Description
Twelve security modules. One lightweight plugin. Zero compromise.
Login Armor is a complete WordPress security stack built for agencies, freelancers and pros who deliver audit-ready sites. No premium tier, no bundled marketing dashboard, no telemetry. Every module runs locally, ships with safe defaults, and stays out of your way.
Stop juggling Wordfence’s bloat, Solid Security’s upsells, and Limit Login Attemptsâ gaps â Login Armor delivers twelve independent modules in about one megabyte.
New in 2.4.0
- Request Firewall â an optional, 8G-inspired PHP filter that blocks malicious requests (SQL injection, code execution, traversal, XSS, disallowed HTTP methods) before WordPress finishes loading, on Apache, Nginx and LiteSpeed alike. Off by default, it starts in monitor mode and never filters logged-in administrators; every block is logged, aggregated to one incident per IP per hour.
- Guided onboarding â a first-run wizard offers a one-click âsafe baselineâ that turns on the no-risk essentials, so a beginner is protected in seconds. The same âApply safe baselineâ button stays available any time.
Why Login Armor
- No upsells, ever. No âpremiumâ tier, no greyed-out âProâ buttons. Every feature is GPL.
- No external services to sign up for. No API keys, no remote dashboards, no telemetry. The only outbound calls are opt-in: Have I Been Pwned (breach/password checks), Slack/Discord/webhook (notifications), the keyless ipwho.is API (geolocation), and your own WordPress 7 AI connector.
- Built to be invisible. Sub-megabyte ZIP, lazy-loaded modules, indexed queries â under 2 ms on a normal login flow.
- Multisite-aware, PHP 8.1-native, production-grade defaults. Network-activate a fleet, configure per-site, manage from a complete WP-CLI suite; zero-config gets you 80 percent of the protection.
Twelve independent modules
- Hide Login â Replace wp-login.php with a custom slug; the old URL returns a 404, and a branded pre-activation modal lets you pick or generate the slug and emails it to you so you can’t lock yourself out. Compatible with multisite, reverse proxies and password-recovery flows.
- Brute Force Protection â Cascading lockouts escalating to a 24-hour ban, with subnet blocking and trusted X-Forwarded-For; lostpassword, register, XML-RPC and the REST users endpoint are all gated when an IP is locked, and every lockout surfaces as an incident.
- Hardening â Fifteen one-click toggles across surface reduction, credential hardening, request filtering and account monitoring: disable XML-RPC/pingbacks, the file editor, version exposure, application passwords and author enumeration; block reserved usernames (Unicode-confusable detection); add a login honeypot; get alerted on new administrators.
- Two-Factor Authentication â TOTP, one-time codes by email and printable backup codes, with trusted devices for thirty days, per-role enforcement, a configurable grace period and an email recovery flow when the authenticator is lost.
- Detection and Incidents â A real-time engine groups raw events into six attack patterns, each with a drill-down (timeline, source IPs, target users, severity, UA fingerprint) and one-click actions (reset password, block subnet, mark resolved).
- Activity Log â A compliance-ready, tamper-evident (hash-chained) audit trail of admin actions across seven logger domains, with filtering, CSV export, configurable retention and optional signed webhook forwarding to a SIEM.
- Login Page Security Headers â Content-Security-Policy, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options on wp-login.php and the lockout page, in two presets with an optional CSP report-uri; baseline headers can optionally extend site-wide.
- Breach Check â Detect logins using a breached password via privacy-preserving k-anonymity against Have I Been Pwned (only a 5-character SHA-1 prefix leaves the server); optional XposedOrNot email lookup, fail-soft so an outage never blocks login.
- Password Policy â Enforce strong, unique passwords at registration, profile update and reset: minimum length and character classes, forbid the username inside the password, optionally reject breached passwords, with optional non-locking expiration nudges.
- Session Management â Idle-timeout logout measured on real page loads, a maximum session lifetime regardless of âremember meâ, an optional single-active-device restriction, and a one-click âsign out all other devicesâ.
- IP Geolocation â Show the attacker’s country on the Incidents and Events tabs; lazy, cached thirty days, capped per page load, private ranges never sent. Keyless ipwho.is by default, swappable for an offline database via a filter.
- Request Firewall â An optional, 8G-inspired PHP filter that blocks malicious query strings, paths, HTTP methods and (opt-in) user-agents/referrers before WordPress loads, on Apache/Nginx/LiteSpeed alike; off by default, starts in monitor mode, never filters admins, skips REST/cron/WP-CLI, with an IP/path allowlist (CIDR). Not scored.
