":"2026-09-24 03:52:17","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/wpformation.com","header_plugin_uri":"https:\/\/wpformation.com\/login-armor","header_author_uri":"https:\/\/wpformation.com","rating":5,"author_block_rating":0,"active_installs":500,"downloads":5964,"num_ratings":6,"support_threads":2,"support_threads_resolved":2,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"wpformation","date":"2026-04-27 13:04:42","revision":3516483},"2.0.0":{"tag":"2.0.0","author":"wpformation","date":"2026-04-27 16:57:55","revision":3516681},"2.0.1":{"tag":"2.0.1","author":"wpformation","date":"2026-04-28 06:46:51","revision":3517031},"2.0.2":{"tag":"2.0.2","author":"wpformation","date":"2026-04-28 07:30:39","revision":3517057},"2.0.3":{"tag":"2.0.3","author":"wpformation","date":"2026-04-28 09:15:08","revision":3517150},"2.0.4":{"tag":"2.0.4","author":"wpformation","date":"2026-04-28 10:51:34","revision":3517260},"2.0.5":{"tag":"2.0.5","author":"wpformation","date":"2026-04-28 13:07:13","revision":3517438},"2.1.0":{"tag":"2.1.0","author":"wpformation","date":"2026-04-29 05:58:05","revision":3517980},"2.1.1":{"tag":"2.1.1","author":"wpformation","date":"2026-04-29 16:52:57","revision":3518663},"2.1.10":{"tag":"2.1.10","author":"wpformation","date":"2026-05-05 13:35:50","revision":3523413},"2.1.11":{"tag":"2.1.11","author":"wpformation","date":"2026-05-05 16:54:05","revision":3523606},"2.1.12":{"tag":"2.1.12","author":"wpformation","date":"2026-05-11 07:24:30","revision":3528339},"2.1.13":{"tag":"2.1.13","author":"wpformation","date":"2026-05-11 15:47:32","revision":3528908},"2.1.14":{"tag":"2.1.14","author":"wpformation","date":"2026-05-20 09:39:54","revision":3538740},"2.1.15":{"tag":"2.1.15","author":"wpformation","date":"2026-05-20 19:30:50","revision":3539950},"2.1.16":{"tag":"2.1.16","author":"wpformation","date":"2026-05-20 22:05:36","revision":3540203},"2.1.17":{"tag":"2.1.17","author":"wpformation","date":"2026-06-05 05:27:35","revision":3561854},"2.1.18":{"tag":"2.1.18","author":"wpformation","date":"2026-06-05 07:09:59","revision":3561961},"2.1.19":{"tag":"2.1.19","author":"wpformation","date":"2026-06-05 09:13:44","revision":3562130},"2.1.2":{"tag":"2.1.2","author":"wpformation","date":"2026-04-29 19:59:32","revision":3518860},"2.1.21":{"tag":"2.1.21","author":"wpformation","date":"2026-06-05 13:19:59","revision":3562407},"2.1.22":{"tag":"2.1.22","author":"wpformation","date":"2026-06-08 14:01:45","revision":3564809},"2.1.23":{"tag":"2.1.23","author":"wpformation","date":"2026-06-10 14:39:36","revision":3567656},"2.1.25":{"tag":"2.1.25","author":"wpformation","date":"2026-06-11 11:33:19","revision":3568766},"2.1.26":{"tag":"2.1.26","author":"wpformation","date":"2026-06-11 14:36:57","revision":3568979},"2.1.3":{"tag":"2.1.3","author":"wpformation","date":"2026-04-29 20:36:16","revision":3518888},"2.1.4":{"tag":"2.1.4","author":"wpformation","date":"2026-04-30 09:16:15","revision":3519351},"2.1.6":{"tag":"2.1.6","author":"wpformation","date":"2026-04-30 19:38:48","revision":3519934},"2.1.7":{"tag":"2.1.7","author":"wpformation","date":"2026-05-02 14:38:40","revision":3520945},"2.1.8":{"tag":"2.1.8","author":"wpformation","date":"2026-05-02 15:42:39","revision":3520981},"2.1.9":{"tag":"2.1.9","author":"wpformation","date":"2026-05-05 12:37:37","revision":3523353},"2.2.0":{"tag":"2.2.0","author":"wpformation","date":"2026-06-15 13:23:10","revision":3573211},"2.3.0":{"tag":"2.3.0","author":"wpformation","date":"2026-06-16 16:45:41","revision":3574798},"2.4.0":{"tag":"2.4.0","author":"wpformation","date":"2026-06-17 10:27:48","revision":3575659},"2.4.1":{"tag":"2.4.1","author":"wpformation","date":"2026-07-05 11:17:54","revision":3596680},"2.4.2":{"tag":"2.4.2","author":"wpformation","date":"2026-07-05 14:53:33","revision":3596858},"2.4.3":{"tag":"2.4.3","author":"wpformation","date":"2026-07-05 17:49:40","revision":3596989},"2.4.4":{"tag":"2.4.4","author":"wpformation","date":"2026-07-12 14:30:15","revision":3604882},"2.4.5":{"tag":"2.4.5","author":"wpformation","date":"2026-07-22 03:46:59","revision":3617902},"2.4.6":{"tag":"2.4.6","author":"wpformation","date":"2026-08-04 14:55:43","revision":3634315},"2.4.7":{"tag":"2.4.7","author":"wpformation","date":"2026-08-06 09:35:23","revision":3636385},"2.4.8":{"tag":"2.4.8","author":"wpformation","date":"2026-08-06 10:07:54","revision":3636420},"2.5.0":{"tag":"2.5.0","author":"wpformation","date":"2026-08-09 16:57:32","revision":3639597},"2.5.1":{"tag":"2.5.1","author":"wpformation","date":"2026-08-13 07:16:15","revision":3644448},"2.5.2":{"tag":"2.5.2","author":"wpformation","date":"2026-08-20 14:26:25","revision":3657078},"2.5.3":{"tag":"2.5.3","author":"wpformation","date":"2026-08-23 12:22:11","revision":3661816},"2.6.0":{"tag":"2.6.0","author":"wpformation","date":"2026-09-07 15:02:35","revision":3685151},"2.7.5":{"tag":"2.7.5","author":"wpformation","date":"2026-09-24 03:52:17","revision":3710442}},"upgrade_notice":{"2.7.5":"<p>Removes the dashed break near the right-hand edge of the activity chart. It was added in 2.7.3 to flag a partial final hour that does not in fact exist, and it read as a gap in the data. The curve is one continuous line again.<\/p>","2.7.4":"<p>Fixes two things: the activity chart on the Overview showed what looked like a gap in the data while it loaded, and the Activity Log&#039;s nightly purge was never re-scheduled if it went missing, so a site could stop deleting old rows for good.<\/p>","2.7.3":"<p>Fixes a false TAMPERED alarm on the Activity Log: the nightly retention purge broke the integrity chain it was verified against, on every site that kept the module on longer than its retention window. Also corrects the activity chart, which was stretched 1.63 times too tall.<\/p>","2.7.2":"<p>Fixes three defects an independent review of 2.7.1 found. An AI analysis could be generated, billed and then silently lost on a site with an incomplete table; a malformed bulk request could resolve every incident; and the test guarding that endpoint&#039;s access check proved nothing.<\/p>","2.7.1":"<p>First release to carry the 2.7.0 work. Fixes fourteen defects, three of them serious: an export could call a module off while it was running, a cache could freeze your login decoys so a changed setting did nothing, and saving a hardening rule could report success while the file went unwritten.<\/p>","2.7.0":"<p>New safe mode: one line in wp-config.php gets you back in when a setting locks you out. Plus a scheduled security digest, eight Site Health tests, a search box in Settings and a Force HTTPS control. Two fixes reach every site: password reset links on apex+www, and a hardening toggle read as ON.<\/p>","2.6.1":"<p>Reliability release. Your rules in the uploads .htaccess are preserved instead of erased. On multisite, every site is set up and gets its scheduled tasks. Two alerts in the same second no longer cancel one another; critical alerts keep a reserve. Country lookups moved off the admin screen.