{"id":361311,"date":"2026-09-02T23:31:48","date_gmt":"2026-09-02T23:31:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/login-sentinel-limit-login-attempts-login-security-activity-log\/"},"modified":"2026-09-18T08:26:39","modified_gmt":"2026-09-18T08:26:39","slug":"sentrilog","status":"publish","type":"plugin","link":"https:\/\/pt.wordpress.org\/plugins\/sentrilog\/","author":23382822,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.0","stable_tag":"1.2.0","tested":"7.1.1","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"SentriLog - Limit Login Attempts, Security & Activity Log","header_author":"Md Rayhan Uddin","header_description":"Limit login attempts, log activity, and receive email alerts on suspicious logins. Keep your WordPress site secure with a lightweight, privacy-first security plugin.","assets_banners_color":"101c31","last_updated":"2026-09-18 08:26:39","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/wise.com\/pay\/me\/mdrayhanu2","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/sentrilog","header_author_uri":"https:\/\/rayetun.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":227,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"rayetun","date":"2026-09-02 23:31:40","revision":3678792},"1.0.1":{"tag":"1.0.1","author":"rayetun","date":"2026-09-07 05:19:51","revision":3684197},"1.1.0":{"tag":"1.1.0","author":"rayetun","date":"2026-09-15 18:40:16","revision":3697570},"1.2.0":{"tag":"1.2.0","author":"rayetun","date":"2026-09-18 08:26:39","revision":3701591}},"upgrade_notice":{"1.2.0":"<p>Adds Cloudflare Turnstile as a privacy-first alternative to Google reCAPTCHA. Your existing CAPTCHA settings are kept.<\/p>","1.1.0":"<p>Adds optional Google reCAPTCHA for your login and related forms (off by default; bring your own keys).<\/p>","1.0.1":"<p>Adds optional two-factor authentication (authenticator app + backup codes). Enable it under Users \u2192 Profile.<\/p>","1.0.0":"<p>Initial release. No upgrade steps needed.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3678792,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3678792,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3678792,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3678792,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3678792,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.1.0","1.2.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3678792,"resolution":"1","location":"assets","locale":"","width":1712,"height":1465},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3678792,"resolution":"2","location":"assets","locale":"","width":1708,"height":1410},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3678792,"resolution":"3","location":"assets","locale":"","width":1709,"height":1261},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3678792,"resolution":"4","location":"assets","locale":"","width":1718,"height":1440},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3678792,"resolution":"5","location":"assets","locale":"","width":1715,"height":1843},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3678792,"resolution":"6","location":"assets","locale":"","width":1713,"height":1240},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3678792,"resolution":"7","location":"assets","locale":"","width":1715,"height":1312}},"screenshots":{"1":"Dashboard \u2014 at-a-glance stats for logins, failures, and lockouts over 24 hours and 7 days, with a 7-day trend chart.","2":"Activity Log \u2014 filterable, badge-coded table of every authentication event with IP, username, and timestamp.","3":"Lockouts Manager \u2014 view active lockouts with live countdown timers and clear them individually or all at once.","4":"Settings \u2014 Lockout: configure attempt limits, time window, lockout duration, and progressive escalation.","5":"Settings \u2014 Security: change the login URL, harden against username enumeration, and set the client IP source.","6":"Settings \u2014 Notifications: choose the alert email and the conditions that trigger it.","7":"Magic Login \u2014 generate temporary, single-use, passwordless login links."