Secure Login Shield PRO gives you multiple secret login URLs, honeypot traps, IP allow and deny rules, country filters, schedule-based access, detailed logs, and export tools — all wrapped in a clean admin experience.
/wp-login.php hits with a honeypot.Requires WordPress 6.0+ · Works with most caching/CDN setups · One-time purchase pricing on this page uses your existing PayPal buttons unchanged.
✓Use global secrets, role-based secrets, and personal user login slugs for tighter access separation.
✓Allow or deny access by IP, CIDR range, or country when paired with a GeoIP source.
✓Only allow logins during selected days and time windows that fit your operation.
✓Route direct login probing into a fake login path and optionally auto-block repeat offenders.
✓Review access attempts, suspicious events, and protection activity inside the dashboard.
✓Export security events for audits, forensics, or your own reporting workflows.
| Feature | Free | PRO |
|---|---|---|
| Private login URL (single slug) | ✔ | ✔ |
| Multiple secret URLs by global, role, or user | — | ✔ |
Stealth 404 for /wp-login.php |
✔ | ✔ + honeypot option |
| Honeypot fake login and auto-block | — | ✔ |
| IP whitelist and blacklist (IPv4 / IPv6 / CIDR) | — | ✔ |
| Country allow and deny controls | — | ✔ |
| Schedule-based access windows | — | ✔ |
| Role-based redirects after login | — | ✔ |
| Logging dashboard | — | ✔ |
| CSV and JSON log exports | — | ✔ |
🔒 Verify download checksums (MD5 & SHA-256)
🔒 Verify download checksums (MD5 & SHA-256)
🔒 Verify download checksums (MD5 & SHA-256)
Go beyond a single hidden login slug with layered access controls for real-world WordPress administration needs.
See what is hitting your login endpoints, export records, and keep better operational awareness of suspicious behavior.
Agency-friendly licensing and multiple-site tiers make PRO a stronger choice for freelancers and maintainers.
Yes. After changing secret URLs, go to Settings → Permalinks and click Save. Then clear your cache or CDN so the rewrite updates propagate.
Yes. PRO supports global secrets, role-based secrets, and user-specific personal secrets.
It can log IP, path, user-agent, referrer, and event type for security visibility. Retention is configurable and exports are on demand.
Country rules rely on a GeoIP source surfaced through the appropriate filter, letting you run allow or deny behavior for selected countries.