{"id":63778,"date":"2013-10-28T18:00:14","date_gmt":"2013-10-28T18:00:14","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/unlockurl\/"},"modified":"2013-10-28T18:00:14","modified_gmt":"2013-10-28T18:00:14","slug":"unlockurl","status":"closed","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/unlockurl\/","author":12463585,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"","stable_tag":"trunk","tested":"","requires":"","requires_php":"","requires_plugins":"","header_name":"unlockurl","header_author":"","header_description":"","assets_banners_color":"","last_updated":"2013-10-28 18:00:14","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/www.unlockurl.com\/unlockurl.zip","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":393,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":[],"tags":[],"upgrade_notice":[],"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":[],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[],"plugin_category":[],"plugin_contributors":[],"plugin_business_model":[],"class_list":["post-63778","plugin","type-plugin","status-closed","hentry","plugin_committers-rbevanrestdevelopercom"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/unlockurl.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"","raw_excerpt":"<p>Hi,<\/p>\n<p>I wanted to produce something to stop the constant wp-login.php &amp; wp-admin\/xyz calls. Returning a 403 via apache only seems to spur them on. So I have a plugin that will return a 404. No web server config changes needed. Just a good old WP plugin.<\/p>\n<p>Using a shared key configured in the plugin settings &amp; generated on www.unlockurl.com, a user will be given a token that they can use to login. And a clickible link on www.unlockurl.com for as many URL&#039;s as they like.<\/p>\n<p>Something along the lines of <\/p>\n<p>http:\/\/customer-wordpress-site\/wp-login.php?t=X&amp;h=Y<\/p>\n<p>Links expire after 1 day. ie each time they want to log in, they visit www.unlockurl.com<\/p>\n<p>Using a sha1 using the secret-key+token+day-of-the-year the plugin will decide to allow the login screen to be rendered. Called early on the admin_init &amp; login_enqueue_scripts hooks.<\/p>\n<p>If the token is missing or incorrect, fire a 404. This is because I am sick of people hitting my wp-login.php once they have found it. Pass back a 404, and this seems to slow\/stop their efforts.<\/p>\n<p>Requires a Google or Facebook account (I am using oauth). That way, I store no details about the users login, further reducing the setup hassle. <\/p>\n<p>Seems to be working for me. Server logs alone have been reduced in size.<\/p>\n<p>Also, a customer calls to ask for their login URL (not that they ever call it that), I can just pass them to www.unlockurl.com (once setup).<\/p>\n<p>Any questions or suggestions or improvements, please email me.<\/p>\n<p>Thanks,<\/p>\n<p>Richard\n<\/p>","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/63778","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=63778"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/rbevanrestdevelopercom"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=63778"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=63778"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=63778"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=63778"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=63778"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=63778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}