AI Security Briefing (optional)
Built on the WordPress 7 native AI Client, one click turns your last thirty days of activity into a plain-language verdict, an IP picture and a short list of prioritised actions; âExplain with AIâ does the same on a single incident. Minimised mode (anonymised signals) is the default and deep mode is an explicit opt-in. No API key is stored â it uses your own WordPress AI connector, so provider and cost stay yours. It always leads with a deterministic facts snapshot that works with or without AI.
Plus
- Guided onboarding â a first-run wizard with a one-click safe baseline (Simple) or manual setup (Advanced); the âApply safe baselineâ button stays available, and upgrading sites never see the wizard.
- Security score â a weighted 0-100 read of your posture with a one-click ânext best actionâ; observability features (geolocation, notifications, the AI assistant) are deliberately not scored.
- Conflict detection â warns when another login-security plugin (Wordfence, Solid Security, Sucuri, All-In-One Security, SecuPress and more) or a cache plugin (with Hide Login on) could clash.
- Notifications â email, Slack, Discord or webhook with SSRF-safe URL validation, severity threshold and rate limiting.
- WP-CLI suite and a dashboard widget (14-day sparkline, six headline metrics).
GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies.
Douze modules de sécurité. Une seule extension légÚre. Zéro compromis.
Login Armor est une stack complĂšte de sĂ©curitĂ© WordPress conçue pour les agences, les freelances et les pros qui livrent des sites prĂȘts Ă passer un audit. Pas de version premium, pas de tableau de bord marketing intĂ©grĂ©, pas de tĂ©lĂ©mĂ©trie. Chaque module tourne en local, embarque des rĂ©glages par dĂ©faut sĂ©curisĂ©s, et reste discret.
Fini de jongler entre la lourdeur de Wordfence, les fenĂȘtres d’upsell de Solid Security et les angles morts de Limit Login Attempts â Login Armor regroupe douze modules indĂ©pendants en environ un mĂ©ga-octet.
Nouveau en 2.4.0
- Pare-feu de requĂȘtes : un filtre PHP optionnel, inspirĂ© du pare-feu 8G, qui bloque les requĂȘtes malveillantes (injection SQL, exĂ©cution de code, traversĂ©e de rĂ©pertoires, XSS, mĂ©thodes HTTP non autorisĂ©es) avant mĂȘme que WordPress ait fini de charger, aussi bien sur Apache que Nginx ou LiteSpeed. DĂ©sactivĂ© par dĂ©faut, il dĂ©marre en mode surveillance et ne filtre jamais les administrateurs connectĂ©s ; chaque blocage est journalisĂ©, agrĂ©gĂ© en un incident par IP et par heure.
- Assistant de configuration : Ă la premiĂšre activation, un assistant propose une « base sĂ»re » en un clic qui active les essentiels sans risque â un dĂ©butant est protĂ©gĂ© en quelques secondes. Le mĂȘme bouton « Appliquer la base sĂ»re » reste disponible Ă tout moment.
Pourquoi Login Armor
- Aucun upsell, jamais. Pas de niveau « premium », pas de boutons « Pro » grisés. Tout est en GPL.
- Aucun service externe Ă activer. Pas de clĂ© API, pas de tableau distant, pas de tĂ©lĂ©mĂ©trie. Les seuls appels sortants sont opt-in : Have I Been Pwned (fuites/mots de passe), Slack/Discord/webhook (notifications), l’API sans clĂ© ipwho.is (gĂ©olocalisation) et votre propre connecteur IA WordPress 7.
- Conçu pour ĂȘtre invisible. ZIP de moins d’un mĂ©ga, modules chargĂ©s Ă la demande, requĂȘtes indexĂ©es â sous 2 ms sur un flux de connexion normal.
- Compatible multisite, natif PHP 8.1, rĂ©glages prĂȘts pour la production. Activation rĂ©seau d’une flotte, configuration par site, pilotage via une suite WP-CLI complĂšte ; sans configuration, vous avez dĂ©jĂ 80 % de la protection.
Douze modules indépendants
- Masquer la connexion : remplace wp-login.php par une URL personnalisĂ©e (l’ancienne renvoie une 404) ; une modale de prĂ©-activation choisit ou gĂ©nĂšre le slug et vous l’envoie par e-mail pour Ă©viter tout verrouillage. Compatible multisite, reverse proxies et rĂ©cupĂ©ration de mot de passe.
