Skip to content

WordPress Plugin

Protect WordPress logins and accounts

Guard Dog is a comprehensive WordPress security plugin for custom login URLs, two-factor authentication, passkeys, social login, CAPTCHA protection, session management, and detailed activity logging — without a premium tier or subscription trap.

Free and open source. No pro version, no premium upsells.

Version
1.9.55
Requires WP
5.9+
Tested to
7.1
Requires PHP
8.1+
Paid tier
None

What it does

  • Custom login URL

    Hide the default /wp-admin and /wp-login.php entry points behind your own slug to cut automated bot traffic.

  • Two-factor authentication

    App-based or email-based 2FA with recovery codes, enforcement options, and frontend setup controls.

  • Passkeys

    Passwordless authentication with device credentials — Face ID, Touch ID, Windows Hello, and security keys.

  • Login attempt limiting

    Lock out repeated failed logins with configurable retry limits and durations, before brute-force attacks get comfortable.

  • Session management

    Track active sessions, enforce limits, set timeouts, terminate remotely, and detect suspicious IP or location shifts.

  • Activity monitoring

    Log security events across logins, lockouts, 2FA, CAPTCHA, sessions, social login, users, content, settings, plugins, and themes.

Every feature, in full

FeatureWhat It Does for You
Custom Login URLHide the default /wp-admin and /wp-login.php entry points behind your own login slug to reduce automated bot traffic and brute-force attempts.
WordPress Login Screen CustomizationBrand the native login screen with custom logo, colors, layout, links, and messaging while keeping the normal WordPress login flow intact.
Frontend Login FormUse the Guard Dog Login Form block or shortcode on normal pages, with support for CAPTCHA, passkeys, social login buttons, remember-me, lost-password links, and redirects.
Frontend Account SecurityGive logged-in users self-service controls for 2FA, passkeys, and active sessions through blocks or shortcodes designed for account dashboards and block themes.
Two-Factor Authentication (2FA)Require app-based or email-based 2FA with recovery codes, enforcement options, and frontend setup controls that only show enabled methods.
PasskeysSupport passwordless authentication with device-based credentials such as Face ID, Touch ID, Windows Hello, and security keys.
Social LoginLet users sign in with Google, Microsoft, or Apple OAuth, with account linking, optional auto-creation, provider controls, and activity logging.
Multiple CAPTCHA ProvidersChoose Google reCAPTCHA v2 or v3, hCaptcha, or Cloudflare Turnstile to match your site’s privacy and friction preferences.
Login Attempt LimitingLock out repeated failed login attempts with configurable retry limits and durations before brute-force attacks get comfortable.
Access Control + Trusted ProxiesUse IP, username, country, whitelist, and blacklist controls with proxy-aware visitor IP detection and trusted proxy CIDR ranges for CDN or load-balanced sites.
Session ManagementTrack active sessions, enforce session limits, set timeouts, remotely terminate sessions, and detect suspicious IP or location shifts.
User Enumeration ProtectionBlock common username discovery vectors across author archives, REST API requests, login errors, password reset flows, XML-RPC, registration, and more.
Temporary User AccessCreate real WordPress users with secure, time-limited access links, login limits, role controls, and automatic cleanup.
Email Provider ControlSend 2FA and WordPress emails through providers such as Amazon SES, Mailgun, Resend, SendGrid, or Google Workspace/Gmail.
Password Policy + Email VerificationSet password strength requirements, block password reuse, and require users to verify email addresses before login when your site needs tighter account hygiene.
Activity MonitoringLog security events across logins, lockouts, 2FA, CAPTCHA, sessions, social login, user changes, content changes, settings, plugins, themes, and more.

Who it’s for

  • Bloggers and writers

    Keep your personal site protected from login spam, username scraping, and brute-force noise without paying for a security suite.

  • Small business owners

    Protect customer, staff, and admin accounts with stronger login controls, session visibility, and reliable security emails.

  • Membership and community sites

    Give users frontend account-security tools for 2FA, passkeys, and session management without sending everyone into wp-admin.

  • Developers and agencies

    Install a flexible security foundation on client sites, including blocks and shortcodes that fit custom login and account pages.

  • Sites behind CDNs or proxies

    Use trusted proxy settings so IP-based security features understand the real visitor IP instead of yelling about your infrastructure.

What changed in the latest release

1.9.55

Version 1.9.55 is maintenance with no settings changes: it translates the Activity Log event names, 114 of the 121 built-in event types having previously displayed in English regardless of locale. Just before it, 1.9.53 improved passkey fallback feedback so a cancelled passkey prompt shows password guidance as a status message rather than an error, and cleaned up WordPress markup in frontend login form error messages. 1.9.51 corrected visitor IP detection behind Cloudflare, so security features act on the visitor rather than the proxy.

The one to check is 1.9.52. It fixed a custom generic login error message that switched login error masking off instead of on — which let visitors tell registered usernames apart from unregistered ones.

Secure the front door of your WordPress site

Download Guard Dog