NibbleSecure – Hide Login, Limit Login Attempts & Brute Force Shield Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
NibbleSecure protects your WordPress login page from bots, scanners, and brute force attacks. It hides your default wp-login.php page behind a secret URL, so automated login attacks never even find your real login form.
On top of hiding your login page, NibbleSecure limits login attempts and locks out an IP address once it crosses your configured threshold. The lockout period grows for repeat offenders. It then sends you an instant email alert when that happens. No external service, API key, or subscription is required.
NibbleSecure runs natively on WordPress’s own database. It’s lightweight, fast, and 100% free.
Looking for Two-Factor Authentication (2FA)? Two-Factor Authentication (2FA/TOTP) compatible with Google Authenticator, Authy, Microsoft Authenticator, and 1Password is available through the separate NibbleSecure PRO add-on, along with heuristic malware scanning, file integrity monitoring, self-healing plugin protection, session hijacking control, Application-Layer (L7) DDoS protection, advanced .htaccess server hardening, an automated 404 scanner with IP auto-ban, manual IP/country blocking, scheduled automatic backups with one-click restore, and a math CAPTCHA on the login and lost-password forms. These PRO features are not included in this free version – see “Available in PRO Version” below for details.
Free Version Capabilities
- Hide Login (Secret Login URL)
- Limit Login Attempts & Brute Force Protection
- Configurable Lockout Thresholds with Escalating Repeat-Offense Penalties
- Email Alerts & Secret URL Backup
Available in PRO Version
The following features require the separate, self-hosted NibbleSecure PRO add-on (https://mvpplugins.com/nibblesecure/) and are not part of this free plugin:
- Two-Factor Authentication (2FA/TOTP) – Adds a second verification step at login using Google Authenticator, Authy, Microsoft Authenticator, 1Password, or other standard authenticator apps, with emergency backup codes and secure email-based recovery if you lose your device.
- Heuristic Malware Detection & File Integrity Monitoring – Scans plugin and core files every hour against SHA-256 baselines to catch unauthorized changes, injected code, and malware.
- Self-Healing Plugin Protection – Automatically restores NibbleSecure’s own core files if an attacker deletes or tampers with them.
- Session Hijacking Control – Detects unauthorized concurrent device logins and lets you instantly log out every other active session.
- Application-Layer (L7) DDoS & Flood Protection – Rate-limits and blocks malicious traffic spikes and botnet floods before they reach your server.
- Scheduled Automatic WordPress Backups & Restore – Creates scheduled restore points for your database, files, and configuration, with one-click recovery.
- Advanced Server Hardening (.htaccess Tweaks) – XML-RPC and pingback toggles, hidden-file blocking (.git, .env), bad-bot and malicious query-string blocking, and other server-level hardening options.
- Automated 404 Scanner & IP Auto-Ban – Detects IPs that repeatedly request non-existent pages within a short time window (a common sign of vulnerability scanning) and automatically bans them for a configurable duration, independent of the login-attempt counter.
- Manual IP, IP Range & Country Blocking – Instantly allow or block specific IP addresses, IP ranges, or entire countries from accessing your site, from a dedicated management panel.
- Math CAPTCHA on Login & Lost Password Forms – Adds a simple math challenge to the login and password-reset forms to stop automated bot submissions before they reach the brute-force checks.
Screenshots
NibbleSecure dashboard overview with secret login URL settings.
Brute force & limit login attempts settings with attempt limits and lockout duration.
PRO feature preview tabs inside the dashboard.
