Description
NibbleSecure protects your WordPress login page from bots, scanners, and brute force attacks. It hides your default wp-login.php page behind a secret URL, so automated login attacks never even find your real login form.
On top of hiding your login page, NibbleSecure limits login attempts and locks out an IP address once it crosses your configured threshold. The lockout period grows for repeat offenders. It then sends you an instant email alert when that happens. No external service, API key, or subscription is required.
NibbleSecure runs natively on WordPress’s own database. It’s lightweight, fast, and 100% free.
Looking for Two-Factor Authentication (2FA)? Two-Factor Authentication (2FA/TOTP) compatible with Google Authenticator, Authy, Microsoft Authenticator, and 1Password is available through the separate NibbleSecure PRO add-on, along with heuristic malware scanning, file integrity monitoring, self-healing plugin protection, session hijacking control, Application-Layer (L7) DDoS protection, advanced .htaccess server hardening, an automated 404 scanner with IP auto-ban, manual IP/country blocking, scheduled automatic backups with one-click restore, and a math CAPTCHA on the login and lost-password forms. These PRO features are not included in this free version – see “Available in PRO Version” below for details.
Free Version Capabilities
- Hide Login (Secret Login URL)
- Limit Login Attempts & Brute Force Protection
- Configurable Lockout Thresholds with Escalating Repeat-Offense Penalties
- Email Alerts & Secret URL Backup
Available in PRO Version
The following features require the separate, self-hosted NibbleSecure PRO add-on (https://mvpplugins.com/nibblesecure/) and are not part of this free plugin:
- Two-Factor Authentication (2FA/TOTP) – Adds a second verification step at login using Google Authenticator, Authy, Microsoft Authenticator, 1Password, or other standard authenticator apps, with emergency backup codes and secure email-based recovery if you lose your device.
- Heuristic Malware Detection & File Integrity Monitoring – Scans plugin and core files every hour against SHA-256 baselines to catch unauthorized changes, injected code, and malware.
- Self-Healing Plugin Protection – Automatically restores NibbleSecure’s own core files if an attacker deletes or tampers with them.
- Session Hijacking Control – Detects unauthorized concurrent device logins and lets you instantly log out every other active session.
- Application-Layer (L7) DDoS & Flood Protection – Rate-limits and blocks malicious traffic spikes and botnet floods before they reach your server.
- Scheduled Automatic WordPress Backups & Restore – Creates scheduled restore points for your database, files, and configuration, with one-click recovery.
- Advanced Server Hardening (.htaccess Tweaks) – XML-RPC and pingback toggles, hidden-file blocking (.git, .env), bad-bot and malicious query-string blocking, and other server-level hardening options.
- Automated 404 Scanner & IP Auto-Ban – Detects IPs that repeatedly request non-existent pages within a short time window (a common sign of vulnerability scanning) and automatically bans them for a configurable duration, independent of the login-attempt counter.
- Manual IP, IP Range & Country Blocking – Instantly allow or block specific IP addresses, IP ranges, or entire countries from accessing your site, from a dedicated management panel.
- Math CAPTCHA on Login & Lost Password Forms – Adds a simple math challenge to the login and password-reset forms to stop automated bot submissions before they reach the brute-force checks.
Screenshots



Installation
- Upload the plugin folder to your server’s /wp-content/plugins/ folder, or install the plugin package directly via the WordPress Admin Plugins panel screen.
- Click “Activate” on NibbleSecure from your Plugins dashboard.
- Open the new “NibbleSecure” settings tab under your WordPress admin settings.
- Set and save your custom secret login URL slug.
- Set your preferred maximum failed login attempts and lockout duration.
FAQ
-
What does the Hide Login feature do?
-
NibbleSecure replaces public access to your default wp-login.php page with a unique secret URL. Anyone or any bot trying to reach the standard login page is blocked before it ever loads.
-
What happens if I forget my secret login URL?
-
Your secret login URL is shown in an on-screen notice right after you activate the plugin, and it’s always visible on the NibbleSecure settings page. If you’d also like a copy emailed to you, use the “Email Me” button on the settings page: enter your admin email and it will send your current secret login URL to your inbox. No email is sent automatically; this only happens when you choose to click that button.
-
How does Limit Login Attempts & Brute Force Protection work?
