{"id":364448,"date":"2026-09-11T22:58:47","date_gmt":"2026-09-11T22:58:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/loginly\/"},"modified":"2026-09-12T10:38:46","modified_gmt":"2026-09-12T10:38:46","slug":"digitsummit-loginly","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/digitsummit-loginly\/","author":23559778,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"6.1.1","stable_tag":"6.1.1","tested":"7.1","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"DigitSummit Loginly","header_author":"DiGit Summit","header_description":"Brand your login page, move it to an address only you know, and secure the door \u2014 with a safety net that will not lock you out.","assets_banners_color":"282111","last_updated":"2026-09-12 10:38:46","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/loginly.digitsummit.net\/","header_author_uri":"https:\/\/digitsummit.net\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":64,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"6.1.0":{"tag":"6.1.0","author":"digitsummit","date":"2026-09-11 22:58:19","revision":3692189},"6.1.1":{"tag":"6.1.1","author":"digitsummit","date":"2026-09-12 10:38:46","revision":3692583}},"upgrade_notice":{"6.1.1":"<p>Only matters if you installed this plugin from a zip before: two active copies\nno longer collide, and the screen tells you which one to deactivate.<\/p>","6.1.0":"<p>Security release. The attempt slowdown and the anti-bot challenge were refusing\nnothing at all, and three requests could make the site hand out your hidden\nlogin address. Update.<\/p>","6.0.3":"<p>Housekeeping release: the version constant had drifted two releases behind, so\nbrowsers kept serving the old stylesheets. Nothing to do on your side.<\/p>","6.0.0":"<p>Security release: two ways around two-step verification and three around the\nhidden login address are closed. Some features moved to Loginly Pro, a separate\nplugin \u2014 what stays free stays free, and nothing you run today switches off.<\/p>","5.0.0":"<p>The interface is now English by default, with French shipped as a translation.\nNothing else changes; your settings are untouched.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3692189,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3692189,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3692189,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3692189,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":{"loginly\/login":{"$schema":"https:\/\/schemas.wp.org\/trunk\/block.json","apiVersion":3,"name":"loginly\/login","title":"Login","category":"widgets","icon":"unlock","description":"A login form that follows the styling of your login page.","textdomain":"digitsummit-loginly","supports":{"html":false,"align":["wide","full"],"spacing":{"margin":true,"padding":true}},"attributes":{"title":{"type":"string","default":""},"showRememberMe":{"type":"boolean","default":true},"rememberChecked":{"type":"boolean","default":false},"showLostPassword":{"type":"boolean","default":true},"showRegister":{"type":"boolean","default":false},"redirectTo":{"type":"string","default":""},"loggedInText":{"type":"string","default":""}},"editorScript":"loginly-block-editor","style":"loginly-block"}},"tagged_versions":["6.1.0","6.1.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3692189,"resolution":"1","location":"assets","locale":"","width":1200,"height":900},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3692189,"resolution":"2","location":"assets","locale":"","width":1200,"height":900},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3692189,"resolution":"3","location":"assets","locale":"","width":1200,"height":900},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3692189,"resolution":"4","location":"assets","locale":"","width":1200,"height":900},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3692189,"resolution":"5","location":"assets","locale":"","width":1200,"height":900}},"screenshots":{"1":"The editor, with the live preview of the login page.","2":"Settings: activation, exposure report, login address, door status.","3":"The exposure report: what a stranger actually gets from your site.","4":"A branded login screen \u2014 the visitor's side of the plugin.","5":"The access log: who signed in, when, and from where."