Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

LyoGate — Login Security

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

LyoGate — Login Security

By Andres Hunger
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

LyoGate replaces the default WordPress login page with a modern, protected one. Everything is configured from Settings → LyoGate. No external accounts, no third-party services: everything runs on your own site.

Security

  • Arithmetic captcha — a simple sum is required before signing in, backed by an HMAC-signed token with expiry (10 minutes): the answer never travels in clear text and is never stored in the database.
  • Per-IP brute-force lockout — after N failed attempts (default 5) the IP address is locked out for X minutes (default 15). Wrong captcha and honeypot hits count too; a successful login resets the counter. The lockout applies even with correct credentials.
  • Honeypot — a field hidden from humans: whoever fills it in is a bot and gets rejected without hints.
  • Unified error messages — no username enumeration: “unknown user” and “wrong password” produce the same generic message.
  • Reduced attack surface — XML-RPC disabled, X-Pingback header removed, public REST user endpoints removed (they remain available to users who can edit posts, for the block editor), and ?author=N requests plus author archives redirect to the home page: no username scraping.

Customizable appearance

  • Title, subtitle and footer message
  • Custom logo from the media library, with a configurable clickable link (empty = site home)
  • Two Google Fonts to choose from: Syne, Instrument Sans, Inter, Space Grotesk, Manrope, DM Sans, Outfit, Sora, Archivo, Playfair Display and JetBrains Mono (one for headings, one for body text)
  • Three colors: background, text and accent (buttons and focus)

Compatibility

  • The security gate runs as a late filter on the authenticate flow: captcha and lockout always take precedence over valid credentials. The gate only acts on the wp-login.php form: XML-RPC is disabled entirely while LyoGate is active, and application password / REST requests follow the normal WordPress flow (should another plugin re-enable XML-RPC, its authentication is not intercepted by the captcha).
  • All settings live in a single database option; on uninstall, options and transients are removed (also on multi-site).

Screenshots

The login page with the default dark theme, captcha and subtitle.
The login page with the default dark theme, captcha and subtitle.
The configuration screen in Settings → LyoGate.
The configuration screen in Settings → LyoGate.
The lockout message after too many failed attempts.
The lockout message after too many failed attempts.

Installation

  1. Upload the lyogate folder to /wp-content/plugins/, or install the ZIP via Plugins → Add New → Upload Plugin.
  2. Activate the plugin.
  3. Go to Settings → LyoGate to pick title, logo, fonts and colors.
  4. Open your login page: the new look and the protection are already active.

FAQ

Can I disable the captcha?

Yes: in Settings → LyoGate untick “Anti-robot captcha”. Honeypot and brute-force lockout stay active.

Am I locked out myself?

The lockout is per IP address and expires on its own (default 15 minutes). A successful login resets the counter immediately. With WP-CLI: wp transient delete --all also clears lockouts.

Does it work with application passwords or mobile apps?

Yes: the captcha and lockout only act on the wp-login.php form. XML-RPC is disabled while LyoGate is active, so XML-RPC logins cannot happen at all; requests authenticated via REST or application passwords follow the normal WordPress flow.

Does it add cookies or interfere with other plugins?

No. LyoGate only touches the login form authentication flow and the appearance of the login page; no extra cookies, no tracking.

Does it work on multi-site?

Yes, and on uninstall it cleans up options on every site in the network.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“LyoGate — Login Security” is open source software. The following people have contributed to this plugin.

Contributors
  • Andres Hunger

Translate “LyoGate — Login Security” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.0.0

  • First public release: arithmetic captcha with HMAC token, honeypot, per-IP brute-force lockout, unified anti-enumeration errors, protected XML-RPC and REST user endpoints, customizable appearance (logo, fonts, colors) under Settings → LyoGate.

Meta

  • Version 1.0.0
  • Last updated 21 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.0 or higher
  • Tested up to 7.1.2
  • PHP version 8.0 or higher
  • Tags
    Brute Forcecaptchacustom loginloginsecurity
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • Andres Hunger

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org
  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry
The WordPress® trademark is the intellectual property of the WordPress Foundation.