Linux 软件免费装

DoLogin Security

开发者 WPDO
更新时间 2026年7月29日 07:24
PHP版本: 5.6 及以上
WordPress版本: 7.0
版权: GPLv3
版权网址: 版权信息

标签

limit login attempts reCAPTCHA Login security passwordless login 2FA login

下载

2.5 3.4 3.5.1 2.1 2.9.2 1.3 4.1.1 1.4.5 1.6 2.2 1.1 1.1.1 1.5 2.9.3 2.9.4 3.5.2 3.6 1.3.1 1.4.1 1.7 2.0 2.6 2.8 1.2.1 2.7 3.2 3.7.1 1.0 1.2 2.2.1 3.1 3.8 1.2.2 1.3.2 4.3 4.4 1.3.4 1.4.2 1.4.6 1.9 3.3 1.3.5 2.7.1 3.0 4.7.7 1.3.3 1.4 1.4.3 1.4.4 1.4.7 1.7.1 1.8 2.2.2 2.3 2.4 2.9 3.5 3.7 4.0 4.1 4.2 4.8.3

详情介绍:

In one click, your WordPress login page will be pretected with the smart brute force attack protection! Any login attempts more than 6 in 10 minutes (default value) will be limited. Limit the number of login attempts through both the login and the auth cookies. 🛡️ Security, explained simply 🔑 A stolen database should not become a bag of ready-to-use login secrets. DoLogin separates stored data from the WordPress authentication salts. If an attacker copies only the database—but does not have the salts from the site configuration—the protected values cannot be used as login links, TOTP seeds, or signing keys. 🔗 Passwordless and child-site tokens: compare without storing the secret Secret in the generated linksalt-keyed HMACdatabase stores only the verifier 🔐 TOTP and signing keys: encrypted when the server must recover them TOTP seed or private keyauthenticated encryption + site saltciphertext in the database TOTP verification and digital signatures need the original secret at runtime, so these values cannot use a one-way hash. DoLogin encrypts them instead and rejects modified ciphertext. Existing TOTP seeds and Site Easy Login private keys are migrated automatically. 🏠 Site Easy Login: one signed message, one destination, one use User + trusted public key + destination + issue time + random token IDone Ed25519 signature The child site verifies the complete signed message with the public key already saved for that connection. Changing the user or destination breaks the signature, and an atomic consume step blocks replay. 📱 KeyLockr SSO: stable signing and encryption identity Scan QRapprove on phoneverify Safe + AppData bindingWordPress login cookie 🚦 Force KeyLockr SSO that fails closed Enable force mode after a verified admin bindingkeep QR-only policy activenever reopen older interactive login methods automatically DoLogin checks the current administrator binding before force mode can be enabled. After that policy is saved, a missing binding, changed App Tag, broken site identity, or unavailable KeyLockr service does not restore password, passwordless-link, connected-site, or password-reset login paths. The WordPress lost-password link and core password-reset screens are removed while force mode is active; unlinking and site-key reset are also blocked. Existing authenticated sessions can disable force mode from settings; if no session remains, rename the plugin folder through FTP or the hosting file manager before repairing the connection. WordPress Application Passwords remain available for API clients. API The generated one-time used link will be expired after 7 days. KeyLockr SSO Recovery Forced KeyLockr SSO blocks password, passwordless-link, and connected-site interactive logins. Existing authenticated cookies and WordPress Application Passwords remain available. DoLogin never restores another interactive login method because KeyLockr is unavailable or the saved binding becomes invalid. Use an existing authenticated administrator session to disable force mode. If no such session remains, rename the plugin folder through FTP or the hosting file manager, then repair the connection before enabling force mode again. CLI How GeoLocation works When visitors hit the login page, this plugin will lookup the Geolocation info from API, compare the Geolocation setting (if has) with the whitelist/blacklist to decide if allow login attempts.

屏幕截图:

  • Plugin Settings
  • Plugin Passwordless Login
  • Plugin Login Attempts Log
  • Login Page (KeyLockr SSO QR login)
  • Login Page (2 times left)
  • Login Page (Too many failure)
  • Login Page (Blacklist blocked)
  • WooCommerce login protection

更新日志:

4.8.3 - Jul 28 2026 4.7.7 - Jul 22 2026 4.4 - Jul 6 2026 4.3 - Jun 11 2025 4.2 - May 31 2025 4.1.1 - May 27 2025 4.1 - May 27 2025 4.0 - May 26 2025 3.8 3.7.1 3.7 3.6 3.5.2 3.5.1 3.5 3.4 3.3 3.2 3.1 3.0 2.9.4 2.9.3 2.9.2 2.9.1 2.9 2.8 2.7.1 2.7 2.6 2.5 2.4 2.3 2.2.2 2.2.1 2.2 2.1 2.0 1.9 1.8 1.7.1 1.7 1.6 1.5 1.4.7 1.4.5 1.4.4 1.4.3 1.4.2 1.4.1 1.4 1.3.5 1.3.4 1.3.3 1.3.2 1.3.1 1.3 1.2.2 1.2.1 1.2 1.1.1 1.1 1.0 - Sep 27 2019