<\/p>","2.6.0":"<p>Export your settings as JSON and replay them on your other sites, from the Settings tab or with wp login-armor settings import. Two-factor entries in authenticator apps now carry the site domain, so a long list stays searchable.<\/p>","2.5.3":"<p>Fixes the &quot;trust this device&quot; checkbox, which could not be ticked because the code field submitted itself on the sixth digit. Incident timelines now show every event that raised the incident, instead of the last ten minutes only.<\/p>","2.5.2":"<p>Fixes password reset links failing with &quot;this key is no longer valid&quot; when Hide Login is enabled and usernames are e-mail addresses. Recommended for every site using Hide Login.<\/p>","2.5.1":"<p>Compatibility release. The firewall no longer blocks the requests your site makes to itself, which could break plugins such as SEOPress. Restrict REST API now has an exceptions field, so a plugin needing public REST access no longer requires custom PHP.<\/p>","2.5.0":"<p>New optional Bot Challenge module: an invisible proof-of-work on the login form, a CAPTCHA alternative with no external service. Off by default; enabling starts in monitor mode. Existing sites unchanged.<\/p>","2.4.8":"<p>Security follow-up: prevents a misconfigured trusted proxy from becoming a shared lockout identity and completes reliable webhook delivery for audit rows retained under contention.<\/p>","2.4.7":"<p>Security update: closes proxy-header rate-limit bypass, unauthenticated 2FA recovery email amplification, and unauthenticated HIBP request amplification. Recommended for all installations.<\/p>","2.4.6":"<p>Fixes the Hide Login custom redirect and restores FSE block styles on protected 404 responses.<\/p>","2.4.5":"<p>The plugin&#039;s own blocks (2FA lockout, honeypot, reserved username) no longer count as failed passwords, so a legitimate user is not locked out while using the correct one. Failed logins now show their real reason. Also fixes the incidents table failing to create on MariaDB 11.7+\/MySQL 9.<\/p>","2.4.4":"<p>Hardening: accurate dashboard threat level, canonical wp_login cycle after 2FA, atomic lockout escalation, SSRF validation before every webhook delivery, and CSV formula-injection neutralisation. Recommended for all installations.<\/p>","2.4.3":"<p>Security: mandatory 2FA is enforced after grace expiry, with an administrator recovery path. Also blocks TOTP replay, tightens webhook SSRF validation, and neutralises attacker input before AI incident analysis. Recommended for all installations.<\/p>","2.4.2":"<p>Coherence release: cleaner deactivation and uninstall, a confirmation before disabling Two-Factor, faster brute-force lookups, and a heads-up when a front-end login plugin (e.g. Ultimate Member) is active. No behaviour change on standard installs. Recommended for all.<\/p>","2.4.1":"<p>Fixes a &quot;critical error&quot; during password recovery when another plugin re-fires a WordPress hook with an off-contract argument type. Strict parameter hints relaxed, with internal guards, on every core-hook callback plugin-wide. Neutral on standard calls. Recommended for all installs.<\/p>","2.4.0":"<p>New: an optional Request Firewall (8G-inspired PHP filter) that blocks malicious requests - off by default, starts in monitor mode (logs without blocking), admins never filtered. Plus a first-run onboarding wizard with a one-click safe baseline. All opt-in; existing sites unchanged.<\/p>","2.3.0":"<p>Account-security release: Password Policy (length\/complexity + reject breached passwords via privacy-preserving HIBP), Session Management (idle timeout, max lifetime, single session), and opt-in IP Geolocation. All off by default; nothing changes until you enable it.<\/p>","2.2.0":"<p>New: the AI Security Briefing turns your last 30 days of activity into a plain-language verdict, an IP picture and prioritised actions, on top of a deterministic facts snapshot. Built on the WordPress 7 native AI Client - uses your own connector, no API key stored, runs on click.<\/p>","2.1.26":"<p>Fixes email\/backup 2FA bouncing to &quot;session expired&quot; on browsers that don&#039;t return the verification cookie on submit (some Chrome setups; Firefox worked). The form now also carries the session token, so login works regardless. Recommended if Email 2FA is enabled. Security unchanged.<\/p>","2.1.25":"<p>Fixes email\/backup two-factor verification being rejected (&quot;session expired&quot;) in some browsers, notably Chrome, while Firefox worked. The form is now uncached and authenticated by the signed same-site cookie. Recommended if Email 2FA is enabled.<\/p>","2.1.24":"<p>Fixes a fatal error (HTTP 500 \/ &quot;network error&quot;) during authenticator-app (TOTP) setup on hosts whose wp-config.php does not define AUTH_KEY, such as some Infomaniak installs. Recommended if Two-Factor is enabled. Existing setups are unaffected.<\/p>","2.1.23":"<p>Fixes the two-factor login screen: the &quot;use a different method&quot; links now work (and email a fresh code when switching to Email), expired\/locked sessions explain themselves, and the authenticator-setup button reports errors. Recommended for 2FA users.<\/p>","2.1.22":"<p>Fixes a Security Score that under-counted active modules: Brute Force and Detection (on by default) are now scored correctly, so the header, the score number and the module list agree. Display and scoring only: recommended for all installs.<\/p>","2.1.21":"<p>Cosmetic patch: cleaner user-agent labels in the Events table: Jetpack\/WordPress.com clients are recognised, and long agents are trimmed at a word boundary with an ellipsis instead of a chopped-off string with a dangling parenthesis.<\/p>","2.1.20":"<p>Migration-friendly integrity: a security-key change now shows an amber &quot;Keys changed&quot; advisory with one-click chain re-baseline instead of a false &quot;TAMPERED&quot; alarm. Adds an XML-RPC blind-spot warning when Hide Login is on but XML-RPC stays open. Completes the French translation.<\/p>","2.1.19":"<p>Clearer attack-type labels + descriptions on incidents, French translation of the visible admin tabs, translatable toast notifications, and a fix for the Activity Log integrity badge staying &quot;UNVERIFIED&quot; after a successful verify. Recommended for all installs.<\/p>","2.1.18":"<p>Patch. Fixes &quot;Select all&quot; \/ bulk actions when incidents are all resolved (checkboxes now on every card) and only labels the attack vector for XML-RPC\/REST (no more misleading &quot;via login form&quot;). Recommended for 2.1.17 users.<\/p>","2.1.17":"<p>Feature release. Incidents now show the attack vector (XML-RPC \/ REST \/ login form), so you can spot which attempts bypass your hidden login URL, plus bulk mark-resolved\/ignore. Adds a vector column to the incidents table (auto migration). Recommended for all installs.<\/p>","2.1.16":"<p>Bug fix release from an external audit. Fixes plain-permalinks compat (Hide Login URL, REST API allowlist), restores activity-log coverage for 2FA, frontend registration and password reset, and extends Honeypot to WooCommerce + frontend login forms. Recommended for all installs.