{"id":376340,"date":"2026-10-01T13:15:48","date_gmt":"2026-10-01T13:15:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/dci-admin-security\/"},"modified":"2026-10-01T13:25:11","modified_gmt":"2026-10-01T13:25:11","slug":"dci-admin-security","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/dci-admin-security\/","author":23210519,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"DCI Admin Security","header_author":"DreamCode Infotech","header_description":"Protect WordPress login and wp-admin with an IP allowlist, a custom login URL, email OTP verification, brute-force rate limiting, CAPTCHA, security logging and alerts.","assets_banners_color":"faf9f2","last_updated":"2026-10-01 13:25:11","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/ko-fi.com\/dreamcodeinfotech","header_plugin_uri":"https:\/\/dreamcodeinfotech.com\/dci-admin-security\/","header_author_uri":"https:\/\/dreamcodeinfotech.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":61,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["installation","changelog","description"],"tags":{"1.0.0":{"tag":"1.0.0","author":"dreamcodeinfotech","date":"2026-10-01 13:25:11","revision":3723222}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3723214,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128}},"assets_banners":{"banner-772x250.png":{"filename":"banner-772x250.png","revision":3723214,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"Screenshot-1.png":{"filename":"Screenshot-1.png","revision":3723197,"resolution":"1","location":"assets","locale":"","width":1206,"height":811},"Screenshot-2.png":{"filename":"Screenshot-2.png","revision":3723197,"resolution":"2","location":"assets","locale":"","width":1216,"height":636},"Screenshot-3.png":{"filename":"Screenshot-3.png","revision":3723197,"resolution":"3","location":"assets","locale":"","width":1226,"height":792}},"screenshots":[]},"plugin_section":[],"plugin_tags":[55390,3691,253358,1229,600],"plugin_category":[54],"plugin_contributors":[237879],"plugin_business_model":[],"class_list":["post-376340","plugin","type-plugin","status-publish","hentry","plugin_tags-admin-security","plugin_tags-custom-login","plugin_tags-ip-whitelist","plugin_tags-login-security","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-dreamcodeinfotech","plugin_committers-dreamcodeinfotech"],"banners":{"banner":"https:\/\/ps.w.org\/dci-admin-security\/assets\/banner-772x250.png?rev=3723214","banner_2x":false,"banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/dci-admin-security\/assets\/icon-128x128.png?rev=3723214","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/dci-admin-security\/assets\/Screenshot-1.png?rev=3723197","caption":""},{"src":"https:\/\/ps.w.org\/dci-admin-security\/assets\/Screenshot-2.png?rev=3723197","caption":""},{"src":"https:\/\/ps.w.org\/dci-admin-security\/assets\/Screenshot-3.png?rev=3723197","caption":""}],"raw_content":"<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP from Plugins &gt; Add New &gt; Upload Plugin.<\/li>\n<li>Activate DCI Admin Security.<\/li>\n<li>Open Settings &gt; DCI Admin Security.<\/li>\n<li>Add at least one IP address or CIDR range that should be allowed to reach the protected login\/admin area.<\/li>\n<li>Set the custom login slug.<\/li>\n<li>Save the General settings.<\/li>\n<li>Test the custom login URL before enabling strict IP protection on a production site.<\/li>\n<li>Configure Email OTP, CAPTCHA, rate limiting and alerts as required.<\/li>\n<\/ol>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Resolved Plugin Check database-query and nonce warnings.<\/li>\n<li>Sanitized emergency fallback-code input.<\/li>\n<li>Added explicit versions to CAPTCHA provider scripts.<\/li>\n<li>Kept IP allowlist, email OTP, and WordPress.org compatibility fixes from 1.0.0.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Removed the obsolete TOTP\/two-factor authentication implementation and related files.<\/li>\n<li>Fixed WordPress coding-standard issues in IP handling, AJAX actions, CAPTCHA output and custom database queries.<\/li>\n<li>Added proper login CAPTCHA script enqueueing and a CAPTCHA nonce.<\/li>\n<li>Improved PHP 7.4 compatibility by removing PHP 8-only string helper usage.<\/li>\n<li>Updated documentation and feature list for the email OTP implementation.<\/li>\n<\/ul>\n\n<h4>2.4.10<\/h4>\n\n<ul>\n<li>Improved IP allowlist matching and localhost development controls.<\/li>\n<li>Added IP diagnostics and test tools.