Dragon Login Security box
All plugins

Dragon Login Security

Brute-force protection and modern two-factor authentication — authenticator apps, backup codes, and passkeys — for WordPress.

Features

What Dragon Login Security does

Most WordPress break-ins are simply guessed passwords at scale. Dragon Login Security throttles repeated failures and adds two-factor through an authenticator app, with backup codes for the day someone loses their phone — and without handing your sign-in flow to a third-party service.

Passkeys (WebAuthn)

Sign in with your device instead of a code; the modern, phishing-resistant standard

Authenticator App (TOTP)

Works with Google Authenticator, 1Password, Authy, and any RFC 6238 app

Single-Use Backup Codes

Downloadable recovery codes for when you lose your device

Brute-Force Protection

Escalating lockouts after repeated failed logins, with IP allow/deny lists

Secure by Design

No auth cookie is issued until the second factor passes; secrets encrypted at rest, backup codes hashed

Activity Log Ready

Feeds Dragon Activity Log's tamper-evident audit when installed

WP-CLI Recovery

`wp dragon-login-security disable-2fa <user>` if you ever lock yourself out

Requirements

  • · WordPress 6.2 or newer
  • · PHP 8.0 or newer
  • · WordPress 6.2+ · PHP 8.0+

Changelog

v1.0.1
Dragon Login Security — WordPress Plugin · Dragon Core