
Dragon Login Security
Brute-force protection and modern two-factor authentication — authenticator apps, backup codes, and passkeys — for WordPress.
Features
What Dragon Login Security does
Most WordPress break-ins are simply guessed passwords at scale. Dragon Login Security throttles repeated failures and adds two-factor through an authenticator app, with backup codes for the day someone loses their phone — and without handing your sign-in flow to a third-party service.
Passkeys (WebAuthn)
Sign in with your device instead of a code; the modern, phishing-resistant standard
Authenticator App (TOTP)
Works with Google Authenticator, 1Password, Authy, and any RFC 6238 app
Single-Use Backup Codes
Downloadable recovery codes for when you lose your device
Brute-Force Protection
Escalating lockouts after repeated failed logins, with IP allow/deny lists
Secure by Design
No auth cookie is issued until the second factor passes; secrets encrypted at rest, backup codes hashed
Activity Log Ready
Feeds Dragon Activity Log's tamper-evident audit when installed
WP-CLI Recovery
`wp dragon-login-security disable-2fa <user>` if you ever lock yourself out
Requirements
- · WordPress 6.2 or newer
- · PHP 8.0 or newer
- · WordPress 6.2+ · PHP 8.0+