| 开发者 | mvpplugins |
|---|---|
| 更新时间 | 2026年9月29日 18:54 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
NibbleSecure replaces public access to your default wp-login.php page with a unique secret URL. Anyone or any bot trying to reach the standard login page is blocked before it ever loads.
Your secret login URL is shown in an on-screen notice right after you activate the plugin, and it's always visible on the NibbleSecure settings page. If you'd also like a copy emailed to you, use the "Email Me" button on the settings page: enter your admin email and it will send your current secret login URL to your inbox. No email is sent automatically; this only happens when you choose to click that button.
NibbleSecure tracks failed login attempts by IP address. Once an IP crosses your configured maximum attempts, it's locked out from logging in for your set lockout period. If the same IP gets locked out again within 24 hours, each repeat offense adds your configured "Compounding Progression Interval" on top of the base lockout, so persistent attackers face progressively longer bans. If your site sits behind a trusted proxy or CDN, see the nibblesecure_trusted_proxy_headers filter to configure which proxy header, if any, should be trusted for identifying the real visitor IP. This is a code-level setting for developers, added via a filter in your theme or a small custom plugin; it is not a toggle found on the Brute Force settings tab, since the correct header depends on your specific hosting/CDN setup.
No. NibbleSecure runs entirely on your own WordPress database. It doesn't load external tracking scripts or require any paid cloud API to hide your login page or limit login attempts.
No. NibbleSecure is built to be lightweight. Login attempt checks and lockout lookups are optimized to have minimal impact on your site's load time.
The locked settings tabs preview PRO-only features: Two-Factor Authentication (2FA/TOTP), malware & file integrity scanning, session hijacking control, Application-Layer (L7) DDoS protection, advanced .htaccess server hardening, an automated 404 scanner with IP auto-ban, manual IP/country blocking, a login math CAPTCHA, and scheduled backups with one-click restore. These are unlocked by installing the separate, self-hosted NibbleSecure PRO add-on from our website. The free version on WordPress.org is fully functional without it.
Two-Factor Authentication (2FA/TOTP) is not included in this free version. It's available exclusively through the separate NibbleSecure PRO add-on. Once installed, NibbleSecure PRO adds TOTP-based two-factor authentication compatible with Google Authenticator, Authy, Microsoft Authenticator, 1Password, and other standard authenticator apps. It also adds emergency backup codes and secure email recovery if you ever lose your device.
Two-Factor Authentication (2FA) adds a second verification step after your username and password: a time-based 6-digit code from an authenticator app. This keeps your account protected even if your password is stolen, guessed, or leaked elsewhere. This free version protects your login with a secret login URL, limit login attempts, and brute force protection; full 2FA/TOTP support is available in the NibbleSecure PRO add-on.
The free version's Limit Login Attempts & Brute Force Protection only tracks failed login attempts. Detecting and auto-banning IPs that repeatedly probe non-existent pages is a separate PRO-only feature, Automated 404 Scanner & IP Auto-Ban. Repeatedly probing non-existent pages is a common sign of vulnerability scanning. This feature is available through the NibbleSecure PRO add-on.
Not in this free version. Manual IP, IP range, and country blocking is available through the NibbleSecure PRO add-on, which includes a dedicated management panel for adding and removing blocks.
Not in this free version. A math CAPTCHA on the login and lost-password forms, which helps stop automated bot submissions before they reach the brute-force checks, is available through the NibbleSecure PRO add-on.
Not in this free version. Application-Layer (L7) DDoS & Flood Protection, which rate-limits and blocks malicious traffic spikes and botnet floods before they reach your server, is available through the NibbleSecure PRO add-on.
Not in this free version. Scheduled automatic backups with one-click restore, covering your database, files, and configuration, are available through the NibbleSecure PRO add-on.
Not in this free version. Blocking author/user enumeration attacks, a common technique bots use to discover valid usernames before attempting a brute-force login, is available through the NibbleSecure PRO add-on.
Not in this free version. Blocking RSS/Atom feeds from content scrapers is available through the NibbleSecure PRO add-on.