WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by ishitaka v3.11.0

XO Security

XO Security is a plugin to enhance login related security.

XO Security

The facts

Rating
5★ from 11
Active installs
30k+
Price
Free
Last updated
19 Jul 2026
Added
Jan 2016
Requires WP
6.0
Tested up to
WP 7.0.4
Requires PHP
7.2
Downloads
404,476

Our analysis

AI-assisted

XO Security is a WordPress plugin designed to enhance security related to user logins. It offers various features such as limiting login attempts, adding Captcha to forms, and enabling two-factor authentication. This plugin is suitable for anyone looking to improve the security of their WordPress site, particularly in environments where user login is a critical function.

The plugin does not modify the .htaccess file and is compatible with various server types including Apache, LiteSpeed, Nginx, and IIS. It includes options for logging login activity, changing login URLs, and disabling various access points, making it a comprehensive tool for site administrators focused on security.

Best for: This plugin suits WordPress site administrators looking to bolster login security.

What it does well

  • Records login logs
  • Limits login attempts
  • Supports two-factor authentication
  • Compatible with multiple server types
  • Offers various options to enhance login security

Where it falls short

  • No information on premium features or support
  • Limited details on user interface or ease of use
  • Requires specific PHP version (7.2 or higher)

Verdict

XO Security provides a range of features aimed at improving login security for WordPress sites. It is a solid choice for those prioritising user authentication and access control.

From the developer

ishitaka's own description of XO Security, lightly tidied.

XO Security is a plugin to enhance login related security.
This plugin does not write to .htaccess file. Besides Apache, LiteSpeed, Nginx and IIS also work.

Functions

  • Record login log.
  • Limit login attempts.
  • Add Captcha to the login form and comment form.
  • Change the URL of the login page.
  • Enable two-factor authentication (2FA) for login.
  • Login Alert.
  • Disable login by mail address.
  • Disable login by user name.
  • Change login error message.
  • Disable XML-RPC and XML-RPC Pingback.
  • Disable REST API.
  • Disable author archive page.
  • Remove comment author class of comments list.
  • Remove the username from the oEmbed response data.
  • WooCommerce login page protection.
  • Anti-spam comment.
  • Hide WordPress version information.
  • Edit the author slug.
  • Disable RSS and Atom feeds.
  • Activate maintenance mode.
  • Delete the readme.html file.

WordPress multisite considerations

If you set the login page separately for the main site and the subsite, you will not be able to use the password loss function of the subsite. We recommend that you set the login page to be common to all sites.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)