بازدان بۆ ناوەڕۆک
WordPress.org

وۆردپرێس بەکوردی

  • ڕووکارەکان
  • پێوەکراوەکان
  • دەربارە
  • وۆردپرێس بە دەستبێنە
وۆردپرێس بە دەستبێنە
WordPress.org

Plugin Directory

DCI Admin Security

  • پێوەکراوێک بڵاوبکەرەوە
  • دڵخوازەکانم
  • Log in
  • پێوەکراوێک بڵاوبکەرەوە
  • دڵخوازەکانم
  • Log in

DCI Admin Security

لەلایەن DreamCode Infotech
داگرتن
  • وردەکارییەکان
  • پێداچوونەوەکان
  • دامەزراندن
  • گەشەپێدان
پشتیوانی

وەسف

Protect WordPress login and wp-admin with IP allowlisting, custom login URLs, email OTP, rate limiting, CAPTCHA, logging and alerts.

Features

  • Allow exact IPv4/IPv6 addresses and CIDR ranges.
  • Accept IPv4 shorthand such as 171.61, stored as 171.61.0.0/16.
  • Change the WordPress login URL.
  • Protect the normal wp-login.php endpoint.
  • Restrict wp-admin by IP while keeping admin-ajax.php available.
  • Optional Cloudflare CF-Connecting-IP detection.
  • Optional trusted X-Forwarded-For detection for known reverse-proxy setups.
  • Optional localhost/loopback bypass for local development.
  • Brute-force rate limiting and temporary lockouts.
  • Email OTP verification for administrators, delivered to each administrator’s WordPress profile email address.
  • Administrator-configured emergency fallback code for environments where email cannot be delivered.
  • Optional Google reCAPTCHA v2, reCAPTCHA v3 or hCaptcha on the WordPress login form.
  • Security event logging with an administrator viewer and configurable retention.
  • Optional email and Slack alerts for repeated blocked-IP or brute-force events.

Important

Keep at least one known administrator IP in the allowlist before enabling IP protection.

Only enable Cloudflare IP detection when the site is actually behind Cloudflare. Only enable trusted X-Forwarded-For when the server is behind a trusted reverse proxy that sets that header.

On localhost, PHP commonly sees 127.0.0.1 or ::1 rather than the browser’s public VPN address. Use a publicly reachable staging site for an end-to-end VPN IP test.

The emergency fallback code is stored as a password hash and is never displayed after saving.

External Services

This plugin can optionally communicate with third-party CAPTCHA verification services when CAPTCHA is enabled:

  • Google reCAPTCHA: the login page loads Google reCAPTCHA assets and sends the submitted CAPTCHA token to Google’s verification endpoint. See https://policies.google.com/privacy and https://policies.google.com/terms.
  • hCaptcha: the login page loads hCaptcha assets and sends the submitted CAPTCHA token to hCaptcha’s verification endpoint. See https://www.hcaptcha.com/privacy and https://www.hcaptcha.com/terms.

The plugin does not contact these services when CAPTCHA is disabled.

IP access examples

Exact IP: 186.189.26.220

IPv4 /16 shorthand: 171.61

CIDR: 171.61.0.0/16

Email OTP

After a successful WordPress administrator password check, a six-digit OTP is generated and sent to that administrator’s WordPress profile email address.

If email delivery is unavailable, an administrator-configured emergency fallback code can be used.

سکرین شۆتەکان

دامەزراندن

  1. Upload the plugin ZIP from Plugins > Add New > Upload Plugin.
  2. Activate DCI Admin Security.
  3. Open Settings > DCI Admin Security.
  4. Add at least one IP address or CIDR range that should be allowed to reach the protected login/admin area.
  5. Set the custom login slug.
  6. Save the General settings.
  7. Test the custom login URL before enabling strict IP protection on a production site.
  8. Configure Email OTP, CAPTCHA, rate limiting and alerts as required.

پێداچوونەوەکان

هیچ پێداچوونەوەیەک نەنووسراوە بۆ ئەم پێوەکراوە.