}},"plugin_section":[],"plugin_tags":[3691,25642,602,1229,9217],"plugin_category":[38],"plugin_contributors":[280315],"plugin_business_model":[],"class_list":["post-364448","plugin","type-plugin","status-publish","hentry","plugin_tags-custom-login","plugin_tags-hide-login","plugin_tags-login","plugin_tags-login-security","plugin_tags-two-factor","plugin_category-authentication","plugin_contributors-digitsummit","plugin_committers-digitsummit"],"banners":{"banner":"https:\/\/ps.w.org\/digitsummit-loginly\/assets\/banner-772x250.png?rev=3692189","banner_2x":"https:\/\/ps.w.org\/digitsummit-loginly\/assets\/banner-1544x500.png?rev=3692189","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/digitsummit-loginly\/assets\/icon-128x128.png?rev=3692189","icon_2x":"https:\/\/ps.w.org\/digitsummit-loginly\/assets\/icon-256x256.png?rev=3692189","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/digitsummit-loginly\/assets\/screenshot-1.png?rev=3692189","caption":"The editor, with the live preview of the login page."},{"src":"https:\/\/ps.w.org\/digitsummit-loginly\/assets\/screenshot-2.png?rev=3692189","caption":"Settings: activation, exposure report, login address, door status."},{"src":"https:\/\/ps.w.org\/digitsummit-loginly\/assets\/screenshot-3.png?rev=3692189","caption":"The exposure report: what a stranger actually gets from your site."},{"src":"https:\/\/ps.w.org\/digitsummit-loginly\/assets\/screenshot-4.png?rev=3692189","caption":"A branded login screen \u2014 the visitor's side of the plugin."},{"src":"https:\/\/ps.w.org\/digitsummit-loginly\/assets\/screenshot-5.png?rev=3692189","caption":"The access log: who signed in, when, and from where."}],"raw_content":"<!--section=description-->\n<p>DigitSummit Loginly takes care of the whole front door of your WordPress site: how it looks,\nwhere it lives, what protects it, and how you get back in when something goes\nwrong.<\/p>\n\n<p>Everything is edited from one screen with a live preview. No Customizer, so it\nworks the same on classic and block themes.<\/p>\n\n<h4>Looks<\/h4>\n\n<ul>\n<li>Logo, colours, background (solid, gradient or image), card, fields, button.<\/li>\n<li>Three layouts: centred, split screen with a visual panel, form to one side.<\/li>\n<li>Three ready-made templates \u2014 one per layout.<\/li>\n<li>A \"Login\" block for the editor: the same styling on any page.<\/li>\n<li>A built-in contrast check against WCAG 2.1 level AA, with a suggested fix when\na pair falls short.<\/li>\n<\/ul>\n\n<h4>A login address only you know<\/h4>\n\n<p>Serve the login page from <code>example.com\/your-address\/<\/code> and make <code>\/wp-login.php<\/code>\nanswer 404. This removes the automated background noise that hits every\nWordPress site around the clock.<\/p>\n\n<p><strong>It will not lock you out.<\/strong> After you apply a new address, the server calls it\nback like a logged-out visitor and checks that the form really appears \u2014 and\nthat the old address really stopped answering. If the check fails, the previous\nsetting is restored automatically. An hourly watch repeats that check: after\nthree consecutive failures, <code>\/wp-login.php<\/code> comes back and you are emailed. On\ntop of that: a recovery address, a <code>wp-config.php<\/code> constant, and a\n    wp loginly unlock command.<\/p>\n\n<h4>Security that is honest about itself<\/h4>\n\n<p>An exposure report queries your own site from the server, without being logged\nin, and tells you what a stranger actually gets: the account list through the\nREST API, the <code>?author=1<\/code> probe, the author sitemap. Most findings have a button\nthat closes them on the spot.<\/p>\n\n<p>The report also states plainly what moving the login page does <em>not<\/em> do. It is\nnot a lock. The lock is:<\/p>\n\n<ul>\n<li>attempt slowdown, per IP address, with a growing delay;<\/li>\n<li>a decoy field that costs nothing and depends on no third party;<\/li>\n<li>neutral error messages, so nobody learns which accounts exist;<\/li>\n<li>two-step verification by authenticator app, with backup codes.<\/li>\n<\/ul>\n\n<h4>What you keep a trace of<\/h4>\n\n<p>An access log with anonymised IP addresses: who came in, from where, with what\noutcome. Seven days by default \u2014 enough to understand what just happened \u2014 and\nup to a year if an audit asks for it.<\/p>\n\n<h4>What Loginly Pro adds<\/h4>\n\n<p>Loginly Pro is a separate plugin. Nothing here is switched off waiting for a\npayment: the code of these features is not in this plugin at all.<\/p>\n\n<p>One styling published once and fetched by every site under the same licence \u2014\nthe login address, the recovery key and the secrets of each site never travel.\nSign-in hours and approved addresses by role, a session length of your own,\npasswords checked against known breaches when they are chosen \u2014 the password\nnever leaves your server, only five characters of its fingerprint do. An\nanti-bot shield that asks nothing of your visitors and shows them to nobody:\nthe server sets a puzzle only solvable by trying, which a browser answers in a\nfraction of a second and a password-guessing program has to answer on every\nsingle attempt. An email the moment someone signs in from an origin never seen\non this site, a\nweekly summary, every event forwarded to Slack or your own endpoint with a\nsignature, and the log exported as CSV for an audit. Passkeys (Face ID, Touch\nID, Windows Hello, security keys), sign-in links sent by email, nine more\ntemplates, redirects by role or by user, the same styling on\nthe WooCommerce \"My account\" page and in the authentication emails, passkeys and\none-time sign-in links, leaked-password checking, sign-in hours and approved\naddresses by role, carrying a configuration from one site to the next, temporary\naccess links, connected-device limits, network-wide styling for multisite, and\nadmin white labelling.<\/p>\n\n<h4>Does it call anyone?<\/h4>\n\n<p>No analytics, no telemetry, no phone-home. Two-step verification runs entirely\non your own server. The full list of what can be contacted, and when, is in the\n\"External services\" section below.<\/p>\n\n<h3>Source code and build<\/h3>\n\n<p>The admin interface is written in JSX and bundled with esbuild. Both the sources\nand the bundle ship inside the plugin: <code>assets\/admin\/<\/code> and <code>assets\/block\/<\/code> hold\nthe readable source, <code>build\/<\/code> holds what WordPress loads.<\/p>\n\n<p>To rebuild it from the sources shipped here:<\/p>\n\n<pre><code>npm install &amp;&amp; npm run build\n<\/code><\/pre>\n\n<p>The build script is <code>build.mjs<\/code> at the plugin root \u2014 a hundred lines, one\nesbuild call, no code generation. It bundles <code>assets\/admin\/index.jsx<\/code> and\n    assets\/block\/index.jsx and minifies the result, which is what <code>build\/<\/code>\ncontains. Nothing in <code>build\/<\/code> comes from anywhere else, and rebuilding from the\nsources shipped here reproduces it.<\/p>\n\n<p>Bundled third-party resources: Inter and JetBrains Mono (Latin subset, variable\nweight), under the SIL Open Font License 1.1 \u2014 full text in\n    assets\/fonts\/LICENSE.txt. They are served from your own site: no request ever\nleaves the browser to fetch them.<\/p>\n\n<h3>External services<\/h3>\n\n<p>Loginly makes no external request unless you enable a feature that needs one, or\nuntil you press play on the introduction video. Here is exactly what is\ncontacted, and when:<\/p>\n\n<ul>\n<li><strong>loginly.digitsummit.net<\/strong> (DiGit Summit, the plugin author) \u2014 the one-minute\nintroduction video on the plugin's Home screen is served from this domain. The\nposter image ships inside the plugin, so opening the screen contacts nobody:\nthe request happens only when you press play. That server then receives your\nIP address and browser user agent. Nothing else is sent, and nothing is sent\non any other screen.