- Protection contre la force brute : verrouillages en cascade montant Ă un bannissement de 24 h, blocage de sous-rĂ©seaux et support X-Forwarded-For ; lostpassword, register, XML-RPC et l’endpoint REST users sont bloquĂ©s pour une IP verrouillĂ©e, et chaque verrouillage devient un incident.
- Renforcement : quinze bascules en un clic (rĂ©duction de surface, identifiants, filtrage des requĂȘtes, surveillance des comptes) â dĂ©sactiver XML-RPC/pingbacks, l’Ă©diteur de fichiers, l’exposition de version, les mots de passe applicatifs et l’Ă©numĂ©ration d’auteurs ; bloquer les identifiants rĂ©servĂ©s (homoglyphes Unicode) ; ajouter un pot de miel ; ĂȘtre alertĂ© Ă la crĂ©ation d’un administrateur.
- Authentification à deux facteurs : TOTP, codes à usage unique par e-mail et codes de secours imprimables, avec appareils de confiance 30 jours, application par rÎle, période de grùce configurable et récupération par e-mail en cas de perte.
- DĂ©tection et incidents : un moteur en temps rĂ©el regroupe les Ă©vĂ©nements en six patterns d’attaque, chacun avec une vue dĂ©taillĂ©e (chronologie, IP sources, comptes cibles, sĂ©vĂ©ritĂ©, empreinte UA) et des actions en un clic.
- Journal d’activitĂ© : piste d’audit conforme et inviolable (chaĂźne de hachage) des actions admin sur sept domaines, avec filtrage, export CSV, rĂ©tention configurable et transfert webhook signĂ© optionnel vers un SIEM.
- En-tĂȘtes de sĂ©curitĂ© : CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy et X-Content-Type-Options sur wp-login.php et la page de verrouillage, en deux prĂ©rĂ©glages avec CSP report-uri optionnel ; les en-tĂȘtes de base peuvent s’Ă©tendre Ă tout le site.
- Détection de fuites : repÚre les connexions avec un mot de passe fuité via k-anonymat sur Have I Been Pwned (seul un préfixe SHA-1 de 5 caractÚres sort) ; vérification e-mail XposedOrNot optionnelle, fail-soft.
- Politique de mot de passe : impose des mots de passe forts Ă l’inscription, au profil et Ă la rĂ©initialisation (longueur, classes de caractĂšres, interdiction de l’identifiant, rejet optionnel des mots de passe fuitĂ©s), avec expiration optionnelle qui ne verrouille jamais personne dehors.
- Gestion des sessions : déconnexion sur inactivité mesurée sur les vrais chargements, durée de vie maximale indépendante de « se souvenir de moi », limitation optionnelle à un seul appareil actif, et « déconnecter tous les autres appareils » en un clic.
- GĂ©olocalisation IP : affiche le pays des IP attaquantes dans Incidents et ĂvĂ©nements ; recherches paresseuses, cache 30 jours, plafonnĂ©es par page, plages privĂ©es jamais envoyĂ©es. ipwho.is sans clĂ© par dĂ©faut, base hors ligne possible via un filtre.
- Pare-feu de requĂȘtes : filtre PHP optionnel inspirĂ© du 8G qui bloque chaĂźnes de requĂȘte, chemins, mĂ©thodes HTTP et (en option) user-agents/referrers malveillants avant le chargement de WordPress, sur Apache/Nginx/LiteSpeed ; dĂ©sactivĂ© par dĂ©faut, dĂ©marre en mode surveillance, ne filtre jamais les admins, ignore REST/cron/WP-CLI, allowlist IP/chemins (CIDR). Non notĂ©.
Briefing de sécurité IA (optionnel)
BĂąti sur le client IA natif de WordPress 7, un clic transforme vos trente derniers jours d’activitĂ© en un verdict en langage clair, un panorama des IP et une courte liste d’actions prioritaires ; « Expliquer avec l’IA » fait de mĂȘme sur un incident. Le mode minimisĂ© (signaux anonymisĂ©s) est par dĂ©faut, le mode approfondi est un opt-in explicite. Aucune clĂ© API stockĂ©e : il utilise votre propre connecteur IA WordPress, le coĂ»t et le fournisseur restent les vĂŽtres. Il s’ouvre toujours sur un instantanĂ© de faits dĂ©terministes, utile avec ou sans IA.
En plus
- Assistant de configuration : un assistant à la premiÚre activation propose une base sûre en un clic (Simple) ou une voie manuelle (Avancée) ; le bouton « Appliquer la base sûre » reste disponible, et les sites en mise à jour ne le voient jamais.
