Techbox Login Security protects WordPress login pages from brute-force attacks with IP lockouts, custom login URLs, and activity logs. Free Lite plan; Pro…
Techbox Login Security is a WordPress security plugin focused specifically on protecting the login stage of a site. It runs entirely on-site with no external API calls and only activates at login, so it does not add page-load overhead. Core protection includes smart brute-force lockouts that block repeated attempts from the same IP, IP allow/deny lists, a custom login URL with a security gate to hide wp-login.php, a temporary "login lockdown" mode during attacks, optional email verification codes as a second factor, and customizable login messages. Paid Pro tiers add country/geo-based access control, per-username attempt limits with anti-enumeration protection, a bot-protection suite (user-agent blocklist and honeypot detection), enhanced activity logging with CSV export, active-session management (viewing and terminating logged-in users), and an "Intelligence & Threat Insights" dashboard showing attack patterns. Coverage extends beyond the standard login form to custom login URLs, XML-RPC, the REST API, and application passwords, and the plugin is built to work alongside WooCommerce login/checkout flows and behind Cloudflare, Nginx proxies, or CDNs via configurable X-Forwarded-For support.
Key Features
Smart brute-force lockouts — Automatically blocks repeated failed login attempts from the same IP address.
IP allow & deny lists — Whitelist trusted IP addresses and blacklist malicious ones.