Smart Protector – login protection, 2FA, and an activity log

The plugin hardens how people get into WordPress: it hides the login screen behind your own address, enforces two-factor authentication, and puts a hard server-side checkpoint in front of the dashboard. The blocks run server-side, so they stop automated attempts too.

Smart Protector settings panel – 2FA, login attempt limits, and change control

What Smart Protector does

Nine modules that lock down access to the dashboard and give you visibility into what’s happening on the site.

Hidden login address

Move the login screen to your own address; /wp-login.php then returns a 404 or redirects wherever you choose. Password reset links keep working.

2FA (TOTP) authentication

TOTP codes compliant with RFC 6238, enforced per user or enabled voluntarily, with a ±1 step window and protection against code reuse.

Hard dashboard gate

Until a session passes verification, the dashboard, admin-ajax, and the REST API refuse to serve the account. The protection also covers XML-RPC and application passwords.

Attempt limiting

Separate counters for passwords and codes, per IP address and per username, with a countdown shown on the login screen. Behind a proxy that hides the address, per-IP counting turns itself off.

Password rotation

Force a new password every set number of days. The change is caught at the checkpoint, before the 2FA step.

Change control

Block creating, editing, and deleting accounts, switching and deleting themes, and installing, activating, and updating plugins – even for an administrator.

File monitor

An email alert when a new file appears in the WordPress root or in folders you specify – including hidden ones. Alerts are grouped, at most one per hour.

Activity log

Who logged in, who changed a password, which posts and pages were created or changed, which plugins were activated. With filters and CSV export – absorbed from the User Activity Tracker plugin.

Import and export

Move the configuration between sites as JSON, with or without secrets. Imported values are re-validated.

Lock the door, and keep visibility

Smart Protector first makes it harder for unauthorized users to get in, then shows you what actually happened on the site.

Login hardening

Layers that stop an attack before it reaches the dashboard.

  • A hidden login address and a hard 2FA gate
  • Attempt limits per IP and per user
  • Blocks on account, theme, and plugin changes

Visibility and audit

An event log that explains what happened and when.

  • Security log: logins, lockouts, 2FA
  • Activity log with filters and CSV export
  • File monitor with email alerts

Screenshots

Two-factor login, a hidden address, and a log – Smart Protector in the WordPress dashboard.

Lock down access to the dashboard

Hide the login, enforce 2FA, and keep a full event log. Contact us and we’ll help you roll out the protection without risking a lockout.