- Score de sĂ©curitĂ© : lecture pondĂ©rĂ©e 0-100 de votre posture avec une action prioritaire en un clic ; les fonctions d’observabilitĂ© (gĂ©olocalisation, notifications, assistant IA) ne sont pas notĂ©es.
- DĂ©tection de conflits : alerte quand une autre extension de sĂ©curitĂ© axĂ©e connexion (Wordfence, Solid Security, Sucuri, All-In-One Security, SecuPress et d’autres) ou un plugin de cache (avec Hide Login actif) peut entrer en conflit.
- Notifications : e-mail, Slack, Discord ou webhook, avec validation d’URL anti-SSRF, seuil de sĂ©vĂ©ritĂ© et rate limiting.
- Suite WP-CLI et widget Tableau de bord (sparkline 14 jours, six métriques clés).
Conçu par
Login Armor est conçu et maintenu par Fabrice Ducarme de WPFormation, expert WordPress français obsĂ©dĂ© par les sites propres, rapides et prĂȘts pour l’audit. On l’utilise sur chaque site qu’on livre.
- Présentation et fonctionnement de Login Armor
- Guides de sécurité WordPress sur WPFormation
- Veille des vulnĂ©rabilitĂ©s WordPress : l’outil de veille sĂ©curitĂ© de WPFormation
GPL pour toujours. PHP 8.1+. WordPress 6.8+. Zéro dépendance.
External Services
AI Security Briefing (optional)
The AI Security Briefing and the âExplain with AIâ incident analysis are powered by the WordPress 7 native AI Client (wp_ai_client_prompt()). When the administrator clicks the analysis button, LoginArmor asks WordPress to send a prompt to the AI connector that the administrator configured in their own WordPress (for example OpenAI, Anthropic or Google, depending on the connector). LoginArmor itself stores no API key and contacts no endpoint directly: the request, the provider and the cost are owned by the site’s own AI connector.
Data sent: a text prompt describing the security situation. In minimised mode (the default), only anonymised, non-identifying signals are included (counts, categories, severities, role buckets) – no IP address and no username in clear. In deep mode (an explicit, off-by-default opt-in), the prompt additionally includes real IP addresses and event details so the analysis can name specific sources. No data is ever sent unless the administrator clicks the analysis button.
This feature is inactive unless WordPress 7 (or the AI Building Blocks feature plugin) is present with a configured, approved AI connector. The applicable terms and privacy policy are those of the AI provider the administrator chose for their connector; please refer to that provider’s documentation.
Webhook Notifications (optional)
When explicitly enabled and configured by the administrator in LoginArmor > Settings > Notifications, the plugin sends incident data to third-party services via webhooks.
Data sent: incident type, severity level, IP address, target username, event count, and site URL.
No data is sent unless the administrator actively enables and configures a notification channel.
- Slack – Terms of Service | Privacy Policy
- Discord – Terms of Service | Privacy Policy
- Custom Webhook URL – User-configured endpoint (administrator’s responsibility)
Gravatar (Automattic)
The Activity Log tab uses WordPress core’s get_avatar() function to display user avatars. WordPress may send a hashed email address to Gravatar servers to retrieve avatar images. This is controlled by Settings > Discussion > Avatars.
- Gravatar – Automattic Terms of Service | Privacy Policy
Breach Check – Have I Been Pwned (optional)
When the administrator explicitly enables the Breach Check module (LoginArmor > Settings > Breach …
Screenshots











Installation
- Upload the
login-armordirectory to/wp-content/plugins/ - Activate the plugin through the âPluginsâ menu in WordPress
- Go to LoginArmor in the admin menu to configure
For multisite: Network Activate the plugin to apply it across all sites.
Setting up Hide Login
- Go to LoginArmor > Settings > Hide Login section
- Enter your desired login slug (e.g.,
my-login) - Save settings
- Bookmark your new login URL: you will need it to access your admin
Recovering access
If you forget your custom login URL:
- Use the recovery email feature (configurable in settings)
- Connect to your database and delete the
login_armor_hide_slugrow from thewp_optionstable - Use WP-CLI:
wp option delete login_armor_hide_slug
FAQ
-
Will it lock me out of my own site?
-
No. Hide Login always sends a one-time recovery URL to the admin email. If you lose the slug, check your inbox. The plugin also honors
wp-clifallback so you can reset anything from SSH. -
Does it slow my site down?
