Skip to content
15 years of IT experience
CybexsoftConsultancy Services
WordPress plugin · Free & Pro

Your login page is being guessed at right now

Cybex Login Security puts a limit on failed attempts, a CAPTCHA in front of the form and your login page somewhere the bots aren't looking — then records every attempt so you can see who is trying.

Works on any themeNo code changesRecovery link if locked out
WP Admin · Cybex Login Security · Login attempts
45.83.117.24RUadminLocked out
103.61.9.180CNeditorCAPTCHA failed
191.102.44.7BRadminCountry blocked
82.14.220.19INpriyaSigned in · 2FA
197.44.8.212EGwpuserLocked out
Every attempt logged with IP, username and the rule that stopped it
Version 1.0 · tested to WordPress 6.6
9
Protection modules
3
CAPTCHA providers supported
2FA
TOTP with any authenticator app
< 2h
Pro support response
The problem

Brute force is cheap and automated

Nobody picks your site personally. Scanners walk lists of domains, try the usual usernames against the usual path, and move on when it costs them anything. The point is to make it cost something.

wp-login.php is a known address

Every WordPress site answers on the same path, so a scanner does not need to find you first.

Unlimited guesses by default

Core puts no cap on failed passwords. A weak one falls to a script that never gets tired.

No record of who tried

Without a log there is nothing to show whether an attempt succeeded, or which account was targeted.

Features

Layers, because one control is never enough

Each module handles one job and can be switched on by itself. Turn on what your site needs and leave the rest alone.

Attempt limits and lockouts

Cap failed logins per IP and per username, then lock the pair out for as long as you choose. Repeat offenders get longer.

CAPTCHA that suits you

Google reCAPTCHA v2 or v3, Cloudflare Turnstile, or a self-hosted challenge that calls no third party at all.

Move the login page

Serve the form from a path only you know. Requests to wp-login.php stop resolving, which is most of the automated traffic gone.

Allow and block lists

Block a single address or a whole range, or invert it — restrict wp-admin to the office IPs and nothing else gets in.

Password policy

Set length and complexity, expire old passwords, and reject any that appear in a known breach — checked without sending the password anywhere.

Device history and reports

See which devices signed in to each account and when, with a summary of what was blocked over the period.

Inside the plugin

Every control on one screen

Limit failed attempts
Attempts allowed5
Lockout duration30 minutes
4 addresses locked out todayView log
Login attempts

Set the cap and the lockout, then watch the counter do its work.

Built-inreCAPTCHA v3TurnstileOff
Show on the login form
Show on password reset
Show on registration
CAPTCHA

Pick a provider, or use the built-in challenge and call nobody.

Scan with your authenticator
Or enter the setup key by hand
Require for administrators
Require for editors
Two-factor authentication

Time-based codes from any authenticator app, enrolled by QR code.

ModeAllow list
Indiaallowed
United Kingdomallowed
Everywhere elseblocked
Geo-blocking

Allow the countries you serve and refuse the login form to the rest.

Free vs Pro

The free plugin is not a trial

Everything that stops a brute-force attack is in the free build and stays there. Pro adds the two controls that need a second factor or a data feed behind them.

Capability
Free
Pro
Limit login attempts with lockouts
CAPTCHA, including a self-hosted option
Custom login URL
IP allow and block lists
Password policy and breach check
Device history and login reports
Hardening (XML-RPC, REST, file editor)
Two-factor authentication
Geo-blocking by country
Priority support under 2 hours
Setup

Protected in five minutes

No code and no server configuration. If a rule ever locks you out of your own site, an emergency link mailed to the admin address turns it off again.

Login page moved
wp-login.php now returns 404 · new path saved
1
Install the plugin

From the WordPress plugin directory, or upload the Pro zip and paste your licence key.

2
Turn on the limiter

Pick how many failed attempts you allow and how long a lockout lasts. Sensible defaults are already set.

3
Add a CAPTCHA

Use the built-in challenge for no setup at all, or paste keys for reCAPTCHA or Turnstile.

4
Move the login page

Optional, and the single biggest drop in automated traffic. Save the new address before you sign out.

Pricing

One annual licence, per number of sites

The price shown is what you pay — Indian orders include GST, everywhere else is tax-free. Renews at the same rate; cancel any time and the free protection keeps running.

Founding priceEarly customers keep this rate for as long as they renew, even after it goes up.
Free
WordPress.org
$0
unlimited sites
Attempt limits & CAPTCHACustom login URLForum support
Download
Pro Single
One site
Free
1 activation
Two-factor authenticationGeo-blockingEmail support
Get it free
Pro Studio
Up to 5 sites
$8,900
5 activations
Everything in SingleMultisite supportUnder 2-hour response
Contact us
Pro Agency
Up to 25 sites
$18,999
25 activations
Everything in StudioClient licence managementNamed support contact
Contact us
Placeholder quote — we have not shipped long enough to have a customer say something worth printing yet.
PHOTOClient nameRole · Company
Placeholder quote — send a real customer testimonial and photo to replace it.
FAQ

Questions we get about the plugin

Anything else, write to us — someone who works on the plugin will answer.

admin@cybexsoft.com
What if a rule locks me out of my own site?+

Every lockout screen offers a recovery link sent to the site administrator's email address, which clears the block and reopens the login page. If you have moved the login URL and lost the address, the same email restores it.

Does it work with WooCommerce and membership plugins?+

Yes. The protection sits on the WordPress authentication layer, so any plugin that logs a user in through core — WooCommerce accounts, membership and LMS plugins, custom front-end forms — is covered without per-plugin setup.

Do I need a Google or Cloudflare account for the CAPTCHA?+

No. reCAPTCHA and Turnstile are supported if you want them, but the built-in challenge is served entirely from your own site and sends nothing to a third party — useful if you would rather not add an external request to your login page.

Is my password sent anywhere for the breach check?+

No. The policy checks a password against the Have I Been Pwned range API, which receives only the first five characters of its SHA-1 hash. The password itself never leaves your server, and neither does enough of the hash to identify it.

Does blocking a country stop legitimate users travelling?+

It can, which is why geo-blocking applies to the login form rather than the whole site, and why allow lists take an IP exception. Add the address someone is travelling from and they get through regardless of country.

What happens when my licence expires?+

Everything in the free build keeps protecting the site. Two-factor authentication and geo-blocking pause, and updates and Pro support stop until you renew. Enrolled 2FA devices are remembered, so renewing puts them straight back to work.

Install it, then watch what stops getting through

The free plugin takes five minutes and needs no account anywhere. Pro is a licence key away, with a fourteen-day refund if it does not help.