Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Sentinel Login Guard

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Sentinel Login Guard

By Hossein Ahmadi
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Sentinel Login Guard is a professional security plugin that hides the default WordPress login page and provides geographic restriction based on visitor IP.

Features:

  • Hide the default wp-login.php and /wp-admin paths
  • Custom login URL (your own secret slug)
  • Geographic restriction by country
  • IP Whitelist and Blacklist (single IPs and ranges: CIDR, range, single)
  • Login statistics: successful and failed attempts with country/city info
  • One-click block/allow from the statistics page
  • Choose the behavior for unauthorized visitors (Home, 404, Custom URL)
  • Emergency fallback mode for Geo service failures
  • One-click “Add my IP to Whitelist” button
  • Full RTL and translation support

External services

This plugin connects to the ipwho.is service to detect the visitor’s country for geo-restriction of the login page.

External Service Details:

  • Service name: ipwho.is
  • Service URL: https://ipwho.is/
  • Terms of Use: This service does not publish a public Terms page.
  • Privacy Policy: This service does not publish a public Privacy page.

Data sent: Only the visitor’s IP address is sent to https://ipwho.is/{visitor-ip}. No other data, headers, cookies, or personal information are transmitted.

When: The request is made when a visitor attempts to access the login page.

Purpose: To retrieve the ISO country code (e.g., “IR”) to decide whether the visitor is allowed to see the login form.

Caching: Results are cached locally in the WordPress database using transients for 1 hour.

Fallback: If the service fails, the plugin has an “Emergency mode” setting. When enabled (default), access is allowed so the site admin is never locked out.

Privacy

Login log data:
This plugin stores a temporary record of login attempts (both successful and failed) for security auditing purposes. The stored data includes: visitor IP, country, city, and login status. This data is retained for 30 days and automatically deleted afterward. The legal basis for this processing is legitimate interest in securing the website (GDPR Recital 49).

No third-party tracking:
The plugin does not use any external services for tracking, analytics, or user profiling. ipwho.is is used solely for country detection.

Data retention:

  • Login records are automatically deleted after 30 days via a daily cleanup task.
  • Transient cache entries (country code, country name, city name) automatically expire after 1 hour.
  • If the plugin is uninstalled, all options, transients, and the log table are deleted via uninstall.php.

Installation

  1. Upload the sentinel-login-guard folder to /wp-content/plugins/.
  2. Activate the plugin from the Plugins menu.
  3. Go to Settings > Sentinel Login Guard.
  4. Add your own IP to the whitelist using the one-click button.
  5. Set your custom login slug and allowed countries.
  6. Save changes and flush permalinks (Settings > Permalinks > Save).

FAQ

Does this plugin work with caching plugins?

Yes, but you should clear the cache after changing any settings.

What happens if the Geo service is down?

If “Emergency mode” is enabled, you can still log in. Otherwise, visitors are redirected.

Can I use IP ranges?

Yes. Three formats are supported: CIDR, range, and single IP.

Can I disable geo-restriction completely?

Yes. Leave the “Allowed countries” field empty.

Is my IP address stored?

Yes, temporarily. Login attempts are logged with IP, country, and city for 30 days, then automatically deleted. This is used for security auditing only.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Sentinel Login Guard” is open source software. The following people have contributed to this plugin.

Contributors
  • Hossein Ahmadi

Translate “Sentinel Login Guard” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.1.0

  • Added login statistics tab with success/failure counts.
  • Added IP block/allow buttons in statistics.
  • Added IP blacklist option.
  • Added automatic 30-day cleanup of login logs.
  • Fixed inline script — now uses wp_enqueue_script.
  • Renamed all prefixes to SLGARD_ for consistency.
  • Updated readme with privacy section.

1.0.1

  • Fixed redirect issue after successful login.

1.0.0

  • Initial release.

Meta

  • Version 1.1.0
  • Last updated 24 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.0 or higher
  • Tested up to 7.1.3
  • PHP version 7.4 or higher
  • Tags
    Brute Forcegeohide loginlogin logsecurity
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • Hossein Ahmadi

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry