Title: LyoGate — Login Security
Author: Andres Hunger
Published: <strong>September 30, 2026</strong>
Last modified: September 30, 2026

---

Search plugins

![](https://ps.w.org/lyogate/assets/banner-772x250.png?rev=3721913)

![](https://ps.w.org/lyogate/assets/icon-256x256.png?rev=3721940)

# LyoGate — Login Security

 By [Andres Hunger](https://profiles.wordpress.org/andresitaly/)

[Download](https://downloads.wordpress.org/plugin/lyogate.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/lyogate/#description)
 * [Reviews](https://wordpress.org/plugins/lyogate/#reviews)
 *  [Installation](https://wordpress.org/plugins/lyogate/#installation)
 * [Development](https://wordpress.org/plugins/lyogate/#developers)

 [Support](https://wordpress.org/support/plugin/lyogate/)

## Description

LyoGate replaces the default WordPress login page with a modern, protected one. 
Everything is configured from **Settings  LyoGate**. No external accounts, no third-
party services: everything runs on your own site.

**Security**

 * **Arithmetic captcha** — a simple sum is required before signing in, backed by
   an HMAC-signed token with expiry (10 minutes): the answer never travels in clear
   text and is never stored in the database.
 * **Per-IP brute-force lockout** — after N failed attempts (default 5) the IP address
   is locked out for X minutes (default 15). Wrong captcha and honeypot hits count
   too; a successful login resets the counter. The lockout applies even with correct
   credentials.
 * **Honeypot** — a field hidden from humans: whoever fills it in is a bot and gets
   rejected without hints.
 * **Unified error messages** — no username enumeration: “unknown user” and “wrong
   password” produce the same generic message.
 * **Reduced attack surface** — XML-RPC disabled, X-Pingback header removed, public
   REST user endpoints removed (they remain available to users who can edit posts,
   for the block editor), and `?author=N` requests plus author archives redirect
   to the home page: no username scraping.

**Customizable appearance**

 * Title, subtitle and footer message
 * Custom logo from the media library, with a configurable clickable link (empty
   = site home)
 * Two Google Fonts to choose from: Syne, Instrument Sans, Inter, Space Grotesk,
   Manrope, DM Sans, Outfit, Sora, Archivo, Playfair Display and JetBrains Mono (
   one for headings, one for body text)
 * Three colors: background, text and accent (buttons and focus)

**Compatibility**

 * The security gate runs as a late filter on the `authenticate` flow: captcha and
   lockout always take precedence over valid credentials. The gate only acts on 
   the wp-login.php form: XML-RPC is disabled entirely while LyoGate is active, 
   and application password / REST requests follow the normal WordPress flow (should
   another plugin re-enable XML-RPC, its authentication is not intercepted by the
   captcha).
 * All settings live in a single database option; on uninstall, options and transients
   are removed (also on multi-site).

## Screenshots

[⌊The login page with the default dark theme, captcha and subtitle.⌉⌊The login page
with the default dark theme, captcha and subtitle.⌉[

The login page with the default dark theme, captcha and subtitle.

[⌊The configuration screen in Settings → LyoGate.⌉⌊The configuration screen in Settings
→ LyoGate.⌉[

The configuration screen in Settings  LyoGate.

[⌊The lockout message after too many failed attempts.⌉⌊The lockout message after
too many failed attempts.⌉[

The lockout message after too many failed attempts.

## Installation

 1. Upload the `lyogate` folder to `/wp-content/plugins/`, or install the ZIP via Plugins
    Add New  Upload Plugin.
 2. Activate the plugin.
 3. Go to **Settings  LyoGate** to pick title, logo, fonts and colors.
 4. Open your login page: the new look and the protection are already active.

## FAQ

### Can I disable the captcha?

Yes: in **Settings  LyoGate** untick “Anti-robot captcha”. Honeypot and brute-force
lockout stay active.

### Am I locked out myself?

The lockout is per IP address and expires on its own (default 15 minutes). A successful
login resets the counter immediately. With WP-CLI: `wp transient delete --all` also
clears lockouts.

### Does it work with application passwords or mobile apps?

Yes: the captcha and lockout only act on the wp-login.php form. XML-RPC is disabled
while LyoGate is active, so XML-RPC logins cannot happen at all; requests authenticated
via REST or application passwords follow the normal WordPress flow.

### Does it add cookies or interfere with other plugins?

No. LyoGate only touches the login form authentication flow and the appearance of
the login page; no extra cookies, no tracking.

### Does it work on multi-site?

Yes, and on uninstall it cleans up options on every site in the network.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“LyoGate — Login Security” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ Andres Hunger ](https://profiles.wordpress.org/andresitaly/)

[Translate “LyoGate — Login Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/lyogate)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/lyogate/), check out
the [SVN repository](https://plugins.svn.wordpress.org/lyogate/), or subscribe to
the [development log](https://plugins.trac.wordpress.org/log/lyogate/) by [RSS](https://plugins.trac.wordpress.org/log/lyogate/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * First public release: arithmetic captcha with HMAC token, honeypot, per-IP brute-
   force lockout, unified anti-enumeration errors, protected XML-RPC and REST user
   endpoints, customizable appearance (logo, fonts, colors) under Settings  LyoGate.

## Meta

 *  Version **1.0.0**
 *  Last updated **21 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 8.0 or higher **
 * Tags
 * [Brute Force](https://wordpress.org/plugins/tags/brute-force/)[captcha](https://wordpress.org/plugins/tags/captcha/)
   [custom login](https://wordpress.org/plugins/tags/custom-login/)[login](https://wordpress.org/plugins/tags/login/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/lyogate/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/lyogate/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/lyogate/reviews/)

## Contributors

 *   [ Andres Hunger ](https://profiles.wordpress.org/andresitaly/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/lyogate/)