{"id":235873,"date":"2025-08-25T14:18:53","date_gmt":"2025-08-25T14:18:53","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/shield-wp-admin\/"},"modified":"2026-06-01T10:08:26","modified_gmt":"2026-06-01T10:08:26","slug":"shield-wp-admin","status":"publish","type":"plugin","link":"https:\/\/azb.wordpress.org\/plugins\/shield-wp-admin\/","author":23139645,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.3","stable_tag":"1.0.3","tested":"7.0","requires":"5.0","requires_php":"7.2","requires_plugins":null,"header_name":"Shield WP Admin","header_author":"Differenz System","header_description":"Enhances WordPress admin security by customizing and concealing the login URL, enforcing login attempt limits, integrating Google reCAPTCHA, and disabling potential attack vectors including XML-RPC, the built-in file editor, and WordPress version exposure, etc.","assets_banners_color":"99d2fb","last_updated":"2026-06-01 10:08:26","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/shield-wp-admin\/","header_author_uri":"https:\/\/www.differenzsystem.com\/","rating":0,"author_block_rating":0,"active_installs":10,"downloads":507,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0":{"tag":"1.0","author":"differenzsystem","date":"2026-05-21 09:58:32"},"1.0.2":{"tag":"1.0.2","author":"differenzsystem","date":"2026-05-26 11:17:52"},"1.0.3":{"tag":"1.0.3","author":"differenzsystem","date":"2026-06-01 10:08:26"}},"upgrade_notice":{"1.0.3":"<p>Added audit logs and minor security improvements.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3349778,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3349778,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3397929,"resolution":"1544x500","location":"assets","locale":"","width":2320,"height":752},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3349778,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0","1.0.2","1.0.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3556537,"resolution":"1","location":"assets","locale":"","width":563,"height":709},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3556537,"resolution":"2","location":"assets","locale":"","width":1916,"height":676}},"screenshots":{"1":"Dashboard settings to manage all Shield WP Admin configurations.","2":"Audit Logs page showing login activity."}},"plugin_section":[],"plugin_tags":[46125,25642,1229,595,600],"plugin_category":[54],"plugin_contributors":[246794],"plugin_business_model":[],"class_list":["post-235873","plugin","type-plugin","status-publish","hentry","plugin_tags-brute-force-protection","plugin_tags-hide-login","plugin_tags-login-security","plugin_tags-recaptcha","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-differenzsystem","plugin_committers-differenzsystem"],"banners":{"banner":"https:\/\/ps.w.org\/shield-wp-admin\/assets\/banner-772x250.png?rev=3349778","banner_2x":"https:\/\/ps.w.org\/shield-wp-admin\/assets\/banner-1544x500.png?rev=3397929","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/shield-wp-admin\/assets\/icon-128x128.png?rev=3349778","icon_2x":"https:\/\/ps.w.org\/shield-wp-admin\/assets\/icon-256x256.png?rev=3349778","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/shield-wp-admin\/assets\/screenshot-1.png?rev=3556537","caption":"Dashboard settings to manage all Shield WP Admin configurations."},{"src":"https:\/\/ps.w.org\/shield-wp-admin\/assets\/screenshot-2.png?rev=3556537","caption":"Audit Logs page showing login activity."}],"raw_content":"<!--section=description-->\n<p><strong>Shield WP Admin<\/strong> is a lightweight yet powerful plugin designed to enhance the security of your WordPress admin area. With an easy-to-use interface and essential protection tools, it helps safeguard your site against common threats and vulnerabilities.<\/p>\n\n<p><strong>Key Features:<\/strong><\/p>\n\n<ul>\n<li><p><strong>Custom Admin Login URL<\/strong> \nHide or customize the default <code>\/wp-login.php<\/code> URL to prevent unauthorized login attempts.<\/p><\/li>\n<li><p><strong>Limit Login Attempts<\/strong>\nProtect against brute-force attacks by limiting failed login retries.<\/p><\/li>\n<li><p><strong>Google reCAPTCHA Integration<\/strong> \nAdd reCAPTCHA to the login screen to block bots and automated scripts.<\/p><\/li>\n<li><p><strong>Disable XML-RPC<\/strong><br \/>\nPrevent exploitation via XML-RPC by disabling its access entirely.<\/p><\/li>\n<li><p><strong>Disable File Editor<\/strong><br \/>\nBlock access to the theme and plugin file editor in the WordPress dashboard.<\/p><\/li>\n<li><p><strong>Hide WordPress Version<\/strong><br \/>\nConceal your WordPress version from source code to reduce exposure to targeted attacks.<\/p><\/li>\n<li><p><strong>Force HTTPS Redirection<\/strong><br \/>\nRedirect all HTTP requests to HTTPS to ensure secure access.<\/p><\/li>\n<li><p><strong>Disable Pingbacks &amp; Trackbacks<\/strong><br \/>\nProtect your site from spam and DDoS attacks by disabling pingbacks and trackbacks.<\/p><\/li>\n<li><p><strong>IP Blacklisting<\/strong>\nBlock specific IP addresses directly from the admin panel to protect the site.