Title: DCI Admin Security
Author: DreamCode Infotech
Published: <strong>01.10.2026</strong>
Last modified: 01.10.2026

---

Пошук плагінаў

![](https://ps.w.org/dci-admin-security/assets/banner-772x250.png?rev=3723214)

![](https://ps.w.org/dci-admin-security/assets/icon-128x128.png?rev=3723214)

# DCI Admin Security

 Аўтар: [DreamCode Infotech](https://profiles.wordpress.org/dreamcodeinfotech/)

[Спампаваць](https://downloads.wordpress.org/plugin/dci-admin-security.1.0.0.zip)

 * [Падрабязнасці](https://bel.wordpress.org/plugins/dci-admin-security/#description)
 * [Водгукі](https://bel.wordpress.org/plugins/dci-admin-security/#reviews)
 *  [Ўсталёўка](https://bel.wordpress.org/plugins/dci-admin-security/#installation)
 * [Распрацоўка](https://bel.wordpress.org/plugins/dci-admin-security/#developers)

 [Падтрымка](https://wordpress.org/support/plugin/dci-admin-security/)

## Апісанне

Protect WordPress login and wp-admin with IP allowlisting, custom login URLs, email
OTP, rate limiting, CAPTCHA, logging and alerts.

### Features

 * Allow exact IPv4/IPv6 addresses and CIDR ranges.
 * Accept IPv4 shorthand such as `171.61`, stored as `171.61.0.0/16`.
 * Change the WordPress login URL.
 * Protect the normal `wp-login.php` endpoint.
 * Restrict `wp-admin` by IP while keeping `admin-ajax.php` available.
 * Optional Cloudflare `CF-Connecting-IP` detection.
 * Optional trusted `X-Forwarded-For` detection for known reverse-proxy setups.
 * Optional localhost/loopback bypass for local development.
 * Brute-force rate limiting and temporary lockouts.
 * Email OTP verification for administrators, delivered to each administrator’s 
   WordPress profile email address.
 * Administrator-configured emergency fallback code for environments where email
   cannot be delivered.
 * Optional Google reCAPTCHA v2, reCAPTCHA v3 or hCaptcha on the WordPress login
   form.
 * Security event logging with an administrator viewer and configurable retention.
 * Optional email and Slack alerts for repeated blocked-IP or brute-force events.

### Important

Keep at least one known administrator IP in the allowlist before enabling IP protection.

Only enable Cloudflare IP detection when the site is actually behind Cloudflare.
Only enable trusted `X-Forwarded-For` when the server is behind a trusted reverse
proxy that sets that header.

On localhost, PHP commonly sees `127.0.0.1` or `::1` rather than the browser’s public
VPN address. Use a publicly reachable staging site for an end-to-end VPN IP test.

The emergency fallback code is stored as a password hash and is never displayed 
after saving.

### External Services

This plugin can optionally communicate with third-party CAPTCHA verification services
when CAPTCHA is enabled:

 * Google reCAPTCHA: the login page loads Google reCAPTCHA assets and sends the 
   submitted CAPTCHA token to Google’s verification endpoint. See https://policies.
   google.com/privacy and https://policies.google.com/terms.
 * hCaptcha: the login page loads hCaptcha assets and sends the submitted CAPTCHA
   token to hCaptcha’s verification endpoint. See https://www.hcaptcha.com/privacy
   and https://www.hcaptcha.com/terms.

The plugin does not contact these services when CAPTCHA is disabled.

### IP access examples

Exact IP: `186.189.26.220`

IPv4 /16 shorthand: `171.61`

CIDR: `171.61.0.0/16`

### Email OTP

After a successful WordPress administrator password check, a six-digit OTP is generated
and sent to that administrator’s WordPress profile email address.

If email delivery is unavailable, an administrator-configured emergency fallback
code can be used.

## Скрыншоты

[[

[[

[[

## Ўсталёўка

 1. Upload the plugin ZIP from Plugins > Add New > Upload Plugin.
 2. Activate DCI Admin Security.
 3. Open Settings > DCI Admin Security.
 4. Add at least one IP address or CIDR range that should be allowed to reach the protected
    login/admin area.
 5. Set the custom login slug.
 6. Save the General settings.
 7. Test the custom login URL before enabling strict IP protection on a production 
    site.
 8. Configure Email OTP, CAPTCHA, rate limiting and alerts as required.