بەشداربووان و گەشەپێدەران

“DCI Admin Security” نەرمەواڵەیەکی سەرچاوە کراوەیە. ئەم کەسانەی خوارەوە بەشدارییان تێدا کردووە.

بەشداربووان
  • DreamCode Infotech

“DCI Admin Security” وەربگێڕە بۆ زمانەکەی خۆت.

دەتەوێت بەشداربیت لە گەشەپێدان؟

گەڕان لە کۆدەکەدا بکە، سەیری تەمارگەی (SVN) بکە، یان بەشداربە لە ڕووداوتۆماری گەشەپێدان لە ڕێگەی (RSS).

ڕووداوتۆمارگەریی گۆڕین

1.0.0

  • Resolved Plugin Check database-query and nonce warnings.
  • Sanitized emergency fallback-code input.
  • Added explicit versions to CAPTCHA provider scripts.
  • Kept IP allowlist, email OTP, and WordPress.org compatibility fixes from 1.0.0.

1.0.0

  • Removed the obsolete TOTP/two-factor authentication implementation and related files.
  • Fixed WordPress coding-standard issues in IP handling, AJAX actions, CAPTCHA output and custom database queries.
  • Added proper login CAPTCHA script enqueueing and a CAPTCHA nonce.
  • Improved PHP 7.4 compatibility by removing PHP 8-only string helper usage.
  • Updated documentation and feature list for the email OTP implementation.

2.4.10

  • Improved IP allowlist matching and localhost development controls.
  • Added IP diagnostics and test tools.

2.4.6

  • Added explicit trusted proxy handling for X-Forwarded-For.
  • Normalized IPv4-mapped IPv6 client addresses.

2.0.0

  • Added brute-force rate limiting, CAPTCHA, security logging and alerts.
  • Added administrator email OTP verification.

1.0.0

  • Initial release with IP allowlist and custom login URL protection.

مێتا

  • وەشان 1.0.0
  • دوایین بەڕۆژکردنەوە 3 ڕۆژ لەمەوبەر
  • دامەزراندنی چالاک کەمتر لە 10
  • وەشانی وۆردپرێس 6.0 یان بەرزتر
  • تاقیکراوەتەوە تا 7.1.2
  • وەشانی PHP 7.4 یان بەرزتر
  • زمان
    English (US)
  • تاگەکان
    admin securitycustom loginip whitelistlogin securitysecurity
  • بینینی پێشکەوتوو

هەڵسەنگاندنەکان

No reviews have been submitted yet.

Your review

بینینی هەموو پێداچوونەوەکان

بەشداربووان

  • DreamCode Infotech

پشتیوانی

هیچت هەیە بۆ وتن؟ پێویستت بە یارمەتییە؟

بینینی مەکۆی پاڵپشتی

ببەخشە

دەتەوێت پشتگیریی بەرەوپێشچوونی ئەم پێوەکراوە بکەیت؟

ببەخشە بەم پێوەکراوە

  • دەربارە
  • هەواڵەکان
  • خانەخوێکردن
  • تایبەتمەندێتی
  • پیشاندان
  • ڕووکاره‌کان
  • پێوه‌کراوه‌کان
  • شێوەئاساکان
  • فێربە
  • پاڵپشتی
  • گەشەپێدەران
  • WordPress.tv ↖
  • بەشداری بکە
  • بۆنەکان
  • بەخشین ↖
  • سواگ ↖
  • WordPress.com ↖
  • Matt ↖
  • bbPress ↖
  • BuddyPress ↖
WordPress.org
WordPress.org

وۆردپرێس بەکوردی

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • سەردانی هەژماری (Mastodon) بکە
  • Visit our Threads account
  • سەردانی پەڕەی فەیسبووکمان بکە
  • سەردانی هەژماری ئینستاگراممان بکە
  • سەردانی هەژماری لینکدئینمان بکە
  • Visit our TikTok account
  • سەردانی کەناڵەکەمان بکە لە یوتیوب
  • Visit our Tumblr account
کۆد هۆنراوەیە.
The WordPress® trademark is the intellectual property of the WordPress Foundation.