\n<a href=\"https:\/\/digitsummit.net\/conditions-dutilisation\/\">Terms<\/a> \u2014\n<a href=\"https:\/\/digitsummit.net\/politique-de-confidentialite\/\">Privacy<\/a><\/li>\n<li><strong>Cloudflare Turnstile<\/strong> \u2014 only if you choose it as the anti-bot challenge.\nThe login page loads a script from <code>challenges.cloudflare.com<\/code>, and your\nserver sends the challenge token, your secret key and the visitor IP address\nto <code>challenges.cloudflare.com\/turnstile\/v0\/siteverify<\/code>.\n<a href=\"https:\/\/www.cloudflare.com\/terms\/\">Terms<\/a> \u2014\n<a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">Privacy<\/a><\/li>\n<li><strong>hCaptcha<\/strong> \u2014 same, if you choose it instead. Script from <code>js.hcaptcha.com<\/code>,\nverification against <code>hcaptcha.com\/siteverify<\/code>.\n<a href=\"https:\/\/www.hcaptcha.com\/terms\">Terms<\/a> \u2014\n<a href=\"https:\/\/www.hcaptcha.com\/privacy\">Privacy<\/a><\/li>\n<\/ul>\n\n<p>That is the whole list for this plugin. It sends no analytics and no telemetry,\nchecks no licence server, and two-step verification runs entirely on your own\nserver. The anti-lockout check and the exposure report do make HTTP requests,\nbut only to your own site's address, from your own server: no third party is\ninvolved.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Plugins \u2192 Add New \u2192 Add New \u2192 search for \"DigitSummit Loginly\".<\/li>\n<li>Activate.<\/li>\n<li>Open the \"Login page\" menu in your admin sidebar.<\/li>\n<\/ol>\n\n<p>To move your login address: open the \"Login address\" panel, note the recovery\naddress it shows you, then apply your address. <strong>Test it in a private window\nbefore logging out.<\/strong> The plugin checks it for you as well.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20this%20lock%20me%20out%20of%20my%20own%20site%3F\"><h3>Can this lock me out of my own site?<\/h3><\/dt>\n<dd><p>That is the risk the plugin is built around. Four safety nets, in order: the\nserver verifies any new address and rolls back a failing one; an hourly watch\nrestores <code>\/wp-login.php<\/code> after three failed checks and emails you; a recovery\naddress opens the login page even if you forget the secret one; and\n    define( 'LOGINLY_URL_DISABLE', true ); in <code>wp-config.php<\/code> restores the\noriginal address immediately. Deactivating the plugin also restores it.<\/p><\/dd>\n<dt id=\"does%20hiding%20the%20login%20url%20actually%20protect%20anything%3F\"><h3>Does hiding the login URL actually protect anything?<\/h3><\/dt>\n<dd><p>It removes the automated noise, and that is all \u2014 the plugin says so in its own\nexposure report. A visitor who obtains the new address reaches the same form.\nReal protection comes from strong passwords, a second factor, attempt slowdown\nand few administrator accounts. Loginly provides those too.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20a%20caching%20plugin%3F\"><h3>Does it work with a caching plugin?<\/h3><\/dt>\n<dd><p>Yes. The login page is marked \"do not cache\" on every request, and the address\nis added to the exclusion lists of LiteSpeed Cache, WP Rocket and Cache Enabler\nthrough their own public filters. <strong>No third-party plugin's settings are ever\nmodified.<\/strong> A cache placed in front of WordPress (CDN, host) cannot receive\nthose instructions: the diagnostics screen detects it and says so.<\/p><\/dd>\n<dt id=\"i%20already%20use%20another%20plugin%20that%20hides%20the%20login%20page\"><h3>I already use another plugin that hides the login page<\/h3><\/dt>\n<dd><p>Loginly detects WPS Hide Login and the equivalent option in Really Simple\nSecurity, and refuses to enable its own. Two guards fighting over one address is\na lockout waiting to happen.