<\/li>\n<\/ul>\n\n<h4>2.4.6<\/h4>\n\n<ul>\n<li>Added explicit trusted proxy handling for <code>X-Forwarded-For<\/code>.<\/li>\n<li>Normalized IPv4-mapped IPv6 client addresses.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Added brute-force rate limiting, CAPTCHA, security logging and alerts.<\/li>\n<li>Added administrator email OTP verification.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release with IP allowlist and custom login URL protection.<\/li>\n<\/ul>\n\n<!--section=description-->\n<p>Protect WordPress login and wp-admin with IP allowlisting, custom login URLs, email OTP, rate limiting, CAPTCHA, logging and alerts.<\/p>\n\n<h3>Features<\/h3>\n\n<ul>\n<li>Allow exact IPv4\/IPv6 addresses and CIDR ranges.<\/li>\n<li>Accept IPv4 shorthand such as <code>171.61<\/code>, stored as <code>171.61.0.0\/16<\/code>.<\/li>\n<li>Change the WordPress login URL.<\/li>\n<li>Protect the normal <code>wp-login.php<\/code> endpoint.<\/li>\n<li>Restrict <code>wp-admin<\/code> by IP while keeping <code>admin-ajax.php<\/code> available.<\/li>\n<li>Optional Cloudflare <code>CF-Connecting-IP<\/code> detection.<\/li>\n<li>Optional trusted <code>X-Forwarded-For<\/code> detection for known reverse-proxy setups.<\/li>\n<li>Optional localhost\/loopback bypass for local development.<\/li>\n<li>Brute-force rate limiting and temporary lockouts.<\/li>\n<li>Email OTP verification for administrators, delivered to each administrator's WordPress profile email address.<\/li>\n<li>Administrator-configured emergency fallback code for environments where email cannot be delivered.<\/li>\n<li>Optional Google reCAPTCHA v2, reCAPTCHA v3 or hCaptcha on the WordPress login form.<\/li>\n<li>Security event logging with an administrator viewer and configurable retention.<\/li>\n<li>Optional email and Slack alerts for repeated blocked-IP or brute-force events.<\/li>\n<\/ul>\n\n<h3>Important<\/h3>\n\n<p>Keep at least one known administrator IP in the allowlist before enabling IP protection.<\/p>\n\n<p>Only enable Cloudflare IP detection when the site is actually behind Cloudflare. Only enable trusted <code>X-Forwarded-For<\/code> when the server is behind a trusted reverse proxy that sets that header.<\/p>\n\n<p>On localhost, PHP commonly sees <code>127.0.0.1<\/code> or <code>::1<\/code> rather than the browser's public VPN address. Use a publicly reachable staging site for an end-to-end VPN IP test.<\/p>\n\n<p>The emergency fallback code is stored as a password hash and is never displayed after saving.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin can optionally communicate with third-party CAPTCHA verification services when CAPTCHA is enabled:<\/p>\n\n<ul>\n<li>Google reCAPTCHA: the login page loads Google reCAPTCHA assets and sends the submitted CAPTCHA token to Google's verification endpoint. See https:\/\/policies.google.com\/privacy and https:\/\/policies.google.com\/terms.<\/li>\n<li>hCaptcha: the login page loads hCaptcha assets and sends the submitted CAPTCHA token to hCaptcha's verification endpoint. See https:\/\/www.hcaptcha.com\/privacy and https:\/\/www.hcaptcha.com\/terms.<\/li>\n<\/ul>\n\n<p>The plugin does not contact these services when CAPTCHA is disabled.<\/p>\n\n<h3>IP access examples<\/h3>\n\n<p>Exact IP: <code>186.189.26.220<\/code><\/p>\n\n<p>IPv4 \/16 shorthand: <code>171.61<\/code><\/p>\n\n<p>CIDR: <code>171.61.0.0\/16<\/code><\/p>\n\n<h3>Email OTP<\/h3>\n\n<p>After a successful WordPress administrator password check, a six-digit OTP is generated and sent to that administrator's WordPress profile email address.<\/p>\n\n<p>If email delivery is unavailable, an administrator-configured emergency fallback code can be used.<\/p>","raw_excerpt":"Protect WordPress login and wp-admin with IP allowlisting, custom login URLs, email OTP, rate limiting, CAPTCHA, logging and alerts.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/376340","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=376340"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dreamcodeinfotech"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=376340"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=376340"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=376340"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=376340"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=376340"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=376340"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}