Theme My Login Security is a lightweight WordPress add-on that hardens your login page, reduces brute-force attacks, and protects user accounts without slowing your site. It extends Theme My Login with modern security tools like 2FA, reCAPTCHA, and login rate limiting, all configurable inside your WordPress dashboard.
- Two-Factor Authentication (2FA) via email, app, or backup codes
- Login rate limiting to block brute-force attacks
- reCAPTCHA support for login, registration, and password reset
- Email-based login verification and alerts for suspicious activity
- Blocklist/allowlist by IP or username
- Force strong passwords with customizable policies
- Session management with force logout and session limits
- Auto-lockout after failed login attempts with adjustable thresholds
- Hide or rename wp-login.php to reduce bot traffic
- Custom redirect rules after login, logout, and registration
- Protect REST API authentication endpoints
- Detailed security logs with timestamps and IP tracking
- Multisite compatible with per-site or network-wide settings
- Developer-friendly hooks and filters for custom workflows
- Lightweight, translation-ready, and compatible with most themes/plugins