}},"plugin_section":[],"plugin_tags":[8531,2439,161905,9374,1229],"plugin_category":[],"plugin_contributors":[263109],"plugin_business_model":[],"class_list":["post-361311","plugin","type-plugin","status-publish","hentry","plugin_tags-activity-log","plugin_tags-brute-force","plugin_tags-hide-login-url","plugin_tags-limit-login-attempts","plugin_tags-login-security","plugin_contributors-rayetun","plugin_committers-rayetun"],"banners":{"banner":"https:\/\/ps.w.org\/sentrilog\/assets\/banner-772x250.png?rev=3678792","banner_2x":"https:\/\/ps.w.org\/sentrilog\/assets\/banner-1544x500.png?rev=3678792","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/sentrilog\/assets\/icon.svg?rev=3678792","icon":"https:\/\/ps.w.org\/sentrilog\/assets\/icon.svg?rev=3678792","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/sentrilog\/assets\/screenshot-1.png?rev=3678792","caption":"Dashboard \u2014 at-a-glance stats for logins, failures, and lockouts over 24 hours and 7 days, with a 7-day trend chart."},{"src":"https:\/\/ps.w.org\/sentrilog\/assets\/screenshot-2.png?rev=3678792","caption":"Activity Log \u2014 filterable, badge-coded table of every authentication event with IP, username, and timestamp."},{"src":"https:\/\/ps.w.org\/sentrilog\/assets\/screenshot-3.png?rev=3678792","caption":"Lockouts Manager \u2014 view active lockouts with live countdown timers and clear them individually or all at once."},{"src":"https:\/\/ps.w.org\/sentrilog\/assets\/screenshot-4.png?rev=3678792","caption":"Settings \u2014 Lockout: configure attempt limits, time window, lockout duration, and progressive escalation."},{"src":"https:\/\/ps.w.org\/sentrilog\/assets\/screenshot-5.png?rev=3678792","caption":"Settings \u2014 Security: change the login URL, harden against username enumeration, and set the client IP source."},{"src":"https:\/\/ps.w.org\/sentrilog\/assets\/screenshot-6.png?rev=3678792","caption":"Settings \u2014 Notifications: choose the alert email and the conditions that trigger it."},{"src":"https:\/\/ps.w.org\/sentrilog\/assets\/screenshot-7.png?rev=3678792","caption":"Magic Login \u2014 generate temporary, single-use, passwordless login links."}],"raw_content":"<!--section=description-->\n<p>\ud83d\udee1\ufe0f <strong>SentriLog<\/strong> is the free way to <strong>stop brute-force attacks<\/strong> on your WordPress login and <strong>see exactly what is happening<\/strong> at your front door. Install, activate, and you're protected \u2014 smart per-IP lockouts, a full authentication activity log, login hardening, and instant email alerts, all with <strong>zero configuration required<\/strong>.<\/p>\n\n<p>Most attacks on WordPress start at <code>wp-login.php<\/code>: bots hammer it with thousands of username and password guesses. SentriLog counts every failed attempt, locks out offenders automatically, records the whole story, and lets you move the login page somewhere bots can't find it.<\/p>\n\n<p><strong>Everything runs on your own site by default.<\/strong> SentriLog makes <strong>no external HTTP requests<\/strong> out of the box \u2014 every lockout, log entry, and setting stays in your own WordPress database. No account, no tracking. The one optional exception is the CAPTCHA integration (Google reCAPTCHA or Cloudflare Turnstile), which stays off until you add your own keys (fully disclosed under External Services below).<\/p>\n\n<h4>How SentriLog is built<\/h4>\n\n<ul>\n<li>\u26a1 <strong>Zero-config<\/strong>: protection and logging start the moment you activate \u2014 sensible defaults, nothing to set up<\/li>\n<li>\ud83d\udd12 <strong>Privacy-first<\/strong>: no data collection and no phone-home; no external calls at all unless you switch on the optional CAPTCHA (reCAPTCHA or Turnstile)<\/li>\n<li>\ud83e\udeb6 <strong>Lightweight<\/strong>: bot detection runs only on login\/authentication events, so normal visitors are never slowed down<\/li>\n<li>\ud83e\udde9 <strong>Works with any login form<\/strong>: hooks WordPress core auth (<code>authenticate<\/code>, <code>wp_login_failed<\/code>, <code>wp_login<\/code>), so WooCommerce, membership, and custom login forms are all covered<\/li>\n<li>\ud83c\udf10 <strong>Multisite compatible<\/strong>: activate per-site or network-wide, each site with its own settings and log<\/li>\n<\/ul>\n\n<h4>\u26a1 Smart Brute-Force Protection<\/h4>\n\n<p>Lock out attackers automatically, without locking out your real users.