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>6.1.1<\/h4>\n\n<ul>\n<li>The plugin was distributed as a zip under a <code>loginly\/<\/code> folder before it\nreached this directory as <code>digitsummit-loginly\/<\/code>. A site upgrading has both\non disk, and activating the new one without deactivating the old gave PHP\nwarnings on every request, two identical menus, and two guards fighting over\nthe login address. The copy loaded second now declares nothing and says so,\nand the one that runs points at the other from the Plugins screen. Settings,\nlogin address and access log are untouched either way.<\/li>\n<\/ul>\n\n<h4>6.1.0<\/h4>\n\n<ul>\n<li>Fixed: the attempt slowdown and the anti-bot challenge refused nothing. Both\nhooked <code>authenticate<\/code> below priority 20, where WordPress discards whatever it\nis handed and re-checks the password itself. Six failures in a row went\nunslowed, and the right password opened a session in the middle of a\nten-minute lockout. Measured, fixed, and measured again.<\/li>\n<li>Fixed: three ways to make the site hand out the hidden login address without\nsigning in \u2014 a canonical redirect carrying <code>wp-login.php<\/code> in its query string,\n  wp-signup.php, and the <code>postpass<\/code> redirect. The address is now rewritten\nonly when the URL path really is the login form.<\/li>\n<li>Fixed: <code>?loginly=off<\/code>, the escape hatch for a broken theme, also switched off\nthe neutral error message \u2014 handing an attacker \"this account does not exist\".<\/li>\n<li>Fixed: the ten backup codes were generated, stored in clear in the options\ntable for fifteen minutes, and never shown to anyone. They are now displayed\nonce, right after you enable two-step verification, and erased in the same\nbreath. They are longer, and hashed with the site salt.<\/li>\n<li>Fixed: the \"roles reminded to enable two-step verification\" setting did\nnothing at all. It now shows a reminder \u2014 and still never blocks anyone.<\/li>\n<li>Six settings that the code applied but no screen offered are now in the\ninterface: trusted proxy addresses, author archives, oEmbed author name, and\nthe three that were already there.<\/li>\n<li>The login address can no longer be changed through the generic settings\nroute, which skipped the verification that keeps you from locking yourself\nout.<\/li>\n<li>Removed: four settings for features that live in the separate Pro plugin were\ndeclared here and commanded nothing.<\/li>\n<\/ul>\n\n<h4>6.0.3<\/h4>\n\n<ul>\n<li>Fix: the version constant had drifted two releases behind the plugin header.\nThe header named 6.0.2 while every stylesheet and script was still served\nunder 6.0.0, so browsers kept the old appearance.<\/li>\n<\/ul>\n\n<h4>6.0.2<\/h4>\n\n<ul>\n<li>Fix: the licence card showed a single \"Installed version\" \u2014 the free plugin's\nnumber \u2014 among lines that all describe the Pro licence. Each plugin now\ncarries its own name and number.<\/li>\n<li>Fix: the compiled French catalogue was never regenerated, so translations\nadded since 1 September never reached a French site.<\/li>\n<\/ul>\n\n<h4>6.0.1<\/h4>\n\n<ul>\n<li>Fix: the \"Visit plugin site\" link in the plugins list pointed at an address\nthat no longer exists, and landed on the marketing site's 404 page.<\/li>\n<\/ul>\n\n<h4>6.0.0<\/h4>\n\n<ul>\n<li>The free plugin and the Loginly Pro add-on are split along a clear line: what\nis here makes your door beautiful and closed to strangers; what Pro adds is\nchoosing finely, proving what happened, and applying it to a whole estate.<\/li>\n<li>New in Pro: an estate \u2014 publish the styling of one site and every other site\nunder the same licence fetches it, locked or as a starting point. Sign-in\nhours and approved addresses by role, with your own\naddress added automatically so the setting cannot lock you out. Refusing a\npassword that already appears in a known breach, plus\na minimum length and a ban on passwords containing the username. An anti-bot\nshield without a CAPTCHA \u2014 no third party sees your\nvisitors, and nobody is asked to identify a traffic light. Alerts on a sign-in\nfrom an unknown origin, a weekly summary, a\nsigned webhook for every event, and a CSV export of the access log.