<\/p>","2.1.15":"<p>Fixes a fatal TypeError when third-party plugins (e.g. WP Fastest Cache) call WordPress URL builders with off-contract argument types. Strict parameter hints relaxed on seven callbacks; return types unchanged. Neutral on canonical WP calls.<\/p>","2.1.14":"<p>Bug fix. The prevent_author_enum hardening toggle no longer blocks the legitimate ?author=N filter in wp-admin Posts\/Pages lists (&quot;All \/ Mine \/ &quot; links). Public enumeration block unchanged. Three-line fix.<\/p>","2.1.13":"<p>Bug fix. Silent 2FA failure on installs with permalink_structure without trailing slash (e.g. \/%postname%): the verify cookie path mismatched the request path after handle_loaded&#039;s normalisation. Fixed cookie path to omit trailing slash. Neutral on trailing-slash installs.<\/p>","2.1.12":"<p>Bug fix. Hide Login rendered without CSS when both apex and www routed to the same WP (shared hosting). Two fixes: canonical-host 301 in Hide Login + host-aware CSP in Login Page Security Headers. Neutral on single-host installs. New filter login_armor_canonical_host_redirect for opt-out.<\/p>","2.1.11":"<p>Bug fix for multisite + domain mapping: the Hide Login URL is now host-aware (picks home_url or site_url from HTTP_HOST), fixing a 2.1.9 regression where mapped subsites redirected to \/wp-admin\/ (404). Standard and headless installs keep working.<\/p>","2.1.10":"<p>Cosmetic fix. The 404 page served when an anonymous visitor hits <code>\/wp-admin\/<\/code> with Hide Login enabled now renders as a proper WordPress 404 (body class <code>error404<\/code>, SEO <code>noindex<\/code> meta, theme 404 template) instead of a half-bootstrapped page. No security or functional change.<\/p>","2.1.9":"<p>Bug fix. Hide Login now builds the rewritten login URL from <code>site_url()<\/code> (matching <code>wp_login_url()<\/code> in WP core) instead of <code>home_url()<\/code>. Fixes silent breakage on multisite headless, WordPress in subdirectory, and reverse-proxy installs. Neutral on standard installs.<\/p>","2.1.8":"<p>Hygiene release after a full 2.1.7 audit. Three LOW fixes: the webhook stats query no longer warns on fresh installs, the lockout_window option is cleaned on uninstall, and five missing French translations were added. No end-user-visible change.<\/p>","2.1.7":"<p>Preventive: hardens the Email 2FA enrollment flow. Failed <code>wp_mail()<\/code> no longer leaves a half-committed 2FA state, and a new pre-activation modal forces a real test email + a safety-net check before the user can lock themselves out. Recommended for every install where Email-based 2FA is enabled.<\/p>","2.1.6":"<p>Preventive release. Eliminates a latent V2.1.3-style fatal risk in the TwoFactor module. Finishes the uninstall.php cleanup (zero residual data). Surfaces Activity Log integrity coverage scope in admin UI. No new features, no DB migration.<\/p>","2.1.4":"<p>Critical hotfix: 2.1.3 fatal-errored on every fresh install (Class &quot;LoginArmor\\ActivityLog\\ActivityLog&quot; not found). Sites with Activity Log already enabled were unaffected. Recommended for every install, urgent for new installs.<\/p>","2.1.3":"<p>Critical hotfix: Hardening &quot;Hide WP version&quot; was stripping cache-buster from our own assets, so updates past 2.1.0 were invisible behind hosting CDNs (LiteSpeed LSADC, Cloudflare). Recommended for every install.<\/p>","2.1.2":"<p>Critical hotfix: the Settings tab fatal-errored on every fresh install that had not yet enabled the Activity Log module (Class WebhookDispatcher not found). Recommended for every install.<\/p>","2.1.1":"<p>Activity Log integrity: every row is HMAC-signed and chained, detects any tampering. Optional signed webhook forwarding (SIEM \/ Slack \/ Datadog \/ any HTTPS). New WP-CLI verify-chain. Bundles 6 hardening fixes. Migration automatic. Recommended for every install.<\/p>","2.1.0":"<p>Security: 2FA pending token moved from URL query string to a signed HttpOnly + SameSite=Strict cookie. Closes URL-leak (browser history \/ Referer \/ access logs) and DB-leak (clear token no longer in wp_options). Recommended for every install with 2FA enabled.<\/p>","2.0.5":"<p>Security audit pass: REST author-enum scope, optional HSTS, IPv6 subnet fix, 0.0.0.0 placeholder DoS skip, .htaccess admin-rules preservation. No regression. Recommended.<\/p>","2.0.4":"<p>Real fix for the lockout 429 page on hosts with a public page cache (LiteSpeed Cache, WP Rocket, Cloudflare). Recommended after the 2.0.1-2.0.3 sequence.<\/p>","2.0.3":"<p>Hotfix: HTTP\/2 stream termination on LiteSpeed\/LSAPI for the branded lockout page. Recommended.<\/p>","2.0.2":"<p>Critical fix: 429 branded lockout page now reaches the browser. Recommended.<\/p>","2.0.1":"<p>Branded 429 lockout page on the triggering attempt + Reset Stats UI + correct WP.org banner\/icon. Recommended.<\/p>","2.0.0":"<p>First WordPress.org release of the V2 line. Eight independent security modules. Recommended.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":6},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3517031,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3517031,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3517031,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3517031,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.14","2.1.15","2.1.16","2.1.17","2.1.18","2.1.19","2.1.2","2.1.21","2.1.22","2.1.23","2.1.25","2.1.26","2.1.3","2.1.4","2.1.6","2.1.7","2.1.8","2.1.9","2.2.0","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","2.5.0","2.5.1","2.5.2","2.5.3","2.6.0","2.7.5"],"block_files":[],"assets_screenshots":{"screenshot-1.gif":{"filename":"screenshot-1.gif","revision":3516680,"resolution":"1","location":"assets","locale":"","width":960,"height":648},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3516680,"resolution":"10","location":"assets","locale":"","width":641,"height":732},"screenshot-11.png":{"filename":"screenshot-11.png","revision":3516680,"resolution":"11","location":"assets","locale":"","width":1043,"height":959},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3516680,"resolution":"2","location":"assets","locale":"","width":1366,"height":1063},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3516680,"resolution":"3","location":"assets","locale":"","width":1059,"height":635},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3516680,"resolution":"4","location":"assets","locale":"","width":1229,"height":1086},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3516680,"resolution":"5","location":"assets","locale":"","width":1062,"height":910},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3516680,"resolution":"6","location":"assets","locale":"","width":1389,"height":554},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3516680,"resolution":"7","location":"assets","locale":"","width":1359,"height":858},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3516680,"resolution":"8","location":"assets","locale":"","width":1452,"height":807},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3516680,"resolution":"9","location":"assets","locale":"","width":1052,"height":1022}},"screenshots":{"1":"Quick