Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Login security: KeyLockr SSO scan login, 2FA, passwordless login, Cloudflare Turnstile, GeoLocation/IP limits, whitelist and blacklist.
DoLogin Security is a WordPress plugin designed to enhance the security of your login process. It provides features such as brute force attack protection, two-factor authentication, and passwordless login options. The plugin is suitable for users who want to strengthen the security of their WordPress sites, including those running e-commerce platforms like WooCommerce.
The plugin limits login attempts and offers geo-location based restrictions, along with support for whitelisting and blacklisting IP addresses. It is GDPR compliant, ensuring that logged IPs are obfuscated, and includes advanced features like encrypted app data hash verification and session-bound encryption.
Best for: This plugin suits WordPress site owners looking for enhanced login security features.
What it does well
Where it falls short
DoLogin Security offers a comprehensive set of tools for improving login security on WordPress sites. It is particularly useful for those who require robust protection against unauthorized access.
WPDO's own description of DoLogin Security, lightly tidied.
In one click, your WordPress login page will be pretected with the smart brute force attack protection! Any login attempts more than 6 in 10 minutes (default value) will be limited.
Limit the number of login attempts through both the login and the auth cookies.
Two-factor Authentication login.
KeyLockr SSO scan login with encrypted appdata hash verification and session-bound encryption.
Cloudflare Turnstile (better than Google reCAPTCHA).
GeoLocation (Continent/Country/City) or IP range to limit login attempts.
Passwordless login link.
Support Whitelist and Blacklist.
GDPR compliant. With this feature turned on, all logged IPs get obfuscated (md5-hashed).
WooCommerce Login supported.
XMLRPC gateway protection.
🔑 A stolen database should not become a bag of ready-to-use login secrets.
DoLogin separates stored data from the WordPress authentication salts. If an attacker copies only the database—but does not have the salts from the site configuration—the protected values cannot be used as login links, TOTP seeds, or signing keys.
🔗 Passwordless and child-site tokens: compare without storing the secret
Secret in the generated link ➜ `salt-keyed HMAC` ➜ `database stores only the verifier`
🔐 TOTP and signing keys: encrypted when the server must recover them
TOTP seed or private key ➜ `authenticated encryption + site salt` ➜ `ciphertext in the database`
TOTP verification and digital signatures need the original secret at runtime, so these values cannot use a one-way hash. DoLogin encrypts them instead and rejects modified ciphertext. Existing TOTP seeds and Site Easy Login private keys are migrated automatically.
🏠 Site Easy Login: one signed message, one destination, one use
User + trusted public key + destination + issue time + random token ID ➜ `one Ed25519 signature`
The child site verifies the complete signed message with the public key already saved for that connection. Changing the user or destination breaks the signature, and an atomic consume step blocks replay.
📱 KeyLockr SSO: stable signing and encryption identity
Other plugins for securing a site.
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...