<\/p>\n\n<ul>\n<li>\ud83d\udd22 <strong>Limit login attempts<\/strong> \u2014 lock an IP after a configurable number of failed tries within a rolling time window<\/li>\n<li>\ud83d\udcc8 <strong>Progressive lockout escalation<\/strong> \u2014 repeat offenders are locked out for longer, automatically<\/li>\n<li>\ud83d\udc65 <strong>Per-IP + username tracking<\/strong> \u2014 attempts are counted per IP and username pair, so one attacker can't lock out everyone<\/li>\n<li>\ud83e\uddee <strong>Remaining-attempts hint<\/strong> \u2014 optionally tell users how many tries remain before a lockout<\/li>\n<li>\ud83e\uddf7 <strong>XML-RPC protection<\/strong> \u2014 detects and blocks <code>system.multicall<\/code> brute-force patterns<\/li>\n<li>\ud83d\uddc2\ufe0f <strong>Lockout manager<\/strong> \u2014 view every active lockout with a live countdown, and clear one or all in a click<\/li>\n<\/ul>\n\n<h4>\ud83d\udccb Full Activity Log &amp; Audit Trail<\/h4>\n\n<p>Know who tried to get in, from where, and when.<\/p>\n\n<ul>\n<li>\ud83d\udcdd <strong>Every event recorded<\/strong> \u2014 login successes, failures, logouts, lockouts, and password events, each with IP address, username, user-agent, and timestamp<\/li>\n<li>\ud83d\udd0d <strong>Filter and search<\/strong> \u2014 narrow the log by event type, username, IP, or date range<\/li>\n<li>\u2b07\ufe0f <strong>CSV export<\/strong> \u2014 download the activity log (respecting your current filters) for audits or spreadsheets<\/li>\n<li>\ud83e\uddf9 <strong>Retention &amp; auto-cleanup<\/strong> \u2014 set how long logs are kept (90 days by default); old records are pruned automatically via WP-Cron<\/li>\n<\/ul>\n\n<h4>\ud83d\udd11 Access Control<\/h4>\n\n<p><strong>\ud83d\udeaa Change Login URL<\/strong>\nMove <code>wp-login.php<\/code> to a secret slug of your choice and block the default endpoint, so automated attacks never even find the login form. A built-in emergency recovery link means you can never be permanently locked out.<\/p>\n\n<p><strong>\ud83e\ude84 Magic Login<\/strong>\nGenerate temporary, single-use, passwordless login links for support staff or clients. The temporary user is created on demand and removed automatically the moment the link expires or is revoked \u2014 no lingering accounts.<\/p>\n\n<p><strong>\u23f2\ufe0f Idle Session Timeout<\/strong>\nAutomatically sign out inactive users after a period you choose, so an unattended browser doesn't become an open door.<\/p>\n\n<h4>\ud83d\udd10 Two-Factor Authentication<\/h4>\n\n<p>Add a second layer to any account \u2014 no external service, no account required.<\/p>\n\n<ul>\n<li>\ud83d\udcf1 <strong>Authenticator app (TOTP)<\/strong> \u2014 works with Google Authenticator, Authy, Microsoft Authenticator, 1Password, and any standard TOTP app<\/li>\n<li>\ud83d\udd33 <strong>Local QR code<\/strong> \u2014 the setup QR is drawn in your browser, so the shared secret never leaves your site<\/li>\n<li>\ud83d\udd11 <strong>Backup codes<\/strong> \u2014 single-use recovery codes for when you don't have your device<\/li>\n<li>\ud83d\udd12 <strong>Encrypted at rest<\/strong> \u2014 the 2FA secret is encrypted in the database, so a stray database dump can't expose it<\/li>\n<li>\ud83d\udc64 <strong>Opt-in per user<\/strong> \u2014 each user turns it on from their own profile screen<\/li>\n<\/ul>\n\n<h4>\ud83e\uddf1 Login Hardening<\/h4>\n\n<ul>\n<li>\ud83d\ude48 <strong>Username enumeration protection<\/strong> \u2014 normalize login error