tour of all eight modules - Hide Login, Hardening, 2FA setup with QR code, Incidents drill-down, Activity Log, Events, and Overview dashboard.","2":"Overview dashboard - health cards, security pulse, live event tail, threat banner that surfaces active attacks.","3":"Incidents - real-time pattern detection grouped by attack class with severity and one-click resolution.","4":"Incident drill-down - full timeline, user-agent fingerprint, suggested actions, escalation flag.","5":"Events - complete login attempts log with filters and CSV export.","6":"Activity Log - admin action audit trail across seven domains, filterable and exportable.","7":"Settings - modular configuration with live security score and a sticky save bar.","8":"Hide Login pre-activation modal - pick or generate the secret URL and email it to yourself before flipping the switch.","9":"Hardening - thirteen one-click toggles grouped by surface reduction, credential hardening, and request filtering.","10":"Two-factor authentication setup - QR code for any authenticator app, copy-paste fallback, and live verification.","11":"Breach Check - fully transparent k-anonymity lookups, separate password and email toggles, opt-in email check disabled by default."}},"plugin_section":[262246],"plugin_tags":[8531,2439,25642,4552,1229],"plugin_category":[],"plugin_contributors":[192025],"plugin_business_model":[],"class_list":["post-301525","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-activity-log","plugin_tags-brute-force","plugin_tags-hide-login","plugin_tags-limit-login","plugin_tags-login-security","plugin_contributors-wpformation","plugin_committers-wpformation","plugin_support_reps-fabriceducarme"],"banners":{"banner":"https:\/\/ps.w.org\/login-armor\/assets\/banner-772x250.png?rev=3517031","banner_2x":"https:\/\/ps.w.org\/login-armor\/assets\/banner-1544x500.png?rev=3517031","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/login-armor\/assets\/icon-128x128.png?rev=3517031","icon_2x":"https:\/\/ps.w.org\/login-armor\/assets\/icon-256x256.png?rev=3517031","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-1.gif?rev=3516680","caption":"Quick tour of all eight modules - Hide Login, Hardening, 2FA setup with QR code, Incidents drill-down, Activity Log, Events, and Overview dashboard."},{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-2.png?rev=3516680","caption":"Overview dashboard - health cards, security pulse, live event tail, threat banner that surfaces active attacks."},{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-3.png?rev=3516680","caption":"Incidents - real-time pattern detection grouped by attack class with severity and one-click resolution."},{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-4.png?rev=3516680","caption":"Incident drill-down - full timeline, user-agent fingerprint, suggested actions, escalation flag."},{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-5.png?rev=3516680","caption":"Events - complete login attempts log with filters and CSV export."},{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-6.png?rev=3516680","caption":"Activity Log - admin action audit trail across seven domains, filterable and exportable."},{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-7.png?rev=3516680","caption":"Settings - modular configuration with live security score and a sticky save bar."},{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-8.png?rev=3516680","caption":"Hide Login pre-activation modal - pick or generate the secret URL and email it to yourself before flipping the switch."},{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-9.png?rev=3516680","caption":"Hardening - thirteen one-click toggles grouped by surface reduction, credential hardening, and request filtering."},{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-10.png?rev=3516680","caption":"Two-factor authentication setup - QR code for any authenticator app, copy-paste fallback, and live verification."},{"src":"https:\/\/ps.w.org\/login-armor\/assets\/screenshot-11.png?rev=3516680","caption":"Breach Check - fully transparent k-anonymity lookups, separate password and email toggles, opt-in email check disabled by default."}],"raw_content":"<!--section=description-->\n<p>\ud83c\uddeb\ud83c\uddf7 <strong>Fully translated into French. Interface et documentation int\u00e9gralement disponibles en fran\u00e7ais.<\/strong><\/p>\n\n<p><strong>Thirteen security modules. One lightweight plugin. No premium tier.<\/strong><\/p>\n\n<p>Login Armor protects WordPress login, accounts and administration with thirteen independent modules. It is built for agencies, freelancers and site owners who want practical security, clear evidence and safe defaults without a remote dashboard, bundled telemetry or upsells.<\/p>\n\n<h4>Why Login Armor<\/h4>\n\n<ul>\n<li><strong>Complete and free:<\/strong> every module is included under the GPL.<\/li>\n<li><strong>Lightweight:<\/strong> modules load only when needed and normal login checks add less than 2 ms on a typical setup.<\/li>\n<li><strong>Private by default:<\/strong> data stays on your site. Optional external calls are disabled until you enable the related feature.<\/li>\n<li><strong>Ready for real sites:<\/strong> multisite support, reverse-proxy controls, WP-CLI commands and production-safe defaults.<\/li>\n<\/ul>\n\n<h4>Thirteen security modules<\/h4>\n\n<ol>\n<li><strong>Hide Login:<\/strong> replace <code>wp-login.php<\/code> with a private slug and return a 404 or redirect blocked visitors to a chosen URL.<\/li>\n<li><strong>Brute Force Protection:<\/strong> escalating lockouts, subnet blocking, trusted proxy headers and coverage for login, password recovery, registration, XML-RPC and REST users.<\/li>\n<li><strong>Hardening:<\/strong> sixteen controls for XML-RPC, pingbacks, file editing, version exposure, application passwords, author enumeration, reserved usernames, honeypots, new-admin alerts and forcing HTTPS.<\/li>\n<li><strong>Two-Factor Authentication:<\/strong> TOTP, email codes, backup codes, trusted devices, per-role enforcement, grace periods and recovery.<\/li>\n<li><strong>Detection and Incidents:<\/strong> group raw events into attack patterns with severity, timelines, source IPs, targeted users and one-click actions.<\/li>\n<li><strong>Activity Log:<\/strong> tamper-evident admin audit trail with filters, CSV export, retention controls and optional signed SIEM forwarding.<\/li>\n<li><strong>Security Headers:<\/strong> CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options for login and lockout pages, with optional site-wide baseline headers.<\/li>\n<li><strong>Breach Check:<\/strong> privacy-preserving Have I Been Pwned password checks and an optional XposedOrNot email check.