Linux 软件免费装

KHALAF Login Access Guard

开发者 khalaf22
更新时间 2026年10月1日 16:12
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security login custom login url brute force hide login

下载

1.0.3 1.0.0 1.0.1 1.0.2

详情介绍:

KHALAF Login Access Guard defends your WordPress website against automated bots, brute-force attacks, and credential stuffing by transforming the standard /wp-login.php path into a private, customizable URL of your choice. Unlike typical hide-login plugins that simply display a generic 404 error or a blank screen, KHALAF Login Access Guard provides a dedicated visual customizer and a real-time live preview inside your dashboard to design a modern, branded 403 Access Denied page for blocked visitors. Key Features Security Notes

安装:

  1. Upload the khalaf-login-access-guard folder to your /wp-content/plugins/ directory.
  2. Activate the plugin via Plugins → Installed Plugins.
  3. Navigate to Login Access Guard in the WordPress admin menu.
  4. Set your desired custom slug or click Generate for a secure random slug.
  5. (Optional) Customize your Access Denied page and preview it in real time under the Style & Live Preview tab.
  6. Toggle Enable Protection and save your settings.

屏幕截图:

  • Content and dual-language (Arabic/English) blocked page editor.
  • Appearance customizer with interactive real-time live preview.
  • Branded 403 Access Denied page displayed to unauthorized visitors.

升级注意事项:

1.0.3 Bug fixes and compatibility improvements. 1.0.2 Minor improvements and contact link update. 1.0.1 Compliance update. Please upgrade. 1.0.0 Initial release.

常见问题:

I forgot my custom login URL. How do I regain access?

You can regain access at any time via FTP or your hosting File Manager: temporarily rename the khalaf-login-access-guard directory inside /wp-content/plugins/ or delete the klguard_settings entry in wp_options. WordPress will immediately revert to the default /wp-login.php.

Does this plugin work with WooCommerce and membership plugins?

Yes. The plugin only intercepts direct visits to /wp-login.php and protects the admin area against unauthenticated access. It does not alter frontend account pages or WooCommerce endpoints.

Will this break password reset emails or logout?

No. Legitimate password reset links containing verification tokens, logout requests, and GDPR privacy actions are whitelisted and execute normally.

Does it work with caching plugins?

Yes. Ensure your caching plugin (WP Rocket, LiteSpeed, W3 Total Cache, etc.) is configured to exclude your custom secret login slug from page caching.

更新日志:

1.0.3 1.0.2 1.0.1 1.0.0