messages, block <code>?author=N<\/code> and author-archive scans, and lock down the REST API users endpoint so attackers can't harvest valid usernames<\/li>\n<li>\ud83c\udf10 <strong>Configurable IP source<\/strong> \u2014 choose exactly how visitor IPs are detected (direct connection, Cloudflare, reverse proxy, or load balancer) so a spoofed header can't defeat your lockouts<\/li>\n<li>\ud83e\uddf7 <strong>XML-RPC multicall blocking<\/strong> \u2014 shut down a common amplification vector for password guessing<\/li>\n<\/ul>\n\n<h4>\ud83e\udd16 CAPTCHA (optional)<\/h4>\n\n<p>Add a CAPTCHA to your login, lost-password, and registration forms to stop bots before they ever reach your credentials. <strong>Off by default<\/strong> \u2014 bring your own free keys to switch it on.<\/p>\n\n<ul>\n<li>\ud83d\udee1\ufe0f <strong>Choose your provider<\/strong> \u2014 Google reCAPTCHA or <strong>Cloudflare Turnstile<\/strong>, a privacy-first challenge that does not track users<\/li>\n<li>\ud83e\udde9 <strong>reCAPTCHA v3 (invisible) or v2 (checkbox)<\/strong> \u2014 v3 scores requests silently; v2 shows the classic \"I'm not a robot\" checkbox<\/li>\n<li>\ud83c\udfaf <strong>Adjustable score threshold<\/strong> for reCAPTCHA v3 \u2014 tune how strict the bot filter is<\/li>\n<li>\ud83d\uddc2\ufe0f <strong>Per-form control<\/strong> \u2014 protect the login, lost-password, and\/or registration forms independently<\/li>\n<li>\ud83d\udd10 <strong>Verified server-side<\/strong> with your secret key; fails open during a provider outage so you're never locked out<\/li>\n<\/ul>\n\n<p>CAPTCHA is the only part of SentriLog that contacts an external service \u2014 see the <strong>External Services<\/strong> section for the full data disclosure.<\/p>\n\n<h4>\ud83d\udd14 Alerts &amp; Dashboard<\/h4>\n\n<ul>\n<li>\u2709\ufe0f <strong>Email alerts<\/strong> \u2014 get notified after a configurable number of consecutive failures, and whenever a lockout is triggered<\/li>\n<li>\ud83d\udcca <strong>At-a-glance dashboard<\/strong> \u2014 logins, failures, and lockouts over the last 24 hours and 7 days, with a 7-day trend chart (Chart.js, bundled locally \u2014 no external requests)<\/li>\n<li>\ud83c\udf17 <strong>Light &amp; dark mode<\/strong> \u2014 a clean, modern admin UI with a one-click theme toggle; light by default<\/li>\n<li>\ud83e\uddf0 <strong>Tabbed settings<\/strong> \u2014 Lockout, Security, Logging, and Notifications, each with sensible defaults<\/li>\n<\/ul>\n\n<h4>\ud83d\udd12 Privacy First<\/h4>\n\n<p>SentriLog is built to protect your users' privacy as well as your site:<\/p>\n\n<ul>\n<li>Makes <strong>no external HTTP requests by default<\/strong> \u2014 the only feature that contacts an outside service is the optional CAPTCHA (Google reCAPTCHA or Cloudflare Turnstile), which stays off until you enable it (see External Services)<\/li>\n<li>Stores data <strong>only in your own database<\/strong> to enforce lockouts and provide an audit trail<\/li>\n<li>Cleans up completely on uninstall \u2014 drops its tables, deletes its options, removes any temporary Magic Login users, and clears its scheduled events<\/li>\n<li>A <code>rayetun_lsn_anonymise_ip<\/code> filter is available if you want to anonymize stored IP addresses<\/li>\n<\/ul>\n\n<h4>\ud83d\udc69\u200d\ud83d\udcbb For Developers<\/h4>\n\n<p>SentriLog is built on WordPress standards and exposes hooks so you can extend it:<\/p>\n\n<ul>\n<li><code>rayetun_login_sentinel_event_logged( $event_type, $user_id, $username, $ip, $extra_data )<\/code> \u2014 fires after every logged event<\/li>\n<li><code>rayetun_login_sentinel_lockout_triggered( $ip, $username, $duration, $attempt_count )<\/code> \u2014 fires when an IP is locked out<\/li>\n<li><code>rayetun_login_sentinel_should_lockout( $should_check, $ip, $username )<\/code> \u2014 short-circuit the lockout check (e.g. for an allowlist)<\/li>\n<li><code>rayetun_lsn_anonymise_ip<\/code> \u2014 filter stored IP addresses for