{"id":376839,"date":"2026-09-30T19:26:18","date_gmt":"2026-09-30T19:26:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/login-yo\/"},"modified":"2026-09-30T19:25:54","modified_gmt":"2026-09-30T19:25:54","slug":"lyogate","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/lyogate\/","author":15245892,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.2","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"LyoGate \u2014 Login Security","header_author":"Andres Hunger","header_description":"A modern, hardened login page: arithmetic captcha, honeypot, brute-force lockout, anti-enumeration error messages, customizable fonts and colors.","assets_banners_color":"555c7c","last_updated":"2026-09-30 19:25:54","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/www.linkedin.com\/in\/andres-hunger\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":72,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"andresitaly","date":"2026-09-30 19:25:54","revision":3721913}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3721940,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3721940,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3721913,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3721913,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3721913,"resolution":"1","location":"assets","locale":"","width":1200,"height":900},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3721913,"resolution":"2","location":"assets","locale":"","width":1200,"height":900},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3721913,"resolution":"3","location":"assets","locale":"","width":1200,"height":900}},"screenshots":{"1":"The login page with the default dark theme, captcha and subtitle.","2":"The configuration screen in Settings \u2192 LyoGate.","3":"The lockout message after too many failed attempts."}},"plugin_section":[],"plugin_tags":[2439,362,3691,602,600],"plugin_category":[38,44,54],"plugin_contributors":[283770],"plugin_business_model":[],"class_list":["post-376839","plugin","type-plugin","status-publish","hentry","plugin_tags-brute-force","plugin_tags-captcha","plugin_tags-custom-login","plugin_tags-login","plugin_tags-security","plugin_category-authentication","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-andresitaly","plugin_committers-andresitaly"],"banners":{"banner":"https:\/\/ps.w.org\/lyogate\/assets\/banner-772x250.png?rev=3721913","banner_2x":"https:\/\/ps.w.org\/lyogate\/assets\/banner-1544x500.png?rev=3721913","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/lyogate\/assets\/icon-128x128.png?rev=3721940","icon_2x":"https:\/\/ps.w.org\/lyogate\/assets\/icon-256x256.png?rev=3721940","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/lyogate\/assets\/screenshot-1.png?rev=3721913","caption":"The login page with the default dark theme, captcha and subtitle."},{"src":"https:\/\/ps.w.org\/lyogate\/assets\/screenshot-2.png?rev=3721913","caption":"The configuration screen in Settings \u2192 LyoGate."},{"src":"https:\/\/ps.w.org\/lyogate\/assets\/screenshot-3.png?rev=3721913","caption":"The lockout message after too many failed attempts."}],"raw_content":"<!--section=description-->\n<p>LyoGate replaces the default WordPress login page with a modern, protected one. Everything is configured from <strong>Settings \u2192 LyoGate<\/strong>. No external accounts, no third-party services: everything runs on your own site.<\/p>\n\n<p><strong>Security<\/strong><\/p>\n\n<ul>\n<li><strong>Arithmetic captcha<\/strong> \u2014 a simple sum is required before signing in, backed by an HMAC-signed token with expiry (10 minutes): the answer never travels in clear text and is never stored in the database.<\/li>\n<li><strong>Per-IP brute-force lockout<\/strong> \u2014 after N failed attempts (default 5) the IP address is locked out for X minutes (default 15). Wrong captcha and honeypot hits count too; a successful login resets the counter. The lockout applies even with correct credentials.<\/li>\n<li><strong>Honeypot<\/strong> \u2014 a field hidden from humans: whoever fills it in is a bot and gets rejected without hints.<\/li>\n<li><strong>Unified error messages<\/strong> \u2014 no username enumeration: \"unknown user\" and \"wrong password\" produce the same generic message.<\/li>\n<li><strong>Reduced attack surface<\/strong> \u2014 XML-RPC disabled, X-Pingback header removed, public REST user endpoints removed (they remain available to users who can edit posts, for the block editor), and <code>?author=N<\/code> requests plus author archives redirect to the home page: no username scraping.<\/li>\n<\/ul>\n\n<p><strong>Customizable appearance<\/strong><\/p>\n\n<ul>\n<li>Title, subtitle and footer message<\/li>\n<li>Custom logo from the media library, with a configurable clickable link (empty = site home)<\/li>\n<li>Two Google Fonts to choose from: Syne, Instrument Sans, Inter, Space Grotesk, Manrope, DM Sans, Outfit, Sora, Archivo, Playfair Display and JetBrains Mono (one for headings, one for body text)<\/li>\n<li>Three colors: background, text and accent (buttons and focus)<\/li>\n<\/ul>\n\n<p><strong>Compatibility<\/strong><\/p>\n\n<ul>\n<li>The security gate runs as a late filter on the <code>authenticate<\/code> flow: captcha and lockout always take precedence over valid credentials. The gate only acts on the wp-login.php form: XML-RPC is disabled entirely while LyoGate is active, and application password \/ REST requests follow the normal WordPress flow (should another plugin re-enable XML-RPC, its authentication is not intercepted by the captcha).<\/li>\n<li>All settings live in a single database option; on uninstall, options and transients are removed (also on multi-site).<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>lyogate<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the ZIP via Plugins \u2192 Add New \u2192 Upload Plugin.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Go to <strong>Settings \u2192 LyoGate<\/strong> to pick title, logo, fonts and colors.<\/li>\n<li>Open your login page: the new look and the protection are already active.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20i%20disable%20the%20captcha%3F\"><h3>Can I disable the captcha?<\/h3><\/dt>\n<dd><p>Yes: in <strong>Settings \u2192 LyoGate<\/strong> untick \"Anti-robot captcha\". Honeypot and brute-force lockout stay active.<\/p><\/dd>\n<dt id=\"am%20i%20locked%20out%20myself%3F\"><h3>Am I locked out myself?<\/h3><\/dt>\n<dd><p>The lockout is per IP address and expires on its own (default 15 minutes). A successful login resets the counter immediately. With WP-CLI: <code>wp transient delete --all<\/code> also clears lockouts.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20application%20passwords%20or%20mobile%20apps%3F\"><h3>Does it work with application passwords or mobile apps?<\/h3><\/dt>\n<dd><p>Yes: the captcha and lockout only act on the wp-login.php form. XML-RPC is disabled while LyoGate is active, so XML-RPC logins cannot happen at all; requests authenticated via REST or application passwords follow the normal WordPress flow.<\/p><\/dd>\n<dt id=\"does%20it%20add%20cookies%20or%20interfere%20with%20other%20plugins%3F\"><h3>Does it add cookies or interfere with other plugins?<\/h3><\/dt>\n<dd><p>No. LyoGate only touches the login form authentication flow and the appearance of the login page; no extra cookies, no tracking.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multi-site%3F\"><h3>Does it work on multi-site?<\/h3><\/dt>\n<dd><p>Yes, and on uninstall it cleans up options on every site in the network.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First public release: arithmetic captcha with HMAC token, honeypot, per-IP brute-force lockout, unified anti-enumeration errors, protected XML-RPC and REST user endpoints, customizable appearance (logo, fonts, colors) under Settings \u2192 LyoGate.<\/li>\n<\/ul>","raw_excerpt":"A modern, hardened WordPress login page with captcha, honeypot and brute-force protection \u2014 fully customizable, no third-party services.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/376839","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=376839"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/andresitaly"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=376839"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=376839"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=376839"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=376839"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=376839"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=376839"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}