<\/p><\/li>\n<li><p><strong>Admin Login Form Logo Change<\/strong>\nCustomize the logo displayed on the WordPress login form.<\/p><\/li>\n<li><p><strong>Audit Logs<\/strong>\nShield WP Admin includes an <strong>Audit Logs<\/strong> admin page to help you monitor user login activity.<\/p>\n\n<ul>\n<li><strong>Where to find it<\/strong>: <strong>WordPress Admin -&gt; Shield WP Admin -&gt; Audit Logs<\/strong><\/li>\n<li><strong>What it records<\/strong>: user login activity events (e.g. successful\/failed logins).<\/li>\n<li><strong>Why it helps<\/strong>: Investigate suspicious access attempts and review login history.<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<h4>Why Shield WP Admin?<\/h4>\n\n<p>Whether you're a developer or a site owner, Shield WP Admin provides a smart, flexible solution to strengthen your WordPress backend without bloating your site or overwhelming your dashboard.<\/p>\n\n<h3>Shield WP Admin Pro Features:<\/h3>\n\n<p><strong>Shield WP Admin Pro<\/strong> is a powerful WordPress security plugin designed specifically to protect and harden the WordPress admin area. It focuses on preventing unauthorized access, reducing common attack vectors, and providing administrators with clear visibility into security-related activities.<\/p>\n\n<p>Instead of relying on a single protection layer, Shield WP Admin Pro applies multiple security mechanisms such as login protection, two-factor authentication, bot detection, file change monitoring, and backup recovery tools. The plugin is suitable for single-site owners, agencies, and developers managing multiple WordPress installations.<\/p>\n\n<h4><a href=\"https:\/\/www.templatemonster.com\/wordpress-plugins\/shield-wp-admin-pro-plugin-ultimate-admin-protection-570078.html\">Click here to purchase Shield WP Admin Pro now!<\/a><\/h4>\n\nRead our plugin <a href=\"https:\/\/swpapro.differenzuat.com\/documentation\/\">documentation<\/a> for more details.\n\n<h4>1. Login Security:<\/h4>\n\n<p>The <strong>Login Security<\/strong> module protects your WordPress login system against automated bots, brute-force attempts, and malicious injection attacks. It also allows you to configure notifications and manual user registration approval.<\/p>\n\n<h4>2. Rate Limit &amp; Bot Protection:<\/h4>\n\n<p>The <strong>Rate Limit &amp; Bot Protection<\/strong> module helps protect your WordPress admin area and custom login page from automated bots, excessive requests, and brute-force attacks by monitoring request patterns and user-agent behavior.<\/p>\n\n<h4>3. Fake Bot Detection:<\/h4>\n\n<p>The <strong>Fake Bot Detection<\/strong> feature protects your website from malicious crawlers that pretend to be legitimate search engine bots such as Googlebot, Bingbot, or other well-known crawlers. Many bots fake their User-Agent string to bypass basic security checks. Shield WP Admin Pro verifies these requests using DNS validation to ensure that the request actually originates from the official crawler network.<\/p>\n\n<h4>4. Two-Factor Authentication:<\/h4>\n\n<p>The <strong>Two-Factor Authentication (2FA)<\/strong> adds an extra layer of security to WordPress user accounts by requiring a second verification step during login. Even if a password is compromised, unauthorized access is prevented.\nSupported Authenticator Apps: Google Authenticator (iOS &amp; Android) and Microsoft Authenticator (iOS &amp; Android)<\/p>\n\n<h4>5. Secure APIs:<\/h4>\n\n<p>The <strong>Secure APIs<\/strong> module helps protect your WordPress site from data exposure and abuse through REST APIs and application-level entry points.<\/p>\n\n<h4>6. Hotlink Protection:<\/h4>\n\n<p>The <strong>Hotlink Protection<\/strong> feature prevents other websites from directly embedding your images and media files, helping to protect your bandwidth and server resources. When hotlink protection is enabled, only approved domains are allowed to load images hosted on your website.<\/p>\n\n<h4>7. Malware Scanner:<\/h4>\n\n<p>The <strong>Malware Scanner<\/strong> module scans your WordPress installation for suspicious files, malicious code patterns, and unexpected file changes that may indicate a security threat. It provides manual and automatic scanning options, quarantine handling, and file exclusion controls to give you full visibility and control.<\/p>\n\n<h4>8. File Modified Scanner:<\/h4>\n\n<p>The <strong>File Modified Scanner<\/strong> helps you monitor changes made to your WordPress files. It is designed to detect unauthorized or unexpected file modifications that may indicate hacking, malware injection, or suspicious activity.<\/p>\n\n<h4>9. Login Analytics:<\/h4>\n\n<p>The <strong>Login Analytics<\/strong> module provides detailed insights into user login activity across your WordPress site. It helps administrators monitor login behavior, detect unusual access patterns, and improve overall account security.<\/p>\n\n<h4>10. Traffic Analytics:<\/h4>\n\n<p>The <strong>Traffic Analytics<\/strong> module provides real-time visibility into visitor activity across your WordPress site. It tracks page hits, requests, IP addresses, referrers, and client details to help you understand traffic behavior and detect suspicious activity.