anonymization<\/li>\n<li><code>rayetun_login_sentinel_2fa_verified( $user_id )<\/code> \u2014 fires after a user passes two-factor verification<\/li>\n<\/ul>\n\n<h3>Upgrade to SentriLog Pro<\/h3>\n\n<p>SentriLog is fully functional on its own \u2014 Pro is an optional upgrade for teams and agencies that want more. It adds, among other things:<\/p>\n\n<ul>\n<li>Advanced two-factor authentication \u2014 passkeys \/ WebAuthn (Face ID, Touch ID, security keys), email OTP, trusted-device bypass, and per-role enforcement<\/li>\n<li>IP allowlist &amp; blocklist with CIDR ranges, plus country blocking with separate block and allow lists<\/li>\n<li>Breached-password protection (Have I Been Pwned) and login anomaly detection (impossible travel + new device)<\/li>\n<li>File integrity monitoring, threat-intelligence IP reputation, and business-hours admin access<\/li>\n<li>Slack, Discord &amp; webhook alert routing, self-service lockout recovery, and a weekly security digest<\/li>\n<li>Agency tools \u2014 a multisite network dashboard, settings export\/import &amp; sync, and white-labeled client PDF reports<\/li>\n<\/ul>\n\n<p>Every plan includes a 14-day free trial. Open <strong>SentriLog \u2192 Go Pro<\/strong> in your dashboard for the full list and pricing.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>SentriLog is self-contained and, by default, makes no external requests. Its optional CAPTCHA feature can use <strong>one<\/strong> of two third-party providers, both <strong>disabled by default<\/strong> and used only if you choose to turn one on. You pick the provider and supply your own keys.<\/p>\n\n<h4>Google reCAPTCHA<\/h4>\n\n<p>If you select Google reCAPTCHA under <strong>SentriLog \u2192 Settings \u2192 CAPTCHA<\/strong> and enter your own keys, SentriLog protects the login, lost-password, and\/or registration forms you select with Google reCAPTCHA, a bot-detection service provided by Google.<\/p>\n\n<ul>\n<li><strong>When it runs:<\/strong> only on the forms you choose to protect, and only while reCAPTCHA is enabled with valid keys. Visitors' browsers load the reCAPTCHA script from Google, and when a protected form is submitted the reCAPTCHA token and the visitor's IP address are sent to Google to confirm the request is human.<\/li>\n<li><strong>Data sent:<\/strong> the reCAPTCHA response token and the visitor's IP address. No other personal data is transmitted, and nothing is sent when reCAPTCHA is disabled.<\/li>\n<li><strong>Endpoints:<\/strong> the script is loaded from <code>https:\/\/www.google.com\/recaptcha\/api.js<\/code> and tokens are verified at <code>https:\/\/www.google.com\/recaptcha\/api\/siteverify<\/code>.<\/li>\n<li><strong>Terms:<\/strong> use of Google reCAPTCHA is subject to Google's <a href=\"https:\/\/policies.google.com\/terms\">Terms of Service<\/a> and <a href=\"https:\/\/policies.google.com\/privacy\">Privacy Policy<\/a>.<\/li>\n<\/ul>\n\n<h4>Cloudflare Turnstile<\/h4>\n\n<p>If you select Cloudflare Turnstile under <strong>SentriLog \u2192 Settings \u2192 CAPTCHA<\/strong> and enter your own keys, SentriLog protects the forms you select with Cloudflare Turnstile, a privacy-first bot-detection service provided by Cloudflare that does not track users or serve interactive image challenges.<\/p>\n\n<ul>\n<li><strong>When it runs:<\/strong> only on the forms you choose to protect, and only while Turnstile is enabled with valid keys. Visitors' browsers load the Turnstile script from Cloudflare, and when a protected form is submitted the Turnstile token and the visitor's IP address are sent to Cloudflare to confirm the request is human.<\/li>\n<li><strong>Data sent:<\/strong> the Turnstile response token and the visitor's IP address. No other personal data is transmitted, and nothing is sent when Turnstile is disabled.<\/li>\n<li><strong>Endpoints:<\/strong> the script is loaded from <code>https:\/\/challenges.cloudflare.com\/turnstile\/v0\/api.js<\/code> and tokens are verified at <code>https:\/\/challenges.cloudflare.com\/turnstile\/v0\/siteverify<\/code>.