DCI Admin Security Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Protect WordPress login and wp-admin with IP allowlisting, custom login URLs, email OTP, rate limiting, CAPTCHA, logging and alerts.
Features
- Allow exact IPv4/IPv6 addresses and CIDR ranges.
- Accept IPv4 shorthand such as
171.61, stored as171.61.0.0/16. - Change the WordPress login URL.
- Protect the normal
wp-login.phpendpoint. - Restrict
wp-adminby IP while keepingadmin-ajax.phpavailable. - Optional Cloudflare
CF-Connecting-IPdetection. - Optional trusted
X-Forwarded-Fordetection for known reverse-proxy setups. - Optional localhost/loopback bypass for local development.
- Brute-force rate limiting and temporary lockouts.
- Email OTP verification for administrators, delivered to each administrator’s WordPress profile email address.
- Administrator-configured emergency fallback code for environments where email cannot be delivered.
- Optional Google reCAPTCHA v2, reCAPTCHA v3 or hCaptcha on the WordPress login form.
- Security event logging with an administrator viewer and configurable retention.
- Optional email and Slack alerts for repeated blocked-IP or brute-force events.
Important
Keep at least one known administrator IP in the allowlist before enabling IP protection.
Only enable Cloudflare IP detection when the site is actually behind Cloudflare. Only enable trusted X-Forwarded-For when the server is behind a trusted reverse proxy that sets that header.
On localhost, PHP commonly sees 127.0.0.1 or ::1 rather than the browser’s public VPN address. Use a publicly reachable staging site for an end-to-end VPN IP test.
The emergency fallback code is stored as a password hash and is never displayed after saving.
External Services
This plugin can optionally communicate with third-party CAPTCHA verification services when CAPTCHA is enabled:
- Google reCAPTCHA: the login page loads Google reCAPTCHA assets and sends the submitted CAPTCHA token to Google’s verification endpoint. See https://policies.google.com/privacy and https://policies.google.com/terms.
- hCaptcha: the login page loads hCaptcha assets and sends the submitted CAPTCHA token to hCaptcha’s verification endpoint. See https://www.hcaptcha.com/privacy and https://www.hcaptcha.com/terms.
The plugin does not contact these services when CAPTCHA is disabled.
IP access examples
Exact IP: 186.189.26.220
IPv4 /16 shorthand: 171.61
CIDR: 171.61.0.0/16
Email OTP
After a successful WordPress administrator password check, a six-digit OTP is generated and sent to that administrator’s WordPress profile email address.
If email delivery is unavailable, an administrator-configured emergency fallback code can be used.



