Title: A360 Login Avatar Panel
Author: team A360
Published: <strong>July 19, 2026</strong>
Last modified: July 19, 2026

---

Search plugins

![](https://ps.w.org/a360-login-avatar-panel/assets/banner-772x250.png?rev=3613964)

![](https://ps.w.org/a360-login-avatar-panel/assets/icon-256x256.png?rev=3613918)

# A360 Login Avatar Panel

 By [team A360](https://profiles.wordpress.org/igorrubas/)

[Download](https://downloads.wordpress.org/plugin/a360-login-avatar-panel.1.4.zip)

 * [Details](https://wordpress.org/plugins/a360-login-avatar-panel/#description)
 * [Reviews](https://wordpress.org/plugins/a360-login-avatar-panel/#reviews)
 *  [Installation](https://wordpress.org/plugins/a360-login-avatar-panel/#installation)
 * [Development](https://wordpress.org/plugins/a360-login-avatar-panel/#developers)

 [Support](https://wordpress.org/support/plugin/a360-login-avatar-panel/)

## Description

A360 Login Avatar Panel adds a simple visual verification step to the WordPress 
login form.

Administrators can enable the panel globally and assign one required avatar to each
user. During login, the user enters the normal WordPress username and password, 
then selects the assigned avatar from a randomized icon grid.

The avatar selection is checked only after WordPress has already validated the username
and password. This avoids exposing whether a username exists through the avatar 
step.

This plugin is intended as an additional login barrier. It is not a replacement 
for a proper two-factor authentication plugin.

Features:

 * Enable or disable the login avatar panel.
 * Assign required avatars per user.
 * Randomize the avatar order on every login page load.
 * Keep normal WordPress login and password handling unchanged.
 * Validate the avatar only after successful password authentication.
 * Customize the login page background color and background image.
 * Track failed and successful login activity.
 * Temporarily block IP addresses after repeated failed login attempts.
 * Send an administrator email when failed attempts from one IP exceed the configured
   threshold.
 * Optionally block XML-RPC requests when remote publishing or Jetpack is not needed.
 * Show a login security dashboard widget and security report in plugin settings.
 * Save safelist and denylist entries for IP addresses/ranges and usernames.
 * Reset the lockout counter from the security settings tab.

### Privacy

A360 Login Avatar Panel stores plugin settings and login activity data in WordPress
options. Successful login counters store timestamps only. Failed login details store
timestamp, IP address, attempted username, failure reason, and browser user agent
for security monitoring, temporary IP blocking, and administrator email alerts. 
Safelist and denylist values are stored only when an administrator enters them in
the Security tab.

## Screenshots

[⌊User avatar assignment panel.⌉⌊User avatar assignment panel.⌉[

User avatar assignment panel.

[⌊Avatar selection on the WordPress login screen.⌉⌊Avatar selection on the WordPress
login screen.⌉[

Avatar selection on the WordPress login screen.

[⌊Login security report and access-rule settings.⌉⌊Login security report and access-
rule settings.⌉[

Login security report and access-rule settings.

## Installation

 1. Upload the `a360-login-avatar-panel` folder to `/wp-content/plugins/`.
 2. Activate the plugin through the Plugins screen in WordPress.
 3. Go to Settings > Login Avatar Panel.
 4. Enable the panel and assign avatars to selected users.
 5. Save settings.
 6. Review login activity in the Security tab.

## FAQ

### Is this real 2FA?

No. It is an additional visual login barrier, not full two-factor authentication.
For critical admin accounts, use a dedicated 2FA plugin as well.

### Does it change WordPress passwords?

No. WordPress still validates usernames and passwords normally.

### Does the plugin reveal whether a login exists?

The avatar is checked only after WordPress has authenticated the user with the correct
password, so a wrong avatar does not reveal whether a public username exists.

### Can I disable the panel for one user?

Yes. In Settings > Login Avatar Panel, choose “No panel” for that user.

### What login data is stored?

The plugin stores event timestamps for successful login activity. For failed login
activity, it stores the timestamp, IP address, attempted username, failure reason,
and browser user agent. It does not store passwords or submitted passwords.

### Can I block XML-RPC?

Yes. Enable “Block XML-RPC requests” in Settings > Login Avatar Panel > Security.
Do not enable it if you rely on Jetpack, the WordPress mobile app, or remote publishing
through XML-RPC.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“A360 Login Avatar Panel” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ team A360 ](https://profiles.wordpress.org/igorrubas/)

[Translate “A360 Login Avatar Panel” into your language.](https://translate.wordpress.org/projects/wp-plugins/a360-login-avatar-panel)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/a360-login-avatar-panel/),
check out the [SVN repository](https://plugins.svn.wordpress.org/a360-login-avatar-panel/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/a360-login-avatar-panel/)
by [RSS](https://plugins.trac.wordpress.org/log/a360-login-avatar-panel/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.4

 * Added a branded banner to the plugin details modal.
 * Updated WordPress.org banner artwork.

#### 1.3

 * Added an optional XML-RPC request blocker.

#### 1.2

 * Added temporary IP blocking for repeated failed login attempts.
 * Added administrator email alerts for repeated failed attempts from one IP address.
 * Added detailed failed login records with IP address, attempted username, failure
   reason, and browser user agent.

#### 1.1

 * Added failed and successful login tracking.
 * Added login security dashboard widget.
 * Added Security tab under Settings > Login Avatar Panel.
 * Added lockout counter reset.
 * Added safelist and denylist settings for IP addresses/ranges and usernames.
 * Improved admin settings layout for security controls.
 * Added login background color/image settings.

#### 1.0.0

 * Initial release.

## Meta

 *  Version **1.4**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.0.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [admin](https://wordpress.org/plugins/tags/admin/)[authentication](https://wordpress.org/plugins/tags/authentication/)
   [avatar](https://wordpress.org/plugins/tags/avatar/)[login](https://wordpress.org/plugins/tags/login/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/a360-login-avatar-panel/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/a360-login-avatar-panel/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/a360-login-avatar-panel/reviews/)

## Contributors

 *   [ team A360 ](https://profiles.wordpress.org/igorrubas/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/a360-login-avatar-panel/)