<\/li>\n<li><strong>Terms:<\/strong> use of Cloudflare Turnstile is subject to Cloudflare's <a href=\"https:\/\/www.cloudflare.com\/website-terms\/\">Website Terms of Use<\/a> and <a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">Privacy Policy<\/a>.<\/li>\n<\/ul>\n\n<p>If you never enable CAPTCHA, SentriLog makes no external requests at all.<\/p>\n\n<h3>Credits<\/h3>\n\n<p>SentriLog is built and maintained by <a href=\"https:\/\/rayetun.com\/\">Md Rayhan Uddin<\/a>.<\/p>\n\n<p>This plugin bundles the following open-source library, served locally from the plugin \u2014 no external requests are made to load it:<\/p>\n\n<ul>\n<li><strong>Chart.js<\/strong> v4.5.1 \u2014 used to render the dashboard trend chart. Copyright (c) Chart.js Contributors, <a href=\"https:\/\/github.com\/chartjs\/Chart.js\/blob\/master\/LICENSE.md\">MIT License<\/a>. Project: https:\/\/www.chartjs.org<\/li>\n<\/ul>\n\n<p>Thank you to the WordPress community and to everyone who reports issues and suggests features on the <a href=\"https:\/\/wordpress.org\/support\/plugin\/sentrilog\/\">support forum<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>sentrilog<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install directly through <strong>Plugins \u2192 Add New<\/strong>.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> screen in WordPress.<\/li>\n<li>Go to <strong>SentriLog \u2192 Dashboard<\/strong> to watch your login activity in real time.<\/li>\n<\/ol>\n\n<p>No configuration is required to get started \u2014 SentriLog begins limiting login attempts and logging events immediately after activation. Fine-tune attempt limits, hardening, and email alerts any time under <strong>SentriLog \u2192 Settings<\/strong>.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"%E2%9D%93%20will%20this%20plugin%20lock%20me%20out%20of%20my%20own%20site%3F\"><h3>\u2753 Will this plugin lock me out of my own site?<\/h3><\/dt>\n<dd><p>It can, if you enter the wrong credentials too many times. If it happens, you have three easy ways back in: use the <strong>Change Login URL<\/strong> emergency recovery link, temporarily deactivate the plugin by renaming its folder over FTP\/SSH, or remove the lockout in your database with <code>DELETE FROM wp_rayetun_lsn_lockouts WHERE ip_address = 'YOUR_IP';<\/code>.<\/p><\/dd>\n<dt id=\"%F0%9F%8C%90%20does%20it%20make%20any%20external%20requests%20or%20send%20my%20data%20anywhere%3F\"><h3>\ud83c\udf10 Does it make any external requests or send my data anywhere?<\/h3><\/dt>\n<dd><p>By default, no \u2014 SentriLog makes <strong>zero external HTTP requests<\/strong> and stores everything in your own WordPress database. The dashboard chart uses <strong>Chart.js<\/strong>, bundled locally (MIT licensed) \u2014 no CDN. The one exception is the <strong>optional CAPTCHA<\/strong> integration: it stays off until you add your own Google reCAPTCHA or Cloudflare Turnstile keys, and when enabled it verifies protected form submissions with your chosen provider. See the External Services section below for exactly what is sent.<\/p><\/dd>\n<dt id=\"%F0%9F%94%8C%20does%20it%20work%20with%20woocommerce%2C%20membership%20plugins%2C%20or%20custom%20login%20forms%3F\"><h3>\ud83d\udd0c Does it work with WooCommerce, membership plugins, or custom login forms?<\/h3><\/dt>\n<dd><p>Yes. SentriLog hooks WordPress core authentication filters (<code>authenticate<\/code>, <code>wp_login_failed<\/code>, <code>wp_login<\/code>), which fire no matter which login form is used \u2014 WooCommerce, BuddyPress, membership plugins, and custom forms are all protected.<\/p><\/dd>\n<dt id=\"%F0%9F%95%B5%EF%B8%8F%20can%20i%20hide%20my%20login%20page%3F\"><h3>\ud83d\udd75\ufe0f Can I hide my login page?<\/h3><\/dt>\n<dd><p>Yes. The <strong>Change Login URL<\/strong> feature moves <code>wp-login.php<\/code> to a secret slug you choose and blocks the default endpoint, so bots can't find the form. An emergency recovery link makes sure you can always get back in.