<\/li>\n<li><strong>Password Policy:<\/strong> length and character rules, username exclusion, breached-password rejection and optional non-locking expiration reminders.<\/li>\n<li><strong>Session Management:<\/strong> idle timeout, maximum lifetime, optional single-device access and one-click revocation of other sessions.<\/li>\n<li><strong>IP Geolocation:<\/strong> cached country lookup for IPs shown in Incidents and Events, with private ranges excluded.<\/li>\n<li><strong>Request Firewall:<\/strong> optional, monitor-first filtering of malicious paths, query strings and HTTP methods, with administrator exclusions and IP\/path allowlists.<\/li>\n<li><strong>Bot Challenge:<\/strong> an invisible proof-of-work the browser solves before the login form is accepted, an alternative to CAPTCHAs with no external service; monitor-first, then enforce.<\/li>\n<\/ol>\n\n<h4>Additional tools<\/h4>\n\n<p>Login Armor also includes guided onboarding, a 0-100 security score, conflict detection, email\/Slack\/Discord\/webhook notifications, an optional weekly or monthly security digest, eight Tools &gt; Site Health tests with a support panel, a dashboard widget and a complete WP-CLI suite. A safe mode constant in wp-config.php stands down every protection that could lock an administrator out, without changing a single setting.<\/p>\n\n<p>The guided safe baseline turns on brute-force protection, attack detection, login-page security headers, the activity log, the seven safest hardening toggles, and the request firewall and bot challenge in monitor mode, where they record without blocking anything. Hide Login and two-factor stay off so you enable them deliberately. After seven days of monitoring, Login Armor reads your own traffic and tells you whether the firewall and the bot challenge can safely start blocking.<\/p>\n\n<p>The optional AI Security Briefing uses your own WordPress AI connector to explain a thirty-day security snapshot or a single incident. It always starts with deterministic facts, works without AI and sends nothing until an administrator explicitly requests an analysis.<\/p>\n\n<p>GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies.<\/p>\n\n\n\n<p><strong>Treize modules de s\u00e9curit\u00e9. Une seule extension l\u00e9g\u00e8re. Aucune version premium.<\/strong><\/p>\n\n<p>Login Armor prot\u00e8ge la connexion, les comptes et l'administration de WordPress gr\u00e2ce \u00e0 treize modules ind\u00e9pendants. L'extension s'adresse aux agences, freelances et propri\u00e9taires de sites qui veulent une s\u00e9curit\u00e9 concr\u00e8te, des preuves lisibles et des r\u00e9glages s\u00fbrs, sans tableau de bord distant, t\u00e9l\u00e9m\u00e9trie impos\u00e9e ni upsell.<\/p>\n\n<h4>Pourquoi Login Armor<\/h4>\n\n<ul>\n<li><strong>Complet et gratuit :<\/strong> tous les modules sont inclus sous licence GPL.<\/li>\n<li><strong>L\u00e9ger :<\/strong> les modules se chargent uniquement lorsque n\u00e9cessaire et les contr\u00f4les ajoutent moins de 2 ms sur une connexion normale.<\/li>\n<li><strong>Priv\u00e9 par d\u00e9faut :<\/strong> les donn\u00e9es restent sur votre site. Les appels externes optionnels sont d\u00e9sactiv\u00e9s tant que vous n'activez pas la fonction concern\u00e9e.<\/li>\n<li><strong>Pr\u00eat pour la production :<\/strong> multisite, reverse proxies, commandes WP-CLI et r\u00e9glages par d\u00e9faut s\u00e9curis\u00e9s.<\/li>\n<\/ul>\n\n<h4>Treize modules de s\u00e9curit\u00e9<\/h4>\n\n<ol>\n<li><strong>Masquer la connexion :<\/strong> remplace <code>wp-login.php<\/code> par un slug priv\u00e9 et renvoie une 404 ou redirige les visiteurs bloqu\u00e9s vers l'URL choisie.<\/li>\n<li><strong>Protection contre la force brute :<\/strong> verrouillages progressifs, blocage de sous-r\u00e9seaux, proxies de confiance et protection de la connexion, r\u00e9cup\u00e9ration, inscription, XML-RPC et REST users.<\/li>\n<li><strong>Renforcement :<\/strong> quinze contr\u00f4les pour XML-RPC, les pingbacks, l'\u00e9diteur de fichiers, la version, les mots de passe applicatifs, l'\u00e9num\u00e9ration d'auteurs, les identifiants r\u00e9serv\u00e9s, le pot de miel et les alertes nouvel administrateur.<\/li>\n<li><strong>Authentification \u00e0 deux facteurs :<\/strong> TOTP, codes par e-mail, codes de secours, appareils de confiance, application par r\u00f4le, p\u00e9riode de gr\u00e2ce et r\u00e9cup\u00e9ration.<\/li>\n<li><strong>D\u00e9tection et incidents :<\/strong> regroupe les \u00e9v\u00e9nements en sc\u00e9narios d'attaque avec s\u00e9v\u00e9rit\u00e9, chronologie, IP sources, comptes cibl\u00e9s et actions imm\u00e9diates.<\/li>\n<li><strong>Journal d'activit\u00e9 :<\/strong> piste d'audit admin infalsifiable avec filtres, export CSV, r\u00e9tention et transfert SIEM sign\u00e9 optionnel.<\/li>\n<li><strong>En-t\u00eates de s\u00e9curit\u00e9 :<\/strong> CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy et X-Content-Type-Options pour les pages de connexion et de verrouillage, avec en-t\u00eates de base optionnels sur tout le site.<\/li>\n<li><strong>D\u00e9tection de fuites :<\/strong> v\u00e9rification confidentielle des mots de passe via Have I Been Pwned et contr\u00f4le optionnel des e-mails via XposedOrNot.<\/li>\n<li><strong>Politique de mot de passe :<\/strong> longueur, classes de caract\u00e8res, exclusion de l'identifiant, rejet des mots de passe compromis et rappels d'expiration non bloquants.<\/li>\n<li><strong>Gestion des sessions :<\/strong> d\u00e9lai d'inactivit\u00e9, dur\u00e9e maximale, acc\u00e8s limit\u00e9 \u00e0 un appareil et r\u00e9vocation des autres sessions.<\/li>\n<li><strong>G\u00e9olocalisation IP :<\/strong> pays des IP affich\u00e9es dans Incidents et \u00c9v\u00e9nements, avec cache et exclusion des plages priv\u00e9es.<\/li>\n<li><strong>Pare-feu de requ\u00eates :<\/strong> filtrage optionnel, d'abord en surveillance, des chemins, requ\u00eates et m\u00e9thodes HTTP malveillants, avec exclusion des administrateurs et listes d'autorisation IP\/chemins.<\/li>\n<li><strong>D\u00e9fi anti-bot :<\/strong> une preuve de calcul invisible r\u00e9solue par le navigateur avant validation du formulaire de connexion, alternative aux CAPTCHA sans service externe ; d'abord en surveillance, puis en blocage.<\/li>\n<\/ol>\n\n<h4>Outils compl\u00e9mentaires<\/h4>\n\n<p>Login Armor inclut aussi un assistant de configuration, un score de s\u00e9curit\u00e9 de 0 \u00e0 100, la d\u00e9tection de conflits, les notifications par e-mail, Slack, Discord ou webhook, un widget de tableau de bord et une suite WP-CLI compl\u00e8te.<\/p>\n\n<p>La base s\u00fbre guid\u00e9e active la protection contre la force brute, la d\u00e9tection d'attaques, les en-t\u00eates de s\u00e9curit\u00e9 de la page de connexion, le journal d'activit\u00e9, les sept r\u00e9glages de renforcement les plus s\u00fbrs, ainsi que le pare-feu de requ\u00eates et le d\u00e9fi anti-bot en mode surveillance, o\u00f9 ils enregistrent sans rien bloquer. Hide Login et la double authentification restent d\u00e9sactiv\u00e9s pour que vous les activiez d\u00e9lib\u00e9r\u00e9ment. Au bout de sept jours de surveillance, Login Armor lit votre trafic r\u00e9el et vous dit si le pare-feu et le d\u00e9fi anti-bot peuvent passer au blocage sans risque.<\/p>\n\n<p>Le briefing de s\u00e9curit\u00e9 IA optionnel utilise votre propre connecteur IA WordPress pour expliquer les trente derniers jours ou un incident pr\u00e9cis. Il commence toujours par des faits d\u00e9terministes, fonctionne sans IA et n'envoie rien tant qu'un administrateur ne demande pas explicitement une analyse.<\/p>\n\n<h4>Con\u00e7u par<\/h4>\n\n<p>Login Armor est con\u00e7u et maintenu par Fabrice Ducarme de <a href=\"https:\/\/wpformation.com\/login-armor\/\">WPFormation<\/a>. Nous l'utilisons sur chaque site que nous livrons.<\/p>\n\n<ul>\n<li><a href=\"https:\/\/wpformation.com\/login-armor\/\">Pr\u00e9sentation et fonctionnement de Login Armor<\/a><\/li>\n<li><a href=\"https:\/\/wpformation.com\/securite-wordpress\/\">Guides de s\u00e9curit\u00e9 WordPress<\/a> sur WPFormation<\/li>\n<li><a href=\"https:\/\/wpformation.com\/outils\/veille-securite\/\">Veille des vuln\u00e9rabilit\u00e9s WordPress<\/a> sur WPFormation<\/li>\n<\/ul>\n\n<p>GPL pour toujours. PHP 8.1+. WordPress 6.8+. Z\u00e9ro d\u00e9pendance.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>Login Armor has no telemetry and requires no Login Armor account. The following services are contacted only when WordPress itself or an administrator enables the related feature.<\/p>\n\n<h4>WordPress AI connector (optional)<\/h4>\n\n<p>The AI Security Briefing sends a security prompt through the administrator's own WordPress AI connector only after they click an analysis button. Minimised mode sends counts, categories, severities and role buckets without clear IP addresses or usernames. Explicit deep mode also sends IP addresses and event details. Login Armor stores no provider API key. The selected AI provider's terms and privacy policy apply.<\/p>\n\n<h4>Slack, Discord or custom webhook (optional)<\/h4>\n\n<p>When an administrator enables an incident notification channel, Login Armor sends the incident type, severity, IP address, target username, event count and site URL to the configured endpoint. The separate signed Activity Log forwarding option sends the event, object, user ID\/login\/role, IP address, description, integrity hashes, site URL and plugin version to the administrator's SIEM or custom webhook.<\/p>\n\n<ul>\n<li><strong>Slack:<\/strong> <a href=\"https:\/\/slack.com\/terms-of-service\">Terms<\/a> | <a href=\"https:\/\/slack.com\/privacy-policy\">Privacy<\/a><\/li>\n<li><strong>Discord:<\/strong> <a href=\"https:\/\/discord.com\/terms\">Terms<\/a> | <a href=\"https:\/\/discord.com\/privacy\">Privacy<\/a><\/li>\n<li><strong>Custom webhook:<\/strong> terms and privacy are controlled by the administrator's chosen endpoint.<\/li>\n<\/ul>\n\n<h4>Gravatar<\/h4>\n\n<p>The Activity Log uses WordPress core's <code>get_avatar()<\/code>. If avatars are enabled in WordPress, a hashed email address may be sent to Gravatar to retrieve the image.<\/p>\n\n<ul>\n<li><strong>Gravatar:<\/strong> <a href=\"https:\/\/automattic.com\/tos\/\">Terms<\/a> | <a href=\"https:\/\/automattic.com\/privacy\/\">Privacy<\/a><\/li>\n<\/ul>\n\n<h4>Have I Been Pwned (optional)<\/h4>\n\n<p>Breach Check and the optional compromised-password policy send only the first 5 characters of a password's SHA-1 hash to the Pwned Passwords API. The password and full hash never leave the site. Checks fail soft if the service is unavailable. Public registration and password-reset validation do not call the service; authenticated checks remain active.<\/p>\n\n<ul>\n<li><strong>Have I Been Pwned:<\/strong> <a href=\"https:\/\/haveibeenpwned.com\/Privacy\">Privacy<\/a> | <a href=\"https:\/\/haveibeenpwned.com\/AcceptableUse\">Acceptable Use<\/a><\/li>\n<\/ul>\n\n<h4>XposedOrNot (optional)<\/h4>\n\n<p>The separate Email check, disabled by default, sends the user's email address and a plugin-identifying User-Agent to XposedOrNot when a user is created or changes email.<\/p>\n\n<ul>\n<li><strong>XposedOrNot:<\/strong> <a href=\"https:\/\/xposedornot.com\/\">Service<\/a> | <a href=\"https:\/\/xposedornot.com\/privacy.html\">Privacy<\/a><\/li>\n<\/ul>\n\n<h4>ipwho.is (optional)<\/h4>\n\n<p>IP Geolocation sends public IP addresses recorded in the login log or in an incident to ipwho.is, in a background task: at most 20 addresses every five minutes, and no request is made while an admin page is being rendered. There is no request at all for five minutes after an API failure, and the free tier of the API allows 1000 requests a day per site, after which it asks for a pause that the plugin honours. Results are cached for 30 days, and so is an answer that carries no country. Private and reserved ranges are never sent, and developers can replace the lookup through the <code>login_armor_geoip_lookup<\/code> filter. The compromise: the background task is a WordPress scheduled event, so on a site where WP-Cron is disabled and no system cron calls wp-cron.php, the country badges stay empty.<\/p>\n\n<ul>\n<li><strong>ipwho.is:<\/strong> <a href=\"https:\/\/ipwho.is\/\">Service<\/a> | <a href=\"https:\/\/ipwhois.io\/documentation\">Documentation<\/a><\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>login-armor<\/code> directory to <code>\/wp-content\/plugins\/<\/code><\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress<\/li>\n<li>Go to LoginArmor in the admin menu to configure<\/li>\n<\/ol>\n\n<p>For multisite: Network Activate the plugin to apply it across all sites.<\/p>\n\n<h4>Setting up Hide Login<\/h4>\n\n<ol>\n<li>Go to LoginArmor &gt; Settings &gt; Hide Login section<\/li>\n<li>Enter your desired login slug (e.g., <code>my-login<\/code>)<\/li>\n<li>Save settings<\/li>\n<li><strong>Bookmark your new login URL<\/strong>: you will need it to access your admin<\/li>\n<\/ol>\n\n<h4>Recovering access<\/h4>\n\n<p>If you forget your custom login URL:<\/p>\n\n<ul>\n<li>Use the recovery email feature (configurable in settings)<\/li>\n<li>Connect to your database and delete the <code>login_armor_hide_slug<\/code> row from the <code>wp_options<\/code> table<\/li>\n<li>Use WP-CLI: <code>wp option delete login_armor_hide_slug<\/code><\/li>\n<li>Run <code>wp login-armor rescue<\/code> from your server shell: it lists every way back in, and changes nothing until you add <code>--yes<\/code><\/li>\n<li>Last resort, safe mode: add <code>define( 'LOGIN_ARMOR_SAFE_MODE', true );<\/code> to <code>wp-config.php<\/code>. <code>wp-login.php<\/code> is served again, two-factor is not required, the request firewall and the bot challenge only log, single-session enforcement pauses, and Force HTTPS enforces nothing. Your settings are untouched, brute-force lockouts stay active, and everything comes back the moment you delete the line.