<\/p>\n\n<h4>11. Backup &amp; Restore:<\/h4>\n\n<p>The <strong>Backup &amp; Restore<\/strong> feature allows you to create secure backups of your WordPress site and restore them when needed. This is especially useful before updates, migrations, troubleshooting, or recovering from unexpected issues.<\/p>\n\n<h4>12. Email &amp; SMTP:<\/h4>\n\n<p>The <strong>Email &amp; SMTP<\/strong> module ensures reliable email delivery for all system notifications, security alerts, and OTP emails generated by Shield WP Admin Pro. Proper SMTP configuration is essential for features such as Email OTP, alerts, and administrative notifications.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin uses Google reCAPTCHA to protect the admin login from automated brute-force attacks.<\/p>\n\n<ul>\n<li><strong>Service Used<\/strong>: Google reCAPTCHA<\/li>\n<li><strong>Service Domain<\/strong>: https:\/\/www.google.com\/recaptcha<\/li>\n<li><strong>Purpose<\/strong>: Used to verify that the user is human, preventing spam or Brute-force attacks on admin login protected by the plugin.<\/li>\n<li><strong>What Data is Sent<\/strong>: When a user interacts with a reCAPTCHA-protected form, their interaction (including IP address, user agent, and possibly cookies) is sent to Google's reCAPTCHA service for validation and verification.<\/li>\n<li><strong>When Data is Sent<\/strong>: This data is transmitted to Google when the form is loaded (due to the JS script) and again when the form is submitted.<\/li>\n<li><strong>Service Provider<\/strong>: Google<\/li>\n<li><strong>Terms of Service<\/strong>: https:\/\/policies.google.com\/terms<\/li>\n<li><strong>Privacy Policy<\/strong>: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder <code>shield-wp-admin<\/code> to the <code>\/wp-content\/plugins\/<\/code> directory, or install it directly via the WordPress Plugins screen.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu in WordPress.<\/li>\n<li>Navigate to Shield WP Admin in the WordPress admin menu.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20can%20i%20access%20the%20login%20page%20after%20changing%20the%20url%3F\"><h3>How can I access the login page after changing the URL?<\/h3><\/dt>\n<dd><p>Make sure to bookmark or note your new login URL. If you forget it, you can disable the plugin via FTP or your hosting control panel.<\/p><\/dd>\n<dt id=\"will%20this%20plugin%20conflict%20with%20other%20security%20plugins%3F\"><h3>Will this plugin conflict with other security plugins?<\/h3><\/dt>\n<dd><p>Shield WP Admin is built to work alongside most major security plugins. However, it's best to avoid overlapping functionalities like multiple reCAPTCHA or login limiter features.<\/p><\/dd>\n<dt id=\"what%20is%20the%20default%20admin%20login%20slug%20when%20you%27ve%20activated%20it%3F\"><h3>What is the default admin login slug when you've activated it?<\/h3><\/dt>\n<dd><p>Default admin login slug is <code>mysecretlogin<\/code>.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20impact%20website%20performance%3F\"><h3>Does the plugin impact website performance?<\/h3><\/dt>\n<dd><p>The plugin is built to be lightweight.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20forget%20my%20custom%20login%20url%3F\"><h3>What happens if I forget my custom login URL?<\/h3><\/dt>\n<dd><p>Disable the plugin via FTP or your hosting file manager to restore the default WordPress login URL, then reconfigure your preferred custom path.<\/p><\/dd>\n<dt id=\"which%20features%20are%20available%20in%20the%20free%20version%3F\"><h3>Which features are available in the free version?<\/h3><\/dt>\n<dd><p>The free tier includes core login protection. Premium-only modules cover malware integrity scanning, QR code generation, license validation, and advanced controls.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Added user audit logs to the admin panel.<\/li>\n<li>Minor improvements and bug fixes.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Tested compatibility with the latest WordPress version.<\/li>\n<li>Minor improvements and fixes.<\/li>\n<\/ul>\n\n<h4>1.0<\/h4>\n\n<ul>\n<li>Initial release of Shield WP Admin with core security features.<\/li>\n<\/ul>","raw_excerpt":"Secure and harden your WordPress admin area with powerful features like custom login URLs, reCAPTCHA, brute-force protection, and more.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/235873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=235873"}],"author":[{"embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/differenzsystem"}],"wp:attachment":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=235873"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=235873"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=235873"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=235873"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=235873"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=235873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}