<\/p><\/dd>\n<dt id=\"%F0%9F%AA%84%20what%20is%20magic%20login%3F\"><h3>\ud83e\ude84 What is Magic Login?<\/h3><\/dt>\n<dd><p>Magic Login creates a temporary, single-use, passwordless login link you can hand to support staff or a client. The temporary user is removed automatically when the link expires or you revoke it \u2014 no leftover accounts.<\/p><\/dd>\n<dt id=\"%F0%9F%94%90%20how%20do%20i%20turn%20on%20two-factor%20authentication%3F\"><h3>\ud83d\udd10 How do I turn on two-factor authentication?<\/h3><\/dt>\n<dd><p>Go to <strong>Users \u2192 Profile<\/strong> and scroll to the <strong>Two-Factor Authentication<\/strong> section. Scan the QR code with any authenticator app, enter the 6-digit code to confirm, and save your profile. You'll be shown a set of backup codes once \u2014 store them somewhere safe. From then on, you'll enter a code from your app each time you log in. To turn it off, tick \"Disable two-factor authentication\" on the same screen and save. (Trusted devices, email codes, and requiring 2FA for whole roles are available in the Pro add-on.)<\/p><\/dd>\n<dt id=\"%F0%9F%9B%A1%EF%B8%8F%20does%20it%20protect%20xml-rpc%3F\"><h3>\ud83d\udee1\ufe0f Does it protect XML-RPC?<\/h3><\/dt>\n<dd><p>Yes. SentriLog detects <code>system.multicall<\/code> brute-force patterns and blocks that request, closing a common password-guessing amplification vector.<\/p><\/dd>\n<dt id=\"%F0%9F%93%9C%20is%20it%20gdpr-friendly%3F\"><h3>\ud83d\udcdc Is it GDPR-friendly?<\/h3><\/dt>\n<dd><p>SentriLog stores IP addresses in your own database to enforce lockouts and keep an audit trail \u2014 IP addresses can be personal data, so you should disclose this in your site's privacy policy. Nothing is ever transmitted to us, logs are auto-deleted after your chosen retention period, and a <code>rayetun_lsn_anonymise_ip<\/code> filter is available if you want to anonymize stored IPs. If you enable the optional CAPTCHA, visitor IPs are also sent to your chosen provider (Google or Cloudflare) for verification \u2014 see External Services below.<\/p><\/dd>\n<dt id=\"%F0%9F%A4%96%20how%20do%20i%20enable%20captcha%2C%20and%20is%20it%20required%3F\"><h3>\ud83e\udd16 How do I enable CAPTCHA, and is it required?<\/h3><\/dt>\n<dd><p>It's completely optional and off by default. To turn it on, go to <strong>SentriLog \u2192 Settings \u2192 CAPTCHA<\/strong>, pick a provider \u2014 Google reCAPTCHA (<a href=\"https:\/\/www.google.com\/recaptcha\/admin\">get keys<\/a>) or Cloudflare Turnstile (<a href=\"https:\/\/dash.cloudflare.com\/?to=\/:account\/turnstile\">get keys<\/a>) \u2014 paste your Site Key and Secret Key, choose which forms to protect, and save. Until you add your keys, CAPTCHA does nothing and no data is sent anywhere. See the External Services section for exactly what is shared.<\/p><\/dd>\n<dt id=\"%F0%9F%93%A4%20can%20i%20export%20the%20activity%20log%3F\"><h3>\ud83d\udce4 Can I export the activity log?<\/h3><\/dt>\n<dd><p>Yes. Export the activity log to CSV directly from the <strong>Activity Log<\/strong> screen, respecting whatever filters you have applied.<\/p><\/dd>\n<dt id=\"%F0%9F%8C%8D%20does%20it%20work%20on%20wordpress%20multisite%3F\"><h3>\ud83c\udf0d Does it work on WordPress Multisite?<\/h3><\/dt>\n<dd><p>Yes. When network-activated, SentriLog creates its tables for each sub-site, and each site keeps its own independent settings and log.<\/p><\/dd>\n<dt id=\"%E2%99%BB%EF%B8%8F%20what%20happens%20when%20i%20uninstall%3F\"><h3>\u267b\ufe0f What happens when I uninstall?<\/h3><\/dt>\n<dd><p>Everything is cleaned up: all custom tables are dropped, plugin options are deleted, any temporary Magic Login users are removed, and scheduled events are cleared. Nothing is left behind.<\/p><\/dd>\n<dt id=\"%F0%9F%92%AC%20get%20support\"><h3>\ud83d\udcac Get support<\/h3><\/dt>\n<dd><p>Post in the <a href=\"https:\/\/wordpress.org\/support\/plugin\/sentrilog\/\">WordPress.org support forum<\/a>. We aim to respond within 24 hours on business days.