Description
LyoGate replaces the default WordPress login page with a modern, protected one. Everything is configured from Settings LyoGate. No external accounts, no third-party services: everything runs on your own site.
Security
- Arithmetic captcha — a simple sum is required before signing in, backed by an HMAC-signed token with expiry (10 minutes): the answer never travels in clear text and is never stored in the database.
- Per-IP brute-force lockout — after N failed attempts (default 5) the IP address is locked out for X minutes (default 15). Wrong captcha and honeypot hits count too; a successful login resets the counter. The lockout applies even with correct credentials.
- Honeypot — a field hidden from humans: whoever fills it in is a bot and gets rejected without hints.
- Unified error messages — no username enumeration: “unknown user” and “wrong password” produce the same generic message.
- Reduced attack surface — XML-RPC disabled, X-Pingback header removed, public REST user endpoints removed (they remain available to users who can edit posts, for the block editor), and
?author=Nrequests plus author archives redirect to the home page: no username scraping.
Customizable appearance
- Title, subtitle and footer message
- Custom logo from the media library, with a configurable clickable link (empty = site home)
- Two Google Fonts to choose from: Syne, Instrument Sans, Inter, Space Grotesk, Manrope, DM Sans, Outfit, Sora, Archivo, Playfair Display and JetBrains Mono (one for headings, one for body text)
- Three colors: background, text and accent (buttons and focus)
Compatibility
- The security gate runs as a late filter on the
authenticateflow: captcha and lockout always take precedence over valid credentials. The gate only acts on the wp-login.php form: XML-RPC is disabled entirely while LyoGate is active, and application password / REST requests follow the normal WordPress flow (should another plugin re-enable XML-RPC, its authentication is not intercepted by the captcha). - All settings live in a single database option; on uninstall, options and transients are removed (also on multi-site).
Screenshots



Installation
- Upload the
lyogatefolder to/wp-content/plugins/, or install the ZIP via Plugins Add New Upload Plugin. - Activate the plugin.
- Go to Settings LyoGate to pick title, logo, fonts and colors.
- Open your login page: the new look and the protection are already active.
FAQ
-
Can I disable the captcha?
-
Yes: in Settings LyoGate untick “Anti-robot captcha”. Honeypot and brute-force lockout stay active.
-
Am I locked out myself?
-
The lockout is per IP address and expires on its own (default 15 minutes). A successful login resets the counter immediately. With WP-CLI:
wp transient delete --allalso clears lockouts. -
Does it work with application passwords or mobile apps?
-
Yes: the captcha and lockout only act on the wp-login.php form. XML-RPC is disabled while LyoGate is active, so XML-RPC logins cannot happen at all; requests authenticated via REST or application passwords follow the normal WordPress flow.
-
No. LyoGate only touches the login form authentication flow and the appearance of the login page; no extra cookies, no tracking.
-
Does it work on multi-site?
-
Yes, and on uninstall it cleans up options on every site in the network.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“LyoGate — Login Security” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “LyoGate — Login Security” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.0
- First public release: arithmetic captcha with HMAC token, honeypot, per-IP brute-force lockout, unified anti-enumeration errors, protected XML-RPC and REST user endpoints, customizable appearance (logo, fonts, colors) under Settings LyoGate.