<\/li>\n<li>Moving to Pro: passkeys, sign-in links by email, nine of the twelve templates,\nredirects, the WooCommerce and email styling, leaked-password checking,\nsign-in hours and approved addresses by role, configuration export and import,\nplus temporary access links, network-wide policy, admin white labelling and\nconnected devices.<\/li>\n<li>Never sold, and in this plugin for everyone: the recovery key that keeps you\nfrom being locked out, the brute-force protection AND its tuning \u2014 the\nthreshold, the delay and the trusted addresses \u2014, how long the access log is\nkept, and requiring two-step verification of a role. There is no timed trial\neither: a feature is in this plugin, or it is not.<\/li>\n<li>They are not switched off waiting for a payment: the code is no longer in this\nplugin at all. Your settings are kept: install Loginly Pro and they come back\nexactly as they were.<\/li>\n<li>Lighter as a result: fewer classes, fewer strings, a smaller package.<\/li>\n<li>New extension points, documented for anyone building on top: <code>loginly_routes<\/code>,\n  loginly_cron_tasks, <code>loginly_cron_wanted<\/code>, <code>loginly_imposed_settings<\/code> and\n  loginly_settings_locked.<\/li>\n<\/ul>\n\n<h4>5.1.0<\/h4>\n\n<ul>\n<li>Lighter on the public side of your site: hooks moved to the context that\nneeds them. A page view now carries three of our callbacks instead of nine,\nand none of them touch page rendering.<\/li>\n<li>Scheduling and URL routing handled in one place each, instead of spread\nacross five services.<\/li>\n<li>Extension points for an add-on: settings schema, editor panels described\nwithout JavaScript, feature catalogue.<\/li>\n<\/ul>\n\n<h4>5.0.1<\/h4>\n\n<ul>\n<li>A refused login link request now leaves a reason in the access log:\nadministrator excluded, unknown account, or too many requests. The visitor\nstill sees the same confirmation either way.<\/li>\n<li>The access log names every event it records, and shows the reason column.<\/li>\n<\/ul>\n\n<h4>5.0.0<\/h4>\n\n<ul>\n<li>English is now the source language, with a complete French translation\nshipped. No feature change.<\/li>\n<\/ul>\n\n<h4>4.3.0<\/h4>\n\n<ul>\n<li>Anti-bot challenge with Cloudflare Turnstile or hCaptcha.<\/li>\n<li>Simultaneous session cap and connected device list.<\/li>\n<li>Admin white labelling.<\/li>\n<li>WCAG 2.1 AA contrast check in the editor, with a suggested fix.<\/li>\n<\/ul>\n\n<h4>4.2.0<\/h4>\n\n<ul>\n<li>Two-step verification (TOTP) with ten single-use backup codes.<\/li>\n<\/ul>\n\n<h4>4.1.0<\/h4>\n\n<ul>\n<li>Passkeys (WebAuthn) and login link by email.<\/li>\n<\/ul>\n\n<h4>4.0.0<\/h4>\n\n<ul>\n<li>Access log, redirects by role, temporary access links, configuration\nexport\/import, network styling for multisite.<\/li>\n<\/ul>\n\n<h4>3.2.0<\/h4>\n\n<ul>\n<li>WooCommerce \"My account\" styling, \"Login\" block, branded authentication\nemails, twelve templates.<\/li>\n<\/ul>\n\n<h4>3.1.0<\/h4>\n\n<ul>\n<li>Exposure report, attempt slowdown, account enumeration closures.<\/li>\n<\/ul>\n\n<h4>3.0.0<\/h4>\n\n<ul>\n<li>Anti-lockout safety net: server-side verification, hourly watch, automatic\ncache exclusions, WP-CLI commands.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Renamed to Loginly.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Login page customisation with live preview.<\/li>\n<\/ul>","raw_excerpt":"Brand your login page, move it to an address only you know, and secure the door \u2014 with a safety net that will not lock you out.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/364448","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=364448"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/digitsummit"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=364448"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=364448"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=364448"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=364448"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=364448"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=364448"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}