Description
Sentinel Login Guard is a professional security plugin that hides the default WordPress login page and provides geographic restriction based on visitor IP.
Features:
- Hide the default
wp-login.phpand/wp-adminpaths - Custom login URL (your own secret slug)
- Geographic restriction by country
- IP Whitelist and Blacklist (single IPs and ranges: CIDR, range, single)
- Login statistics: successful and failed attempts with country/city info
- One-click block/allow from the statistics page
- Choose the behavior for unauthorized visitors (Home, 404, Custom URL)
- Emergency fallback mode for Geo service failures
- One-click “Add my IP to Whitelist” button
- Full RTL and translation support
External services
This plugin connects to the ipwho.is service to detect the visitor’s country for geo-restriction of the login page.
External Service Details:
- Service name: ipwho.is
- Service URL: https://ipwho.is/
- Terms of Use: This service does not publish a public Terms page.
- Privacy Policy: This service does not publish a public Privacy page.
Data sent: Only the visitor’s IP address is sent to https://ipwho.is/{visitor-ip}. No other data, headers, cookies, or personal information are transmitted.
When: The request is made when a visitor attempts to access the login page.
Purpose: To retrieve the ISO country code (e.g., “IR”) to decide whether the visitor is allowed to see the login form.
Caching: Results are cached locally in the WordPress database using transients for 1 hour.
Fallback: If the service fails, the plugin has an “Emergency mode” setting. When enabled (default), access is allowed so the site admin is never locked out.
Privacy
Login log data:
This plugin stores a temporary record of login attempts (both successful and failed) for security auditing purposes. The stored data includes: visitor IP, country, city, and login status. This data is retained for 30 days and automatically deleted afterward. The legal basis for this processing is legitimate interest in securing the website (GDPR Recital 49).
No third-party tracking:
The plugin does not use any external services for tracking, analytics, or user profiling. ipwho.is is used solely for country detection.
Data retention:
- Login records are automatically deleted after 30 days via a daily cleanup task.
- Transient cache entries (country code, country name, city name) automatically expire after 1 hour.
- If the plugin is uninstalled, all options, transients, and the log table are deleted via
uninstall.php.
Installation
- Upload the
sentinel-login-guardfolder to/wp-content/plugins/. - Activate the plugin from the Plugins menu.
- Go to Settings > Sentinel Login Guard.
- Add your own IP to the whitelist using the one-click button.
- Set your custom login slug and allowed countries.
- Save changes and flush permalinks (Settings > Permalinks > Save).
FAQ
-
Does this plugin work with caching plugins?
-
Yes, but you should clear the cache after changing any settings.
-
What happens if the Geo service is down?
-
If “Emergency mode” is enabled, you can still log in. Otherwise, visitors are redirected.
-
Can I use IP ranges?
-
Yes. Three formats are supported: CIDR, range, and single IP.
-
Can I disable geo-restriction completely?
-
Yes. Leave the “Allowed countries” field empty.
-
Is my IP address stored?
-
Yes, temporarily. Login attempts are logged with IP, country, and city for 30 days, then automatically deleted. This is used for security auditing only.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Sentinel Login Guard” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Sentinel Login Guard” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.1.0
- Added login statistics tab with success/failure counts.
- Added IP block/allow buttons in statistics.
- Added IP blacklist option.
- Added automatic 30-day cleanup of login logs.
- Fixed inline script — now uses wp_enqueue_script.
- Renamed all prefixes to SLGARD_ for consistency.
- Updated readme with privacy section.
1.0.1
- Fixed redirect issue after successful login.
1.0.0
- Initial release.
