SeCWurity WP Login icon

SeCWurity WP Login

SeCWurity WP Login is a WordPress plugin with the following stats:

  • #3,460 Global Rank
  • 10+ active installs
  • 5/5 1 ratings
  • Since 2014 12 years active

PF Score (About PF Scores)

PF Score is not a quality guarantee. It is a ranking based on available public signals.

Bronze52.5
Platinum
Gold
Silver
Bronze
Low

Score Breakdown

16.7
Popularity 40% 10+ active installs
61.9
Reputation 35% 5★ from 1 ratings
96.7
Freshness 25% Updated 1 months ago

No vulnerability history

Download Trends

Loading download data…

Vulnerabilities

No known vulnerabilities

This plugin has no records in the Wordfence Intelligence vulnerability database.

About SeCWurity WP Login

SeCWurity WP Login protects your login page against different attack types...

Is there any doubt the security of your site? Do you think that your computer has keylogger virus? Do you think someone has stolen your password? None of this is important when you get this plugin 🙂
SeCWurity WP Login is coded for your sites against brute force attacks, keylogger viruses and more..

Features:

  • Security code protection: In addition to your WordPress password, the login form asks for randomly selected characters of a secret security code. Because only a few random characters are asked on each attempt, a keylogger cannot capture the whole code.
  • Login page URL protection: Your login page is only reachable with a secret URL parameter (for example wp-login.php?param=value). Visitors without the correct parameter are redirected to the home page.

Screenshots

Plugin Settings

Plugin Settings

Password Settings

Password Settings

Security with URL Settings

Security with URL Settings

Example of login page with password security

Example of login page with password security

Another example of login page with password security

Another example of login page with password security

Frequently Asked Questions

I forgot my security code. What should I do?

You can change it by editing the SCWL_sifre option in the database, or disable the plugin by renaming its folder via FTP.

I enabled URL protection. What is my new login address?

It is shown on the plugin settings page, in the form https://yoursite.com/wp-login.php?param=value. Save it somewhere safe.

Ratings & Reviews

5
1 ratings
5★
1
4★
0
3★
0
2★
0
1★
0

Recent Reviews

Loading reviews…

View all reviews on WordPress.org (opens in a new tab)

Changelog

3.0

  • Security: fixed an information disclosure where the secret login URL was revealed to anyone requesting the login page with the site admin e-mail address as a parameter.
  • Security: the characters asked on the login form are now bound to a signed, expiring token, so an attacker can no longer choose which character positions to answer.
  • Security: settings form is now protected with a nonce and capability checks; all inputs are sanitized and all outputs are escaped.
  • Security: character comparison now uses timing-safe checks.
  • Fixed URL protection running after output was already sent; it now runs on login_init and uses a proper redirect instead of a broken 404 page.
  • Fixed login form submissions being blocked by URL protection; the secret parameter is now preserved during form submission.
  • Multibyte (UTF-8) security codes are now handled correctly.
  • Removed the bundled jQuery copy; scripts are now enqueued the WordPress way and the login script no longer needs jQuery at all.
  • Removed promotional admin pages and external hotlinked images; the plugin now adds a single page under Settings.
  • Plugin settings are no longer deleted on deactivation; they are removed only when the plugin is uninstalled.
  • Admin interface is now in English and fully translatable (Turkish translation can be provided via language packs).
  • Tested up to WordPress 7.0 and PHP 8.4.

2.1

Performance is increased by reducing the number of files.

2.0

New features were added.
Interface design was updated.

1.0

Some bugs were fixed.

Alternatives to SeCWurity WP Login

Other WordPress plugins serving a similar purpose, ranked by relevance and PF Score.

Platinum89.3
WP Ghost (Hide My WP Ghost) – Security & Firewall icon

WP Ghost (Hide My WP Ghost)

Hides WordPress paths and applies firewall protection, brute force blocking, and passkey login security.

★ 4.5/5·100K+ installs·Updated 28 Jul 2026
Platinum98.3
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention icon

Limit Login Attempts Security

Defends WordPress logins with brute force protection, two-factor authentication, and IP blocking.

★ 4.8/5·1.0M+ installs·Updated 8 Jul 2026
Platinum98.1
Loginizer icon

Loginizer

Protects WordPress login pages from brute force attacks through automated threat detection and blocking.

★ 4.8/5·1.0M+ installs·Updated 3 Aug 2026
Platinum90.0
WPS Limit Login icon

WPS Limit Login

Throttles login attempts by IP address to reduce brute force attack risk on WordPress sites.

★ 4.9/5·100K+ installs·Updated 24 Jun 2025
Platinum85.7
WP Hide & Security Enhancer icon

WP Hide & Security Enhancer

Obscures WordPress traces while adding 2FA, firewall rules, and security headers to harden site access.

★ 4.3/5·50K+ installs·Updated 13 Aug 2026
Platinum98.7
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) icon

Really Simple Security

Hardens WordPress security with two-factor authentication, login protection, and vulnerability detection across 3 million active sites.

★ 4.9/5·3.0M+ installs·Updated 27 Jul 2026
Platinum98.5
WPS Hide Login icon

WPS Hide Login

Redirect WordPress login from wp-login.php to a custom URL you specify.

★ 4.8/5·2.0M+ installs·Updated 13 Aug 2026
Platinum97.8
Wordfence Security – Firewall, Malware Scan, and Login Security icon

Wordfence Security

Firewall, malware scanner, and two-factor authentication for WordPress site security.

★ 4.7/5·5.0M+ installs·Updated 10 Aug 2026