-
NibbleSecure tracks failed login attempts by IP address. Once an IP crosses your configured maximum attempts, it’s locked out from logging in for your set lockout period. If the same IP gets locked out again within 24 hours, each repeat offense adds your configured “Compounding Progression Interval” on top of the base lockout, so persistent attackers face progressively longer bans. If your site sits behind a trusted proxy or CDN, see the
nibblesecure_trusted_proxy_headersfilter to configure which proxy header, if any, should be trusted for identifying the real visitor IP. This is a code-level setting for developers, added via a filter in your theme or a small custom plugin; it is not a toggle found on the Brute Force settings tab, since the correct header depends on your specific hosting/CDN setup. -
Does this free version require any outside subscription services?
-
No. NibbleSecure runs entirely on your own WordPress database. It doesn’t load external tracking scripts or require any paid cloud API to hide your login page or limit login attempts.
-
Will login security checks slow down my site?
-
No. NibbleSecure is built to be lightweight. Login attempt checks and lockout lookups are optimized to have minimal impact on your site’s load time.
-
The locked settings tabs preview PRO-only features: Two-Factor Authentication (2FA/TOTP), malware & file integrity scanning, session hijacking control, Application-Layer (L7) DDoS protection, advanced .htaccess server hardening, an automated 404 scanner with IP auto-ban, manual IP/country blocking, a login math CAPTCHA, and scheduled backups with one-click restore. These are unlocked by installing the separate, self-hosted NibbleSecure PRO add-on from our website. The free version on WordPress.org is fully functional without it.
-
Does NibbleSecure support Two-Factor Authentication (2FA)?
-
Two-Factor Authentication (2FA/TOTP) is not included in this free version. It’s available exclusively through the separate NibbleSecure PRO add-on. Once installed, NibbleSecure PRO adds TOTP-based two-factor authentication compatible with Google Authenticator, Authy, Microsoft Authenticator, 1Password, and other standard authenticator apps. It also adds emergency backup codes and secure email recovery if you ever lose your device.
-
What is Two-Factor Authentication and why should I use it?
-
Two-Factor Authentication (2FA) adds a second verification step after your username and password: a time-based 6-digit code from an authenticator app. This keeps your account protected even if your password is stolen, guessed, or leaked elsewhere. This free version protects your login with a secret login URL, limit login attempts, and brute force protection; full 2FA/TOTP support is available in the NibbleSecure PRO add-on.
-
Does NibbleSecure block bots that scan my site for vulnerabilities?
-
The free version’s Limit Login Attempts & Brute Force Protection only tracks failed login attempts. Detecting and auto-banning IPs that repeatedly probe non-existent pages is a separate PRO-only feature, Automated 404 Scanner & IP Auto-Ban. Repeatedly probing non-existent pages is a common sign of vulnerability scanning. This feature is available through the NibbleSecure PRO add-on.
-
Can I manually block specific IPs or countries?
-
Not in this free version. Manual IP, IP range, and country blocking is available through the NibbleSecure PRO add-on, which includes a dedicated management panel for adding and removing blocks.
-
Does NibbleSecure include a CAPTCHA on the login form?
-
Not in this free version. A math CAPTCHA on the login and lost-password forms, which helps stop automated bot submissions before they reach the brute-force checks, is available through the NibbleSecure PRO add-on.
-
Does NibbleSecure protect against DDoS attacks?
-
Not in this free version. Application-Layer (L7) DDoS & Flood Protection, which rate-limits and blocks malicious traffic spikes and botnet floods before they reach your server, is available through the NibbleSecure PRO add-on.
-
Can NibbleSecure back up my site automatically?
-
Not in this free version. Scheduled automatic backups with one-click restore, covering your database, files, and configuration, are available through the NibbleSecure PRO add-on.
-
Does NibbleSecure stop attackers from discovering my usernames?
-
Not in this free version. Blocking author/user enumeration attacks, a common technique bots use to discover valid usernames before attempting a brute-force login, is available through the NibbleSecure PRO add-on.
-
Can NibbleSecure block content scrapers that use my site’s RSS feed?
-
Not in this free version. Blocking RSS/Atom feeds from content scrapers is available through the NibbleSecure PRO add-on.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“NibbleSecure – Hide Login, Limit Login Attempts & Brute Force Shield” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “NibbleSecure – Hide Login, Limit Login Attempts & Brute Force Shield” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.0
- Initial release.
- Hide Login (secret login URL) protection.
- Limit Login Attempts & Brute Force Protection with configurable, escalating IP lockout thresholds.
- Email alerts for brute-force lockouts, plus a “Email Me” option to receive your secret login URL by email at any time.
