Title: Login Security with Telegram Alerts
Author: gabrielrosca
Published: <strong>December 15, 2025</strong>
Last modified: August 26, 2026

---

Search plugins

![](https://ps.w.org/login-security-with-telegram-alerts/assets/banner-772x250.jpg?
rev=3420465)

![](https://ps.w.org/login-security-with-telegram-alerts/assets/icon.svg?rev=3420465)

# Login Security with Telegram Alerts

 By [gabrielrosca](https://profiles.wordpress.org/gabrielrosca/)

[Download](https://downloads.wordpress.org/plugin/login-security-with-telegram-alerts.1.1.1.zip)

 * [Details](https://wordpress.org/plugins/login-security-with-telegram-alerts/#description)
 * [Reviews](https://wordpress.org/plugins/login-security-with-telegram-alerts/#reviews)
 *  [Installation](https://wordpress.org/plugins/login-security-with-telegram-alerts/#installation)
 * [Development](https://wordpress.org/plugins/login-security-with-telegram-alerts/#developers)

 [Support](https://wordpress.org/support/plugin/login-security-with-telegram-alerts/)

## Description

Login Security with Telegram Alerts is your comprehensive solution for fortifying
WordPress login security and staying informed about critical site activities. It
actively combats brute-force attacks, enhances user authentication with multi-factor
options, and provides real-time alerts directly to your Telegram. Scalable for any
site size, from personal blogs to large enterprises, it ensures your WordPress site
remains secure and you’re always in the loop.

Key Features:

Login Security with Telegram Alerts is packed with powerful features designed to
give you peace of mind and full control over your site’s access.

 * **Brute-Force Protection:** Automatically blocks suspicious IP addresses after
   a configurable number of failed login attempts, effectively preventing dictionary
   attacks and credential stuffing.
 * **Real-time Telegram Notifications:** Receive instant alerts for failed login
   attempts and successful logins, delivered directly to your chosen Telegram channel,
   group, or private chat. This provides immediate awareness of critical site events,
   enabling prompt action.
 * **Cloudflare Turnstile (Anti-Bot):** Protect your login form from bots and automated
   brute-force attacks using a privacy-friendly, invisible alternative to reCAPTCHA.
 * **New Device Login Alerts:** Get instant email and Telegram notifications when
   a user logs in from an unrecognized device or browser.
 * **API Protection:** Easily disable XML-RPC and restrict the WordPress REST API
   to logged-in users only, closing common vulnerabilities.
 * **Comprehensive Activity Logging:** Maintains detailed records of both failed
   and successful login events, capturing critical information such as IP addresses,
   usernames, login times, and user agents. This log is invaluable for auditing 
   and identifying suspicious patterns.
 * **IP Management:** Block or unblock IP addresses directly from the Activity Log
   with one-click actions. Administrators can manually manage IP blacklists and 
   whitelists from the plugin’s settings page.
 * **WordPress Core Files Integrity Check:** Verify that WordPress core files haven’t
   been tampered with by comparing them against official checksums from WordPress.
   org.
 * **File Permissions Management:** Automatically check and fix file permissions
   to match WordPress security standards, ensuring your installation follows best
   practices.
 * **Custom Admin URL:** Hide your wp-admin login URL by creating a custom access
   point, adding an extra layer of security by obscurity.
 * **Geolocation Integration:** Includes location data in Telegram notifications,
   adding crucial context to security alerts and aiding in the investigation of 
   suspicious activities.
 * **Optional Email Two-Factor Authentication:** Site administrators can enable 
   an opt-in extra login step; users who choose to turn it on for their own account
   will be emailed a one-time verification code (delivered as a polished HTML email)
   each time they log in.
 * **User-Friendly Admin Interface:** An intuitive, tabbed settings page contributes
   to a clean and easy-to-use experience.
    Why Choose Login Security with Telegram
   Alerts?

Comprehensive Security: Provides advanced features that actively defend your site
against common and persistent threats.
 Instant Awareness: Critical updates are 
delivered directly to Telegram, facilitating immediate action and providing peace
of mind to site administrators. User-Friendly: Engineered for quick setup, often
achievable in minutes, with an intuitive interface that makes configuration accessible
to users of all technical levels. Performance Optimized: Built with efficiency in
mind, ensuring that robust security measures do not compromise site speed. Dedicated
Support: A passionate team is committed to providing prompt and helpful support,
aiming to ensure users maximize the plugin’s potential. Compatibility & Requirements:

WordPress Version: 5.0 or higher (Tested up to 7.1)
 PHP Version: 7.2 or higher (
PHP 7.4+ recommended for optimal performance and security) Performance Considerations:
Login Security with Telegram Alerts is designed with performance in mind:

Efficient API Calls: When interacting with external services like Telegram’s API,
the plugin uses WordPress’s built-in HTTP API for reliable and performant requests,
minimizing impact on page load times.
 Optimized Database Interactions: Designed
to minimize database queries and employs best practices for data storage and retrieval,
ensuring your site’s database remains lean and responsive. Lightweight Codebase:
Development emphasizes avoiding bloated scripts and unnecessary assets, ensuring
the plugin adds minimal overhead to site resources. Security Best Practices: Beyond
merely claiming to be “secure,” Login Security with Telegram Alerts implements rigorous
security measures:

Nonces: All critical actions and forms within the plugin utilize WordPress Nonces
to protect against Cross-Site Request Forgery (CSRF) attacks.
 Input Sanitization:
All user input is rigorously sanitized before processing or storage to prevent malicious
code injection, such as Cross-Site Scripting (XSS) attacks. Output Escaping: Data
displayed on both the frontend and backend is properly escaped to prevent XSS vulnerabilities.
Capability Checks: Access to plugin functionalities is strictly controlled by checking
user capabilities using current_user_can(), preventing unauthorized users from performing
actions they are not permitted to. Regular Audits: The plugin’s codebase undergoes
regular scanning and updates to address emerging security vulnerabilities. Internationalization(
i18n): Login Security with Telegram Alerts is fully internationalized, allowing 
for seamless translation into any language. All strings are meticulously wrapped
in gettext functions, and a dedicated text domain (login-security-with-telegram-
alerts) ensures compatibility with WordPress’s robust translation system.

### Third-Party Services

This plugin may connect to external services to provide certain features:

**Telegram API (api.telegram.org)**
 – Used for: Sending security notifications 
to your configured Telegram bot – Triggered when: You enable Telegram notifications
and configure a bot token and chat ID – Privacy Policy: https://telegram.org/privacy–
Terms: https://telegram.org/tos

**IP Geolocation (ip-api.com)**
 – Used for: Looking up geographical location of
login attempts – Triggered when: Geolocation is enabled in settings (optional feature)–
Privacy Policy: https://ip-api.com/docs/legal – Data sent: IP addresses only

**Cloudflare Turnstile (challenges.cloudflare.com)**
 – Used for: Protecting the
login form from bots – Triggered when: You enable Cloudflare Turnstile in settings
and provide site keys – Privacy Policy: https://www.cloudflare.com/privacypolicy/–
Terms: https://www.cloudflare.com/website-terms/

All external service connections are optional and only occur when explicitly enabled
by the administrator. No data is sent without your configuration and consent.

## Screenshots

[[

[[

[[

[[

[[

[[

[[

[[

## Installation

Easy Setup (Recommended):

Go to your WordPress Dashboard. Navigate to Plugins > Add New. Search for “Login
Security with Telegram Alerts”. Click “Install Now” and then “Activate”. Once activated,
go to Login Security in your WordPress admin menu (under Settings). Telegram Integration:
Follow the on-screen instructions to obtain your Telegram Bot API Token and Chat
ID. Enter these into the plugin settings. Configure your desired security settings(
e.g., failed login limits) and notification preferences. Save changes. The setup
is complete. Manual Installation:

Download the plugin .zip file from WordPress.org. Upload the plugin directory (login-
security-telegram-alerts) to the /wp-content/plugins/ directory via FTP/SFTP. Activate
the plugin through the ‘Plugins’ screen in WordPress. Proceed with steps 5-8 from“
Easy Setup” above. Troubleshooting:

If issues are encountered, ensure that WordPress and PHP versions meet the minimum
requirements. Verify that the Telegram Bot API Token and Chat ID are correctly entered.
The “Send Test Telegram Message” button in settings can be used for verification.
Check for potential plugin conflicts by temporarily deactivating other plugins. 
For further assistance, please refer to the FAQ section or the dedicated support
forums.

## FAQ

Q: What is Login Security with Telegram Alerts for?
 A: Login Security with Telegram
Alerts is a comprehensive WordPress security plugin primarily focused on preventing
brute-force attacks, logging login activity, and providing real-time notifications
of critical site events to Telegram.

Q: Is Login Security with Telegram Alerts free?
 A: Yes, the Login Security with
Telegram Alerts plugin is absolutely free to use and provides robust security features.

Q: How does Login Security with Telegram Alerts protect against brute-force attacks?

