Title: DCI Admin Security
Author: DreamCode Infotech
Published: <strong>October 1, 2026</strong>
Last modified: October 1, 2026

---

Search plugins

![](https://ps.w.org/dci-admin-security/assets/banner-772x250.png?rev=3723214)

![](https://ps.w.org/dci-admin-security/assets/icon-128x128.png?rev=3723214)

# DCI Admin Security

 By [DreamCode Infotech](https://profiles.wordpress.org/dreamcodeinfotech/)

[Download](https://downloads.wordpress.org/plugin/dci-admin-security.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/dci-admin-security/#description)
 * [Reviews](https://wordpress.org/plugins/dci-admin-security/#reviews)
 *  [Installation](https://wordpress.org/plugins/dci-admin-security/#installation)
 * [Development](https://wordpress.org/plugins/dci-admin-security/#developers)

 [Support](https://wordpress.org/support/plugin/dci-admin-security/)

## Description

Protect WordPress login and wp-admin with IP allowlisting, custom login URLs, email
OTP, rate limiting, CAPTCHA, logging and alerts.

### Features

 * Allow exact IPv4/IPv6 addresses and CIDR ranges.
 * Accept IPv4 shorthand such as `171.61`, stored as `171.61.0.0/16`.
 * Change the WordPress login URL.
 * Protect the normal `wp-login.php` endpoint.
 * Restrict `wp-admin` by IP while keeping `admin-ajax.php` available.
 * Optional Cloudflare `CF-Connecting-IP` detection.
 * Optional trusted `X-Forwarded-For` detection for known reverse-proxy setups.
 * Optional localhost/loopback bypass for local development.
 * Brute-force rate limiting and temporary lockouts.
 * Email OTP verification for administrators, delivered to each administrator’s 
   WordPress profile email address.
 * Administrator-configured emergency fallback code for environments where email
   cannot be delivered.
 * Optional Google reCAPTCHA v2, reCAPTCHA v3 or hCaptcha on the WordPress login
   form.
 * Security event logging with an administrator viewer and configurable retention.
 * Optional email and Slack alerts for repeated blocked-IP or brute-force events.

### Important

Keep at least one known administrator IP in the allowlist before enabling IP protection.

Only enable Cloudflare IP detection when the site is actually behind Cloudflare.
Only enable trusted `X-Forwarded-For` when the server is behind a trusted reverse
proxy that sets that header.

On localhost, PHP commonly sees `127.0.0.1` or `::1` rather than the browser’s public
VPN address. Use a publicly reachable staging site for an end-to-end VPN IP test.

The emergency fallback code is stored as a password hash and is never displayed 
after saving.

### External Services

This plugin can optionally communicate with third-party CAPTCHA verification services
when CAPTCHA is enabled:

 * Google reCAPTCHA: the login page loads Google reCAPTCHA assets and sends the 
   submitted CAPTCHA token to Google’s verification endpoint. See https://policies.
   google.com/privacy and https://policies.google.com/terms.
 * hCaptcha: the login page loads hCaptcha assets and sends the submitted CAPTCHA
   token to hCaptcha’s verification endpoint. See https://www.hcaptcha.com/privacy
   and https://www.hcaptcha.com/terms.

The plugin does not contact these services when CAPTCHA is disabled.

### IP access examples

Exact IP: `186.189.26.220`

IPv4 /16 shorthand: `171.61`

CIDR: `171.61.0.0/16`

### Email OTP

After a successful WordPress administrator password check, a six-digit OTP is generated
and sent to that administrator’s WordPress profile email address.

If email delivery is unavailable, an administrator-configured emergency fallback
code can be used.

## Screenshots

[[

[[

[[

## Installation

 1. Upload the plugin ZIP from Plugins > Add New > Upload Plugin.
 2. Activate DCI Admin Security.
 3. Open Settings > DCI Admin Security.
 4. Add at least one IP address or CIDR range that should be allowed to reach the protected
    login/admin area.
 5. Set the custom login slug.
 6. Save the General settings.
 7. Test the custom login URL before enabling strict IP protection on a production 
    site.
 8. Configure Email OTP, CAPTCHA, rate limiting and alerts as required.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“DCI Admin Security” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ DreamCode Infotech ](https://profiles.wordpress.org/dreamcodeinfotech/)

[Translate “DCI Admin Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/dci-admin-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/dci-admin-security/),
check out the [SVN repository](https://plugins.svn.wordpress.org/dci-admin-security/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/dci-admin-security/)
by [RSS](https://plugins.trac.wordpress.org/log/dci-admin-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Resolved Plugin Check database-query and nonce warnings.
 * Sanitized emergency fallback-code input.
 * Added explicit versions to CAPTCHA provider scripts.
 * Kept IP allowlist, email OTP, and WordPress.org compatibility fixes from 1.0.0.

#### 1.0.0

 * Removed the obsolete TOTP/two-factor authentication implementation and related
   files.
 * Fixed WordPress coding-standard issues in IP handling, AJAX actions, CAPTCHA 
   output and custom database queries.
 * Added proper login CAPTCHA script enqueueing and a CAPTCHA nonce.
 * Improved PHP 7.4 compatibility by removing PHP 8-only string helper usage.
 * Updated documentation and feature list for the email OTP implementation.

#### 2.4.10

 * Improved IP allowlist matching and localhost development controls.
 * Added IP diagnostics and test tools.

#### 2.4.6

 * Added explicit trusted proxy handling for `X-Forwarded-For`.
 * Normalized IPv4-mapped IPv6 client addresses.

#### 2.0.0

 * Added brute-force rate limiting, CAPTCHA, security logging and alerts.
 * Added administrator email OTP verification.

#### 1.0.0

 * Initial release with IP allowlist and custom login URL protection.

## Meta

 *  Version **1.0.0**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [admin security](https://wordpress.org/plugins/tags/admin-security/)[custom login](https://wordpress.org/plugins/tags/custom-login/)
   [ip whitelist](https://wordpress.org/plugins/tags/ip-whitelist/)[login security](https://wordpress.org/plugins/tags/login-security/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/dci-admin-security/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/dci-admin-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/dci-admin-security/reviews/)

## Contributors

 *   [ DreamCode Infotech ](https://profiles.wordpress.org/dreamcodeinfotech/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/dci-admin-security/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://ko-fi.com/dreamcodeinfotech)