<\/li>\n<\/ul>\n\n<p>If Force HTTPS was switched on by mistake and the site cannot answer over TLS:<\/p>\n\n<ul>\n<li>Use WP-CLI: <code>wp option patch update login_armor_hardening force_https false<\/code> (write <code>false<\/code> or <code>0<\/code>, nothing else: WordPress reads <code>off<\/code> and <code>no<\/code> as ON)<\/li>\n<li>Or, if you cannot reach a shell, stand it down without changing the setting: add <code>define( 'LOGIN_ARMOR_SAFE_MODE', true );<\/code> to <code>wp-config.php<\/code>. All four effects stop at once, the toggle keeps saying what you chose, and enforcement comes back on the first request after you delete the line.<\/li>\n<\/ul>\n\n<h4>Turning Force HTTPS off: what changes<\/h4>\n\n<p>If the proxy in front of your site starts reporting HTTPS from an address that is not in your Trusted proxy IPs, Force HTTPS <strong>stands down entirely<\/strong>: no redirect, no admin over SSL, no Secure cookies, nothing enforced at all, until you declare that proxy. That is deliberate. On a site whose proxy cannot be verified, each one of those three is a way to lock you out: the redirect loops, WordPress's own admin redirect loops, and the authentication cookie gets written under a name WordPress will not read back, so nobody can stay signed in. The plugin says so in the admin while it lasts, and everything comes back by itself on the first request after you declare the proxy.<\/p>\n\n<p>That notice shows you the address it saw, and it is an observation, not an instruction. Any visitor can make it appear by sending one header, so never add an address to Trusted proxy IPs because it appeared there: ask your host or your CDN which address their terminator uses, and add only that one. An address on that list is believed when it tells Login Armor who your visitors are, which is what every lockout and ban depends on. If the notice says several different addresses have sent that header, that is forgery rather than a proxy you forgot to declare.<\/p>\n\n<p>Switching Force HTTPS on or off changes whether WordPress reads your session from its secure cookie or its ordinary one, so you may be asked to sign in again right after the change. That is normal, and it is the same thing WordPress does on its own when you move your site address to https.<\/p>\n\n<p>Turning the toggle off removes exactly what Login Armor added: its HTTP to HTTPS redirect, its call to <code>force_ssl_admin()<\/code>, the Secure flag it put on the two authentication cookies, and the fact that a request forwarded by one of your declared proxies counted as HTTPS for the length of that request. It changes nothing else.<\/p>\n\n<p>Two things it cannot take back, because they were never a setting of this plugin. If your site sends a <code>Strict-Transport-Security<\/code> header, this option is what made that header effective behind a proxy, and every browser that already received it keeps the pin for the header's own duration, with the option on or off. And the redirect itself is sent with no-cache headers so that a CDN or a page cache does not keep serving it, but a cache that ignores those headers may still need to be purged. Your site address, your <code>.htaccess<\/code>, the <code>FORCE_SSL_ADMIN<\/code> constant in <code>wp-config.php<\/code> and any <code>Strict-Transport-Security<\/code> header stay exactly as they were. So if WordPress still sends the admin to https after you switch the toggle off, it is because the site address is already an <code>https:\/\/<\/code> one or because <code>FORCE_SSL_ADMIN<\/code> is defined in <code>wp-config.php<\/code>, and neither of those belongs to this plugin.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20it%20lock%20me%20out%20of%20my%20own%20site%3F\"><h3>Will it lock me out of my own site?<\/h3><\/dt>\n<dd><p>Hide Login cannot: it always sends a one-time recovery URL to the admin email, so if you lose the slug, check your inbox. The plugin also honors <code>wp-cli<\/code> so you can reset any of it from SSH, and <code>wp login-armor rescue<\/code> prints every way back in without changing anything.<\/p>\n\n<p>One option can, and it says so on its own row: Force HTTPS. It is off by default, it is never switched on by the safe baseline, and the plugin refuses to switch it on from a connection that is not already HTTPS. It also stands down by itself, and tells you so in the admin, if the proxy in front of your site starts reporting HTTPS from an address you have not listed in Trusted proxy IPs, which is what happens when a CDN or a load balancer changes address. If you still end up locked out, one command puts it back: <code>wp option patch update login_armor_hardening force_https false<\/code>.<\/p>\n\n<p>If you cannot reach a shell either, there is a break-glass switch: add <code>define( 'LOGIN_ARMOR_SAFE_MODE', true );<\/code> to <code>wp-config.php<\/code>. <code>wp-login.php<\/code> answers again, the second factor is not demanded, the request firewall and the bot challenge drop back to logging only, and Force HTTPS stops enforcing all four of its effects, without any setting being rewritten. It is a constant and not an option, so it cannot be flipped from the database, and it is read once, while the plugin file loads: only code that runs before that can arm it, which means <code>wp-config.php<\/code>, a must-use plugin, or a plugin that loads earlier. A theme, or anything running on a WordPress hook, cannot, because by then the answer is already fixed. Brute-force lockouts are deliberately left running: clear your own address from the admin notice, or with <code>wp login-armor rescue --ip=&lt;your ip&gt; --yes<\/code>. Delete the line to restore full protection.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20my%20site%20down%3F\"><h3>Does it slow my site down?<\/h3><\/dt>\n<dd><p>No. Everything is lazy-loaded and indexed. On a normal login flow the extra SQL cost is under 2 ms.<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20cloudflare%20%2F%20reverse%20proxies%3F\"><h3>Is it compatible with Cloudflare \/ reverse proxies?<\/h3><\/dt>\n<dd><p>Yes. Choose the proxy header in Settings and list the exact IP addresses or CIDR ranges of the proxies that are allowed to supply it. Forwarding headers are ignored when the immediate network peer is not explicitly trusted.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20multisite%3F\"><h3>Does it work with multisite?<\/h3><\/dt>\n<dd><p>Yes, subdomain and subfolder. Each site has its own modules, logs, and thresholds.<\/p><\/dd>\n<dt id=\"can%20i%20use%20loginarmor%20alongside%20wordfence%20%2F%20ithemes%20security%20%2F%20solid%20security%3F\"><h3>Can I use LoginArmor alongside Wordfence \/ iThemes Security \/ Solid Security?<\/h3><\/dt>\n<dd><p>Yes, but disable overlapping modules on one side to avoid double lockouts.<\/p><\/dd>\n<dt id=\"where%20is%20the%20data%20stored%3F\"><h3>Where is the data stored?<\/h3><\/dt>\n<dd><p>Three custom tables in your own database: events, incidents, activity. Nothing leaves your server.<\/p><\/dd>\n<dt id=\"how%20do%20i%20copy%20my%20configuration%20to%20another%20site%3F\"><h3>How do I copy my configuration to another site?<\/h3><\/dt>\n<dd><p>Settings &gt; Export downloads every setting as a JSON file (webhook URLs only if you tick the box; the SIEM signing secret and users' two-factor enrolments never leave the site). On the other site, Settings &gt; Import shows you every change first and applies nothing until you confirm. From the command line: <code>wp login-armor settings export --file=model.json<\/code>, then <code>wp login-armor settings import model.json --dry-run<\/code> and <code>--yes<\/code>. One invalid value refuses the whole file, and a firewall or bot challenge switched on by import always starts in monitor mode.<\/p><\/dd>\n<dt id=\"what%20are%20the%20.htaccess.login-armor.bak%20and%20.htaccess.login-armor.lock%20files%3F\"><h3>What are the .htaccess.login-armor.bak and .htaccess.login-armor.lock files?<\/h3><\/dt>\n<dd><p>They sit next to a <code>.htaccess<\/code> file that Login Armor writes into, in <code>wp-content\/uploads<\/code> or at the root of the site. The <code>.bak<\/code> file is your restore point: a copy of the file as it was, taken once before the very first change and never overwritten afterwards. The <code>.lock<\/code> file is empty; it exists only to stop two requests writing the same file at the same moment. Both names start with <code>.ht<\/code>, so a web server configured for WordPress never serves them to a visitor. Both are deliberately left in place when you uninstall the plugin: a backup that disappears with the plugin is not a backup.<\/p><\/dd>\n<dt id=\"is%20there%20a%20pro%20version%3F\"><h3>Is there a pro version?<\/h3><\/dt>\n<dd><p>Not currently. LoginArmor is fully free and open source. GPL forever.<\/p><\/dd>\n<dt id=\"where%20can%20i%20report%20bugs%20or%20request%20features%3F\"><h3>Where can I report bugs or request features?<\/h3><\/dt>\n<dd><p>Support forum: <a href=\"https:\/\/wordpress.org\/support\/plugin\/login-armor\/\">wordpress.org\/support\/plugin\/login-armor\/<\/a>.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<p>The three most recent releases are summarised here, because wordpress.org shows at most 5000 characters and silently truncates the rest. The complete history, with the reasoning behind each fix, is in CHANGELOG.md in the plugin's repository.<\/p>\n\n<h4>2.7.5<\/h4>\n\n<p>Removes the dashed segment 2.7.3 added to the activity chart, along with the mistaken reasoning behind it.<\/p>\n\n<ul>\n<li>Fixed - The activity chart no longer breaks off near its right-hand edge. 2.7.3 drew the final segment dashed and detached, on the belief that the last bucket was the clock hour in progress and therefore incomplete. That belief was wrong: the chart groups events into rolling sixty-minute windows counted back from the present moment, so every bucket is a whole hour, the last one included. There was nothing to mark, and marking it produced a gap and a floating stub with no legend anywhere to explain either. Readers took it for missing data, which is exactly what it looked like. The curve is now one continuous line across all twenty-four points, and the shaded area is derived from that same line so the two can never disagree again.<\/li>\n<\/ul>\n\n<h4>2.7.4<\/h4>\n\n<p>Two defects. The first was reported by the plugin's own author from a screenshot of his dashboard; the second was found by walking the real 2.6.0 to 2.7.4 upgrade path on a live site.<\/p>\n\n<ul>\n<li><p>Fixed - For the first second and a half after the Overview loaded, the activity chart contradicted itself. The line was drawn in progressively, which is the effect it has always had, but the shaded area beneath it and the dashed segment for the hour in progress were both painted whole on the very first frame. So until the line caught up there was a filled hump with no curve on it, and a dashed stub attached to nothing: read as data, that is a hole in the series, and it is what the screenshot showed. The area and the dashed segment now follow the line instead of preceding it, which is what the dashboard widget's own sparkline already did. Nothing about the finished chart changes.<\/p><\/li>\n<li><p>Fixed - The Activity Log's nightly purge never came back if it went missing. WordPress rewrites the whole cron option from an array read earlier in the request, with no compare-and-swap, so two concurrent requests drop each other's events; 2.6.1 added a daily repair for exactly that reason, but the repair only knows the events declared in one function, and this one was created when the module was switched on and nowhere else. A site that lost it kept recording rows and stopped deleting them, silently and for good, unless an administrator happened to re-save those settings. Found by walking the real 2.6.0 to 2.7.4 upgrade path on a live site, which had not been done before.<\/p><\/li>\n<\/ul>\n\n<h4>2.7.3<\/h4>\n\n<p>Two defects found by the plugin's own author while using it, one of them the worst thing a security plugin can do: accuse its owner of something that never happened.<\/p>\n\n<ul>\n<li>Fixed - Activity Log Integrity reported TAMPERED on a site where nothing had been tampered with. The nightly retention purge deletes rows older than your retention period, which is what it is for, but verification still started from the first row ever written and met a row whose predecessor had been deleted months earlier. Every site that keeps this module on for longer than its retention window reached that state. Verification now starts from the oldest row that still exists, and says so. A real edit to any surviving row is still detected.<\/li>\n<li>Fixed - The activity chart was stretched to whatever height its card happened to have, so every slope was exaggerated by that much: measured at 1.63 times too tall. It now keeps its own proportions. The three unlabelled gridlines, which implied a scale that was never shown, are replaced by one line drawn at the busiest hour with that hour's count beside it. The hour in progress is dashed, because it holds minutes rather than an hour and a solid line down to it read as a collapse in activity that had not happened.<\/li>\n<\/ul>","raw_excerpt":"Thirteen security modules + AI briefing: hide login, request firewall, brute force, 2FA, password policy, sessions, hardening, audit log. No upsells.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/301525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=301525"}],"author":[{"embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wpformation"}],"wp:attachment":[{"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=301525"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=301525"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=301525"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=301525"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=301525"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/en-gb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=301525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}