LyoGate — Login Security

LyoGate — Login Security

By Andres
Details
View on WordPress

LyoGate replaces the default WordPress login page with a modern, protected one. Everything is configured from Settings LyoGate. No external accounts, no third-party services: everything runs on your own site.

Security

  • Arithmetic captcha — a simple sum is required before signing in, backed by an HMAC-signed token with expiry (10 minutes): the answer never travels in clear text and is never stored in the database.
  • Per-IP brute-force lockout — after N failed attempts (default 5) the IP address is locked out for X minutes (default 15). Wrong captcha and honeypot hits count too; a successful login resets the counter. The lockout applies even with correct credentials.
  • Honeypot — a field hidden from humans: whoever fills it in is a bot and gets rejected without hints.
  • Unified error messages — no username enumeration: “unknown user” and “wrong password” produce the same generic message.
  • Reduced attack surface — XML-RPC disabled, X-Pingback header removed, public REST user endpoints removed (they remain available to users who can edit posts, for the block editor), and ?author=N requests plus author archives redirect to the home page: no username scraping.

Customizable appearance

  • Title, subtitle and footer message
  • Custom logo from the media library, with a configurable clickable link (empty = site home)
  • Two Google Fonts to choose from: Syne, Instrument Sans, Inter, Space Grotesk, Manrope, DM Sans, Outfit, Sora, Archivo, Playfair Display and JetBrains Mono (one for headings, one for body text)
  • Three colors: background, text and accent (buttons and focus)

Compatibility

  • The security gate runs as a late filter on the authenticate flow: captcha and lockout always take precedence over valid credentials. The gate only acts on the wp-login.php form: XML-RPC is disabled entirely while LyoGate is active, and application password / REST requests follow the normal WordPress flow (should another plugin re-enable XML-RPC, its authentication is not intercepted by the captcha).
  • All settings live in a single database option; on uninstall, options and transients are removed (also on multi-site).

Details

Plugin code:
lyogate
Plugin version:
1.0.0
Author:
Outdated:
No
WP version:
6.0 or higher
PHP version:
8.0 or higher
Test up to WP version:
7.1.2
Total installations:
0
Last updated:
2026-09-30
Rating:
Times rated:
0
brute-force
captcha
custom-login
login
security