Protect WordPress login and wp-admin with IP allowlisting, custom login URLs, email OTP, rate limiting, CAPTCHA, logging and alerts.
171.61, stored as 171.61.0.0/16.wp-login.php endpoint.wp-admin by IP while keeping admin-ajax.php available.CF-Connecting-IP detection.X-Forwarded-For detection for known reverse-proxy setups.Keep at least one known administrator IP in the allowlist before enabling IP protection.
Only enable Cloudflare IP detection when the site is actually behind Cloudflare. Only enable trusted X-Forwarded-For when the server is behind a trusted reverse proxy that sets that header.
On localhost, PHP commonly sees 127.0.0.1 or ::1 rather than the browser’s public VPN address. Use a publicly reachable staging site for an end-to-end VPN IP test.
The emergency fallback code is stored as a password hash and is never displayed after saving.
This plugin can optionally communicate with third-party CAPTCHA verification services when CAPTCHA is enabled:
The plugin does not contact these services when CAPTCHA is disabled.
Exact IP: 186.189.26.220
IPv4 /16 shorthand: 171.61
CIDR: 171.61.0.0/16
After a successful WordPress administrator password check, a six-digit OTP is generated and sent to that administrator’s WordPress profile email address.
If email delivery is unavailable, an administrator-configured emergency fallback code can be used.