-
No. Everything is lazy-loaded and indexed. On a normal login flow the extra SQL cost is under 2 ms.
-
Is it compatible with Cloudflare / reverse proxies?
-
Yes. IP detection honors trusted
X-Forwarded-Forheaders; you pick the header in Settings. -
Does it work with multisite?
-
Yes, subdomain and subfolder. Each site has its own modules, logs, and thresholds.
-
Can I use LoginArmor alongside Wordfence / iThemes Security / Solid Security?
-
Yes, but disable overlapping modules on one side to avoid double lockouts.
-
Where is the data stored?
-
Three custom tables in your own database: events, incidents, activity. Nothing leaves your server.
-
How do I migrate my configuration?
-
Settings are plain WordPress options. Export/import via WP-CLI or any standard options-sync tool.
-
Is there a pro version?
-
Not currently. LoginArmor is fully free and open source. GPL forever.
-
Where can I report bugs or request features?
-
Support forum: wordpress.org/support/plugin/login-armor/.
Reviews
Contributors & Developers
“Login Armor” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Login Armor” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
2.4.5
Accuracy release from a user report. Login Armor’s own blocks no longer count as failed passwords: a two-factor lockout, a two-factor rate limit, the mandatory-2FA gate, a honeypot catch and a reserved-username rejection each used to insert a brute-force attempt on top of their own sanction, so one mistyped 2FA code could push a legitimate user into the IP lockout while signing in with the correct password. Failed logins now record the real reason instead of always reporting âWrong passwordâ: the Events tab, the incident timeline, the Overview live tail and the CSV export distinguish a wrong password from an unknown account, cookies blocked by the browser, each of the plugin’s own gates, and a refusal coming from another plugin (shown with its code). Existing log rows keep the previous label. Also fixes a separate bug found while testing this release: the incidents table failed to create on MariaDB 11.7+/MySQL 9 because the vector column collided with a new reserved word, which silently disabled the whole Detection engine on those servers.
2.4.4
Hardening release from an external code audit; five confirmed issues fixed and each verified end-to-end (real HTTP flow locally, re-run under PHP 8.4, and validated on a live WordPress 7.0 / PHP 8.3 install). The Overview dashboard now computes the threat level and active-incident count over every active incident, so an older critical incident can no longer drop the headline back to âNormalâ. A successful two-factor login now fires the canonical wp_login cycle, so failed-attempt counters reset, the login is logged, the single-session policy applies and third-party integrations run. Lockout escalation is now atomic under concurrency, so a burst of simultaneous failures can no longer turn a first offence into an immediate long ban. The Slack/Discord/generic notification webhooks are re-validated against private, reserved, link-local and IPv6-internal addresses before every send (SSRF), and CSV log exports neutralise spreadsheet formula injection from attacker-controlled fields. Plugin Check 0 ERROR.
2.4.3
Security release. Mandatory two-factor authentication is now a hard gate: a user in an enforced role who never enrolled and whose grace period has expired is blocked at login instead of being let in with only a redirect to their profile (reported by the WordPress Plugin Review Team). Existing users are never locked out unexpectedly – the grace window is started automatically the first time enforcement applies, and an admin can reopen it from the Users list (âRestart 2FA graceâ) or via WP-CLI. Hardened: TOTP codes can no longer be replayed within their validity window (single-use per time-step, RFC 6238); the Activity Log webhook URL is validated against private, reserved, link-local and IPv6-internal addresses (SSRF), matching the notification channels; attacker-submitted usernames are neutralised before entering the optional AI incident prompt. A filter (login_armor_2fa_hard_enforcement) restores the previous soft behaviour if needed.
2.4.2
Coherence and lifecycle release. Fixes: deactivation now clears every scheduled task (three were left running); uninstall removes all options, user meta and caches from the newer modules (AI, Password Policy, Sessions, GeoIP, Firewall); disabling Two-Factor now asks for confirmation like every other module; the plugin’s own conflict warnings, silently hidden since 2.4.0, show again. Improvements: a composite database index speeds up brute-force lookups, open incidents are capped so the table cannot grow forever, and the admin UI is more consistent (numeric fields, empty states, module counters). New: a warning when a front-end login plugin such as Ultimate Member is active, since Two-Factor and Hide Login are not compatible with a front-end login form. No behaviour change on standard installs.