A: It limits the number of failed login attempts from a single IP address. After
a configurable threshold is reached, the IP is temporarily blocked, preventing automated
password guessing attacks.

Q: Can I customize the Telegram notifications?
 A: Yes, you can enable/disable specific
notification types (e.g., failed logins, successful logins) from the plugin settings.

Q: How does the email two-factor authentication feature work?
 A: An administrator
first turns the feature on from the “Two-Factor Auth (Email)” settings tab. This
does not enable it for anyone by itself — each user then chooses, from their own
Profile page, whether to require a one-time email code at login. It is entirely 
opt-in and off by default for every user.

Q: What is a Telegram Bot API Token and Chat ID?
 A: The Telegram Bot API Token 
is a unique key for a Telegram bot, enabling it to send messages. The Chat ID identifies
the specific user, group, or channel to which messages will be sent. Instructions
for obtaining these are provided within the plugin settings.

Q: Is this plugin compatible with [specific theme/plugin]?
 A: Login Security with
Telegram Alerts is designed for broad compatibility with standard WordPress themes
and plugins. If a specific compatibility issue arises, please report it on the support
forum.

Q: Where can I get support?
 A: For free support, please visit the WordPress.org
support forums.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Login Security with Telegram Alerts” is open source software. The following people
have contributed to this plugin.

Contributors

 *   [ gabrielrosca ](https://profiles.wordpress.org/gabrielrosca/)

[Translate “Login Security with Telegram Alerts” into your language.](https://translate.wordpress.org/projects/wp-plugins/login-security-with-telegram-alerts)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/login-security-with-telegram-alerts/),
check out the [SVN repository](https://plugins.svn.wordpress.org/login-security-with-telegram-alerts/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/login-security-with-telegram-alerts/)
by [RSS](https://plugins.trac.wordpress.org/log/login-security-with-telegram-alerts/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.1.1

 * New: Added Cloudflare Turnstile (Anti-Bot) integration for the login form to 
   silently block automated attacks without annoying CAPTCHAs.
 * New: Added “New Device Alerts” feature which sends instant email and Telegram
   notifications when a user logs in from an unrecognized device or browser.
 * New: Added API Protection options to easily disable XML-RPC and restrict the 
   WordPress REST API to logged-in users only.
 * Improved: Redesigned the interface utilizing full-width tabs and a cleaner layout.

#### 1.1.0

 * New: Optional email-based Two-Factor Authentication. Disabled site-wide by default;
   once enabled by an administrator, each user can individually opt in from their
   own Profile page.
 * New: Verification codes are delivered as a branded HTML email, with configurable
   expiry, attempt limits, and resend cooldown.
 * Fix: The WordPress Core Files Integrity Check no longer flags the optional, commonly-
   deleted Akismet and Hello Dolly plugins, or the bundled default “Twenty Twenty-*”
   themes, as “missing” files — none of these are required by WordPress and are 
   now excluded from the check.
 * Improved: Refreshed the settings page UI — grouped sections into cards, added
   toggle switches for on/off options, and icons on the tab bar, while keeping standard
   WordPress admin conventions (nav-tabs, form-table, notices) intact.

#### 1.0.0 –

 * Initial Release of Login Security plugin
 * Brute-Force Protection with configurable attempt limits
 * Telegram Notifications for failed and successful logins
 * Comprehensive Activity Logging with filtering
 * IP Management with Block/Unblock functionality
 * Manual IP Blacklist and Whitelist
 * WordPress Core Files Integrity Check
 * File Permissions Check and Fix tool
 * Custom Admin URL for enhanced security
 * Geolocation integration for login notifications
 * Clean and intuitive admin interface

## Meta

 *  Version **1.1.1**
 *  Last updated **4 weeks ago**
 *  Active installations **100+**
 *  WordPress version ** 5.0 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.2 or higher **
 * Tags
 * [Brute Force](https://wordpress.org/plugins/tags/brute-force/)[login security](https://wordpress.org/plugins/tags/login-security/)
   [Notifications](https://wordpress.org/plugins/tags/notifications/)[telegram](https://wordpress.org/plugins/tags/telegram/)
   [two factor authentication](https://wordpress.org/plugins/tags/two-factor-authentication/)
 *  [Advanced View](https://wordpress.org/plugins/login-security-with-telegram-alerts/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/login-security-with-telegram-alerts/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/login-security-with-telegram-alerts/reviews/)

## Contributors

 *   [ gabrielrosca ](https://profiles.wordpress.org/gabrielrosca/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/login-security-with-telegram-alerts/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://ko-fi.com/gabrielrosca)