30% off Pro plugins with LAUNCH30 See plugins
Dragon Login Security Pro box
All plugins

Dragon Login Security Pro

Enforce two-factor by role, trusted devices, risk-based re-challenge, a compliance report, and front-end customer 2FA — for Dragon Login Security.

Have a code? Enter it at checkout.

Documentation

A year of updates and support, renewed yearly. Cancel any time; the plugin keeps working.

Not ready to buy? Dragon Login Security is free

Or get every plugin, unlimited sites — £349/year

Enforce two-factor by role with a grace period, trust devices for a set number of days, re-challenge and alert on risky new-device logins, and route alerts to email or a signed webhook.

Features

What Dragon Login Security Pro does

Pro add-on for Dragon Login Security. Enforce two-factor by role with a grace period, trusted devices, risk-based re-challenge, a compliance report, and front-end (WooCommerce) customer 2FA.

Enforce Two-Factor by Role

Require 2FA for chosen roles, with a grace period and a block-until-enrolled screen

Compliance Report

See who is covered, in grace, or overdue, and export to CSV

Trusted Devices

Let users remember a device and skip the code for a set number of days, with revocation

Risk-Based Re-Challenge

Challenge again on a sign-in from a new device, and alert by email or webhook

Customer 2FA

A WooCommerce My Account panel (and shortcode) so front-end customers can enrol without wp-admin

Lockout-Safe

A user only counts as compliant once they add a factor AND download backup codes

Guides

Put Dragon Login Security Pro to work

Step-by-step guides from the team that builds it. All guides

Requirements

  • · WordPress 6.2 or newer
  • · PHP 8.0 or newer
  • · The free Dragon Login Security plugin
  • · WordPress 6.2+ · PHP 8.0+

Changelog

v1.0.8

Your licence now keeps working after it lapses. Pro features stay on for every activated site; renewing restores updates and support on the same key. - The licence screen shows **Lapsed**, and what that means, instead of a red Expired. - Enforcement, trusted devices and risk checks already kept running after expiry; reports, settings and customer 2FA now do too. - New versions are fetched only while the licence is current. Nothing else changes.

View full changelog →