## Водгукі

На гэты плагін няма водгукаў.

## Удзельнікі і распрацоўшчыкі

“DCI Admin Security” з’яўляецца праграмным забеспячэннем з адкрытым зыходным кодам.
Наступныя людзі ўнеслі свой уклад у гэты плагін.

Удзельнікі

 *   [ DreamCode Infotech ](https://profiles.wordpress.org/dreamcodeinfotech/)

[Перакласці “DCI Admin Security” на вашу мову.](https://translate.wordpress.org/projects/wp-plugins/dci-admin-security)

### Зацікаўлены ў распрацоўцы?

[Праглядзіце код](https://plugins.trac.wordpress.org/browser/dci-admin-security/),
праверце [SVN рэпазітарый](https://plugins.svn.wordpress.org/dci-admin-security/),
або падпішыцеся на [журнал распрацоўкі](https://plugins.trac.wordpress.org/log/dci-admin-security/)
па [RSS](https://plugins.trac.wordpress.org/log/dci-admin-security/?limit=100&mode=stop_on_copy&format=rss).

## Журнал змяненняў

#### 1.0.0

 * Resolved Plugin Check database-query and nonce warnings.
 * Sanitized emergency fallback-code input.
 * Added explicit versions to CAPTCHA provider scripts.
 * Kept IP allowlist, email OTP, and WordPress.org compatibility fixes from 1.0.0.

#### 1.0.0

 * Removed the obsolete TOTP/two-factor authentication implementation and related
   files.
 * Fixed WordPress coding-standard issues in IP handling, AJAX actions, CAPTCHA 
   output and custom database queries.
 * Added proper login CAPTCHA script enqueueing and a CAPTCHA nonce.
 * Improved PHP 7.4 compatibility by removing PHP 8-only string helper usage.
 * Updated documentation and feature list for the email OTP implementation.

#### 2.4.10

 * Improved IP allowlist matching and localhost development controls.
 * Added IP diagnostics and test tools.

#### 2.4.6

 * Added explicit trusted proxy handling for `X-Forwarded-For`.
 * Normalized IPv4-mapped IPv6 client addresses.

#### 2.0.0

 * Added brute-force rate limiting, CAPTCHA, security logging and alerts.
 * Added administrator email OTP verification.

#### 1.0.0

 * Initial release with IP allowlist and custom login URL protection.

## Мета

 *  Версія **1.0.0**
 *  Апошняе абнаўленне **3 дні таму**
 *  Актыўных установак **Менш за 10**
 *  Версія WordPress ** 6.0 або вышэй **
 *  Правераны да версіі **7.1.2**
 *  Версія PHP ** 7.4 або вышэй **
 *  Мова
 * [English (US)](https://wordpress.org/plugins/dci-admin-security/)
 * Тэгі
 * [admin security](https://bel.wordpress.org/plugins/tags/admin-security/)[custom login](https://bel.wordpress.org/plugins/tags/custom-login/)
   [ip whitelist](https://bel.wordpress.org/plugins/tags/ip-whitelist/)[login security](https://bel.wordpress.org/plugins/tags/login-security/)
   [security](https://bel.wordpress.org/plugins/tags/security/)
 *  [Пашыраны прагляд](https://bel.wordpress.org/plugins/dci-admin-security/advanced/)

## Ацэнкі

Пакуль яшчэ няма водгукаў.

[Ваш водгук](https://wordpress.org/support/plugin/dci-admin-security/reviews/#new-post)

[Паглядзець усе водгукі](https://wordpress.org/support/plugin/dci-admin-security/reviews/)

## Удзельнікі

 *   [ DreamCode Infotech ](https://profiles.wordpress.org/dreamcodeinfotech/)

## Падтрымка

Ёсць што сказаць? Патрэбна дапамога?

 [Перайсці да форуму падтрымкі](https://wordpress.org/support/plugin/dci-admin-security/)

## Падтрымаць

Ці жадаеце вы падтрымаць развіццё гэтага плагіна?

 [ Ахвяруйце на гэты плагін ](https://ko-fi.com/dreamcodeinfotech)