Login Armor — WordPress Login Plugin
by wpformation · WordPress.org page · Website
Login Armor has 300+ active installs on WordPress.org and 4,966 downloads all time. We have tracked it since September 4, 2026; download trends appear after 30 days of data. The last update was on August 23, 2026, tested up to WordPress 7.1.
Login Armor at a glance
Is Login Armor well maintained?
Features
The feature list from the plugin's own readme on WordPress.org, trimmed to the essentials.
- Hide Login: replace wp-login.php with a private slug and return a 404 or redirect blocked visitors to a chosen URL
- Brute Force Protection: escalating lockouts, subnet blocking, trusted proxy headers and coverage for login, password recovery, registration, XML-RPC and REST…
- Hardening: fifteen controls for XML-RPC, pingbacks, file editing, version exposure, application passwords, author enumeration, reserved usernames, honeypots…
- Two-Factor Authentication: TOTP, email codes, backup codes, trusted devices, per-role enforcement, grace periods and recovery
- Detection and Incidents: group raw events into attack patterns with severity, timelines, source IPs, targeted users and one-click actions
- Activity Log: tamper-evident admin audit trail with filters, CSV export, retention controls and optional signed SIEM forwarding
- Security Headers: CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options for login and lockout pages, with optional site-wide…
- Breach Check: privacy-preserving Have I Been Pwned password checks and an optional XposedOrNot email check
- Password Policy: length and character rules, username exclusion, breached-password rejection and optional non-locking expiration reminders
- Session Management: idle timeout, maximum lifetime, optional single-device access and one-click revocation of other sessions
- IP Geolocation: cached country lookup for IPs shown in Incidents and Events, with private ranges excluded
- Request Firewall: optional, monitor-first filtering of malicious paths, query strings and HTTP methods, with administrator exclusions and IP/path allowlists
Login Armor reviews and ratings
5 reviews on WordPress.org, with the most recent ones as their authors posted them.
5 reviews
- 5★
-
5
- 4★
-
0
- 3★
-
0
- 2★
-
0
- 1★
-
0
-
Excellent
Very easy to use, and many hacking attempts avoided. Thanks to Login Armor !
kambro -
un plugin professionnel
C'est ce que je pensais quand je l'ai installé, c'est un plugin pro avec des fonctionnalités avancées et pourtant il est gratuit. Bravo Fabrice :)
thierryramirez -
Parfait
Très bien et complet. Je ne suis qu'un simple blogueur mais c'est l'outil indispensable pour sécuriser un site.
markusleicht -
Simple, efficace et fait le job sans effort !
J'utilise pour certain de mes clients d'autres solutions premium, mais quid des petits qui ne veulent pas inverstir dans une licence... Et bien Login Armor fait parfaitement le job !
Raphael -
Un indispensable pour sécuriser mes sites : simple, efficace et robuste.
J'ai testé pas mal de solutions pour sécuriser mes sites WordPress, et Login Armor est devenu mon incontournable. Ce que j'apprécie par-dessus tout, c'est qu'il fait exactement ce qu'on attend de lui sans alourdir le site ou complexifier la configuration. L'installation est rapide, l'interface est claire, et il m'a permis d'arrêter immédiatement les tentatives de connexion abusives sur mes différents sites. C'est le genre de plugin qu'on installe une fois, on règle ses préférences, et on peut dormir sur ses deux oreilles. Depuis que je l'utilise, je l'intègre systématiquement sur chaque nouveau projet que je lance. Un grand merci aux développeurs pour cet outil fiable et bien pensé. Je recommande à 100 % !
Rid Nam
Where Login Armor ranks on WordPress.org
The rankings we track that Login Armor appears in, and how its position changed over 30 days.
| Ranking | WordPress.org placement | Position | 30 days |
|---|---|---|---|
| Best Login Plugins | #52 in search, not tagged | #89 | – |
Details
Thirteen security modules + AI briefing: hide login, request firewall, brute force, 2FA, password policy, sessions, hardening, audit log. No upsells.
The full description, screenshots and every review live on the WordPress.org page.
Rankings Login Armor competes in
Tags
- Activity Log
- Brute Force
- hide login
- limit login
- login security
More from wpformation
-
OGEEAT 100+ installs
- Version
- 2.5.3
- Last updated
- Aug 23, 2026
- First published
- Apr 27, 2026
- Requires WordPress
- 6.8
- Tested up to
- 7.1
- Requires PHP
- 8.1
- Pricing
- Free on WordPress.org
Login Armor FAQ
What does Login Armor do?
According to its WordPress.org readme, Login Armor offers Hide Login: replace wp-login.php with a private slug and return a 404 or redirect blocked visitors to a chosen URL, Brute Force Protection: escalating lockouts, subnet blocking, trusted proxy headers and coverage for login, password recovery, registration, XML-RPC and REST, Hardening: fifteen controls for XML-RPC, pingbacks, file editing, version exposure, application passwords, author enumeration, reserved usernames, honeypots, Two-Factor Authentication: TOTP, email codes, backup codes, trusted devices, per-role enforcement, grace periods and recovery and Detection and Incidents: group raw events into attack patterns with severity, timelines, source IPs, targeted users and one-click actions.
How many active installs does Login Armor have?
WordPress.org reports 300+ active installs for Login Armor as of September 7, 2026.
Is Login Armor still maintained?
Yes. The last release was on August 23, 2026 and it is tested up to WordPress 7.1.
Does Login Armor have good support?
On the WordPress.org forum, 2 of 2 recent support threads for Login Armor are marked resolved. That is the developer's free support; a paid version usually comes with its own channel.
Is Login Armor free?
Login Armor is free to install from WordPress.org. Many plugins also sell a paid version or add-ons.
Where does Login Armor rank among Login Plugins?
Login Armor is #89 in the WordPress.org Login Plugins ranking.