
內容簡介
MSC Stealth Login 外掛可將 WordPress 登入頁面移至自訂的隱秘網址,隱藏 wp-login.php,並有效防止機器人攻擊。透過進階安全功能,提供暴力破解保護、IP 白名單、登入歷史紀錄等功能,確保網站安全無虞。
【主要功能】
• 自訂隱秘登入網址
• 阻擋未登入用戶直接訪問 wp-admin
• 暴力破解保護與鎖定功能
• 設定電子郵件通知安全事件
• 詳細登入歷史紀錄與 CSV 匯出
• XML-RPC 和 REST API 防護
外掛標籤
開發者團隊
原文外掛簡介
Move your WordPress login page to a secret URL of your choosing and make wp-login.php disappear.
Bots hammering wp-login.php and wp-admin are silently redirected away, while you log in at your own custom address. Enable Advanced Security and you also get brute-force lockouts with progressive delays, an IP allowlist with CIDR support, XML-RPC hardening, user-enumeration blocking, a full login history with CSV export, and email alerts — all free, with zero external services.
Stealth Login URL
Change your login page from /wp-login.php to a custom URL like /secure-login/. Attackers scanning for standard WordPress login pages are redirected away before they can even attempt a brute force attack.
wp-admin Protection
Block direct access to /wp-admin/ for users who aren’t logged in — they’re silently redirected to a URL you choose. Logged-in users and AJAX requests are unaffected.
Brute Force Protection (enable Advanced Security to arm)
After a configurable number of failed login attempts (default 3), the IP is locked out for a configurable duration (default 15 minutes). With progressive lockouts enabled, each successive lockout doubles the wait time, up to your configured maximum. This stops automated attacks while minimizing disruption to real users who mistype their password.
Email Notifications
Stay informed about security events with configurable email alerts:
Lockout notifications when IPs are blocked
Admin login alerts for every administrator sign-in
New IP alerts when users log in from previously unseen locations
Login History & Export
Track login attempts with detailed logging: IP, username, result and user agent. Filter by IP address, username, result type, or date range. Export reports to CSV for security audits. Entries older than 30 days are pruned automatically.
XML-RPC & REST API Protection
Disable vulnerable XML-RPC endpoints commonly exploited for brute force attacks. Block REST API user enumeration that lets attackers harvest usernames.
IP Allowlist
Bypass protection for trusted IP addresses — exact IPv4/IPv6 or CIDR ranges (e.g. 10.0.0.0/8). Add your office, home, or server IPs to ensure uninterrupted access while maintaining maximum security for everyone else. A proxy-header trust toggle supports Cloudflare and reverse-proxy setups.
Emergency Recovery URL
Forgot your custom login URL? The Settings tab shows a secure recovery URL that always reaches wp-login.php — copy it, bookmark it, or email it to yourself from the Support tab. You can regenerate it at any time.
Private by design
No external services, no CDN assets, no tracking. Login data stays in your database, is clearable from the History tab, auto-pruned after 30 days, and fully removed on uninstall.
Privacy
MSC Stealth Login collects the following data to provide its security features:
IP Addresses: Logged for every login attempt (successful, failed, and locked out) to enable brute force protection and login history.
Usernames: Logged with each login attempt to help administrators identify targeted accounts.
User Agents: Logged with each login attempt for security auditing.
Login History: All login attempts are stored in the database and can be viewed in the History tab or exported as CSV.
Data collection only occurs when the plugin is active. All collected data is stored in your WordPress database and is not sent to any external services. Administrators can clear login history at any time from the History tab.
This plugin does not use cookies or third-party tracking.
