WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by wpformation v2.5.3

Login Armor

Thirteen security modules + AI briefing: hide login, request firewall, brute force, 2FA, password policy, sessions, hardening, audit log. No upsells.

Login Armor

The facts

Rating
5★ from 5
Active installs
300+
Price
Free
Last updated
23 Aug 2026
Added
Apr 2026
Requires WP
6.8
Tested up to
WP 7.1
Requires PHP
8.1
Downloads
4,846

Our analysis

AI-assisted

Login Armor is a WordPress plugin designed to enhance the security of your site's login and administration areas. It features thirteen independent security modules that provide various protective measures without requiring a remote dashboard or upsells. This plugin is suitable for agencies, freelancers, and site owners looking for practical security solutions with clear evidence of protection.

The plugin includes features such as brute force protection, two-factor authentication, activity logging, and a request firewall. It is lightweight, with modules that load only when necessary, ensuring minimal impact on site performance. Additionally, it keeps data private by default, storing it on your site rather than sending it externally.

Best for: This plugin suits agencies, freelancers, and site owners seeking robust security for their WordPress sites.

What it does well

  • Includes thirteen independent security modules
  • Lightweight with minimal performance impact
  • Data remains private on your site
  • No premium tier, all features included for free
  • Multisite support and production-safe defaults

Where it falls short

  • Limited information on user interface and experience
  • No specific details on support options

Verdict

Login Armor offers a comprehensive set of security features for WordPress without additional costs. It is a solid choice for those prioritising site security and data privacy.

From the developer

wpformation's own description of Login Armor, lightly tidied.

🇫🇷 Fully translated into French. Interface et documentation intégralement disponibles en français.

Thirteen security modules. One lightweight plugin. No premium tier.

Login Armor protects WordPress login, accounts and administration with thirteen independent modules. It is built for agencies, freelancers and site owners who want practical security, clear evidence and safe defaults without a remote dashboard, bundled telemetry or upsells.

Why Login Armor

  • Complete and free: every module is included under the GPL.
  • Lightweight: modules load only when needed and normal login checks add less than 2 ms on a typical setup.
  • Private by default: data stays on your site. Optional external calls are disabled until you enable the related feature.
  • Ready for real sites: multisite support, reverse-proxy controls, WP-CLI commands and production-safe defaults.

Thirteen security modules

  1. Hide Login: replace wp-login.php with a private slug and return a 404 or redirect blocked visitors to a chosen URL.
  2. Brute Force Protection: escalating lockouts, subnet blocking, trusted proxy headers and coverage for login, password recovery, registration, XML-RPC and REST users.
  3. Hardening: fifteen controls for XML-RPC, pingbacks, file editing, version exposure, application passwords, author enumeration, reserved usernames, honeypots and new-admin alerts.
  4. Two-Factor Authentication: TOTP, email codes, backup codes, trusted devices, per-role enforcement, grace periods and recovery.
  5. Detection and Incidents: group raw events into attack patterns with severity, timelines, source IPs, targeted users and one-click actions.
  6. Activity Log: tamper-evident admin audit trail with filters, CSV export, retention controls and optional signed SIEM forwarding.
  7. Security Headers: CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options for login and lockout pages, with optional site-wide baseline headers.
  8. Breach Check: privacy-preserving Have I Been Pwned password checks and an optional XposedOrNot email check.
  9. Password Policy: length and character rules, username exclusion, breached-password rejection and optional non-locking expiration reminders.
  10. Session Management: idle timeout, maximum lifetime, optional single-device access and one-click revocation of other sessions.
  11. IP Geolocation: cached country lookup for IPs shown in Incidents and Events, with private ranges excluded.
  12. Request Firewall: optional, monitor-first filtering of malicious paths, query strings and HTTP methods, with administrator exclusions and IP/path allowlists.
  13. Bot Challenge: an invisible proof-of-work the browser solves before the login form is accepted, an alternative to CAPTCHAs with no external service; monitor-first, then enforce.

Additional tools

Login Armor also includes guided onboarding, a 0-100 security score, conflict detection, email/Slack/Discord/webhook notifications, a dashboard widget and a complete WP-CLI suite.

The optional AI Security Briefing uses your own WordPress AI connector to explain a thirty-day security snapshot or a single incident. It always starts with deterministic facts, works without AI and sends nothing until an administrator explicitly requests an analysis.

GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies.

Treize modules de sécurité. Une seule extension légère. Aucune version premium.

Login Armor protège la connexion, les comptes et l’administration de WordPress grâce à treize modules indépendants. L’extension s’adresse aux agences, freelances et propriétaires de sites qui veulent une sécurité concrète, des preuves lisibles et des réglages sûrs, sans tableau de bord distant, télémétrie imposée ni upsell.

Pourquoi Login Armor

  • Complet et gratuit : tous les modules sont inclus sous licence GPL.
  • Léger : les modules se chargent uniquement lorsque nécessaire et les contrôles ajoutent moins de 2 ms sur une connexion normale.
  • Privé par défaut : les données restent sur votre site. Les appels externes optionnels sont désactivés tant que vous n’activez pas la fonction concernée.
  • Prêt pour la production : multisite, reverse proxies, commandes WP-CLI et réglages par défaut sécurisés.

Treize modules de sécurité

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)