2.4.1
Fix: a âcritical errorâ could occur during password recovery when another active plugin re-fires a WordPress core hook with an off-contract argument type or arity (for example a null passed to retrieve_password_message ahead of Login Armor). Strict parameter hints are relaxed, each with an internal type guard, on every core-hook callback across all modules; behaviour is unchanged on canonical WordPress calls. Generalises the 2.1.15 URL-builder fix to the whole plugin.
2.4.0
Feature release – request firewall, guided onboarding, fuller in-app docs.
- New – Request Firewall (optional, off by default): a PHP â8Gâ-style filter that blocks malicious query strings, paths and HTTP methods before WordPress fully loads (Apache/Nginx/LiteSpeed/IIS). Starts in monitor mode; admins, REST, cron, WP-CLI and admin-ajax are never filtered; IP/path allowlist (CIDR); blocks aggregate to one incident per IP per hour.
- New – Onboarding wizard with a one-click safe baseline (Simple) or manual setup (Advanced), plus a permanent âApply safe baselineâ button. Upgrading sites see no change.
- Improvement – Granular security-plugin conflict warnings, a cache-plugin warning when Hide Login is on, and contextual help for the modules added since 2.2.0.
2.3.0
Feature release – account-security hardening.
- New – Password Policy: minimum length and character-class rules, forbid the username in the password, optionally reject breached passwords (privacy-preserving HIBP), optional non-locking expiration.
- New – Session Management: idle timeout, maximum session lifetime, optional single active device, and âsign out all other devicesâ.
- New – IP Geolocation (opt-in): country next to IPs on Incidents/Events; lazy, cached, private ranges never sent (see External Services).
- Improvement – Score now accounts for Password Policy and Session Management; baseline headers can apply site-wide; every IP lockout creates an incident. New hardening: disable pingbacks, alert on new admin.
2.2.0
Feature release – the AI Security Briefing.
- New – AI Security Briefing on the Overview: one click turns your last 30 days of activity into a plain-language verdict, an IP picture and prioritised actions. Built on the WordPress 7 native AI Client – uses your own connector, stores no API key, runs only on click. Always leads with a deterministic facts snapshot (with or without AI); plus âExplain with AIâ on an incident.
- Privacy – Minimised mode (anonymised signals) is the default; deep mode (real IPs) is an explicit opt-in. See External Services.
2.1.26
Fix: email/backup 2FA bouncing to âsession expiredâ on browsers that don’t return the verification cookie; the form now also carries the session token. Security unchanged.
2.1.25
Fix: email/backup two-factor verification rejected in some browsers (notably Chrome); the form is now uncached and authenticated by the signed same-site cookie.
2.1.24
Fix: fatal error during authenticator-app setup on hosts whose wp-config.php does not define AUTH_KEY (e.g. some Infomaniak installs). Existing setups unaffected.
2.1.23
Fix: 2FA login screen – âuse a different methodâ links now work, expired/locked sessions explain themselves, and the setup button reports errors.
2.1.22
Fix: the Security Score now counts default-on modules (Brute Force, Detection). Display and scoring only.
2.1.21
Cleaner user-agent labels in the Events table.
2.1.20
Migration-aware Activity Log integrity (amber âKeys changedâ instead of a false TAMPERED alarm), an XML-RPC blind-spot warning, and a complete French translation.
2.1.19
Clearer attack-type labels on incidents, translatable admin toasts, French translation of the visible tabs, and an integrity-badge verify fix.
2.1.18
Fix: bulk actions now work when incidents are all resolved; the attack-vector pill shows only for XML-RPC/REST.
2.1.17
Incidents now record and show the attack vector (XML-RPC / REST / login form) and support bulk resolve/ignore.
2.1.16
Plain-permalink fixes (Hide Login URL, REST allowlist), activity-log coverage for 2FA/registration/reset, and Honeypot on WooCommerce and frontend forms.
2.1.15
Fix: fatal TypeError when plugins (e.g. WP Fastest Cache) call WordPress URL builders with off-contract argument types.
2.1.14
Fix: the prevent_author_enum toggle no longer blocks the legitimate ?author=N filter in the wp-admin Posts/Pages lists.
2.1.13
Fix: silent 2FA failure on non-trailing-slash permalinks (e.g. /%postname%) – the verify cookie path mismatched the request path.
2.1.12 and earlier
Bug fixes, security hardening and i18n across the 2.1.x and 2.0.x series (Hide Login host-awareness, CSP, lockout delivery, REST scope, IPv6, HTTP/2, Activity Log integrity), through the initial 2.0.0 release. Full per-version notes: CHANGELOG.md in the plugin folder.
