Sentinel Login Guard is a professional security plugin that hides the default WordPress login page and provides geographic restriction based on visitor IP.
Features:
wp-login.php and /wp-admin pathsThis plugin connects to the ipwho.is service to detect the visitor’s country for geo-restriction of the login page.
External Service Details:
Data sent: Only the visitor’s IP address is sent to https://ipwho.is/{visitor-ip}. No other data, headers, cookies, or personal information are transmitted.
When: The request is made when a visitor attempts to access the login page.
Purpose: To retrieve the ISO country code (e.g., “IR”) to decide whether the visitor is allowed to see the login form.
Caching: Results are cached locally in the WordPress database using transients for 1 hour.
Fallback: If the service fails, the plugin has an “Emergency mode” setting. When enabled (default), access is allowed so the site admin is never locked out.
Login log data:
This plugin stores a temporary record of login attempts (both successful and failed) for security auditing purposes. The stored data includes: visitor IP, country, city, and login status. This data is retained for 30 days and automatically deleted afterward. The legal basis for this processing is legitimate interest in securing the website (GDPR Recital 49).
No third-party tracking:
The plugin does not use any external services for tracking, analytics, or user profiling. ipwho.is is used solely for country detection.
Data retention:
uninstall.php.