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New: Cloudflare Turnstile is now a CAPTCHA option alongside Google reCAPTCHA \u2014 a privacy-first challenge that does not track visitors. Pick your provider under Settings \u2192 CAPTCHA and bring your own free keys.<\/li>\n<li>The reCAPTCHA settings tab is now a unified \"CAPTCHA\" tab; your existing reCAPTCHA keys and settings are preserved.<\/li>\n<li>The External Services section now documents Cloudflare Turnstile (endpoints, data sent, terms).<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: Optional Google reCAPTCHA (v3 invisible or v2 checkbox) on the login, lost-password, and registration forms, with per-form toggles and an adjustable v3 score threshold. Off by default \u2014 bring your own free Google keys.<\/li>\n<li>reCAPTCHA is the plugin's only external service and is fully disclosed in the new \"External Services\" section; it sends data to Google only when you enable it.<\/li>\n<li>New: SentriLog Pro is now available \u2014 an optional premium upgrade adding advanced 2FA &amp; passkeys, IP\/country rules, anomaly detection, alert routing, and agency tools. The free plugin stays fully functional; see SentriLog \u2192 Go Pro.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>New: Two-Factor Authentication \u2014 app-based TOTP (Google Authenticator, Authy, and any standard app) with a locally generated QR code and single-use backup codes, enabled per user from the profile screen.<\/li>\n<li>The 2FA secret is encrypted at rest (libsodium); the QR is rendered in the browser, so nothing is sent to any third party.<\/li>\n<\/ul>\n\n<h4>\ud83c\udf89 1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Limit login attempts with configurable max attempts, rolling time window, and lockout duration.<\/li>\n<li>Progressive lockout escalation for repeat offenders, tracked per IP + username.<\/li>\n<li>Full authentication activity log (logins, failures, logouts, lockouts, password events) with filtering and CSV export.<\/li>\n<li>Change Login URL \u2014 hide wp-login.php behind a custom slug with an emergency recovery link.<\/li>\n<li>Magic Login \u2014 temporary, single-use, passwordless login links that clean themselves up.<\/li>\n<li>Username enumeration protection \u2014 login error normalization, author-scan blocking, and REST API users lockdown.<\/li>\n<li>Idle session timeout with a JavaScript heartbeat.<\/li>\n<li>Configurable client IP source (direct, Cloudflare, reverse proxy, load balancer) to prevent header spoofing.<\/li>\n<li>XML-RPC system.multicall brute-force protection.<\/li>\n<li>Email alerts on repeated failures and on lockout.<\/li>\n<li>Admin dashboard with stats, a 7-day trend chart (Chart.js, bundled locally), the activity log, and the lockout manager.<\/li>\n<li>Light and dark admin theme with a one-click toggle.<\/li>\n<li>Tabbed settings: Lockout, Security, Logging, Notifications.<\/li>\n<li>WP-Cron\u2013powered log retention and expired-lockout cleanup.<\/li>\n<li>WordPress Multisite compatible.<\/li>\n<li>Makes no external requests and collects no data \u2014 everything stays in your database.<\/li>\n<li>Full internationalization support via the bundled <code>.pot<\/code> file.<\/li>\n<\/ul>","raw_excerpt":"Limit login attempts, hide your login URL, log every auth event, and get email alerts \u2014 a lightweight, privacy-first login security plugin.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/361311","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=361311"}],"author":[{"embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/rayetun"}],"wp:attachment":[{"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=361311"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=361311"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=361311"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=361311"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=361311"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=361311"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}