跳至内容
WordPress.org

China 简体中文

  • 主题
  • 插件
  • 新闻
    • 文档
    • 论坛
  • 关于
  • 获取 WordPress
获取 WordPress
WordPress.org

Plugin Directory

24TT Login Security and Brander

  • 提交插件
  • 我的收藏
  • 登录
  • 提交插件
  • 我的收藏
  • 登录

24TT Login Security and Brander

作者:24 Tech Time
下载
  • 详情
  • 评价
  • 安装
  • 开发进展
支持

描述

24TT Login Security and Brander is an enterprise-grade, zero-bloat security and white-labeling solution for WordPress. Designed for agencies and security-conscious site owners, it fortifies your WordPress perimeter while delivering a seamless, custom-branded login experience for your clients.

Instead of relying on heavy frameworks, this plugin uses native WordPress APIs and strictly optimized PHP to protect your site without slowing it down.

🛡️ Enterprise Perimeter Defense

  • Hide wp-login.php & /wp-admin/: Completely obfuscate your login portal. Bots and unauthenticated guests attempting to access default login routes are silently redirected to your homepage before core authentication redirects even trigger.
  • Brute Force Protection: Transient-based Limit Login Attempts. Locks out attackers for 15 minutes after 3 failed attempts, intercepting them at Priority 1 before heavy database queries execute.
  • Kill XML-RPC: Permanently disables XML-RPC to shut down massive DDoS and brute-force vectors.
  • Block User Enumeration: Prevents hackers from scraping usernames via author archives (/?author=1) and the REST API.
  • Generic Error Masking: Overwrites default login errors so attackers cannot verify if a username exists.

🎨 Agency-Grade Brander

  • Custom Login Logo: Replace the default WordPress logo with your client’s brand.
  • Custom Colors: Tailor the background and primary button colors using the native WordPress Color Picker.
  • Smart Contrast Calculator: Automatically detects if your background is light or dark (using the YIQ formula), adjusting the “Lost Password” and “Back to Site” links to guarantee 100% visual accessibility.
  • Role-Based Redirects: Automatically route administrators to the backend dashboard, while sending clients or subscribers to a custom URL (like a user portal).

屏幕截图

The Visual Branding & User Interface (UI) settings panel.
The Visual Branding & User Interface (UI) settings panel.
The Perimeter Defense & Routing configuration.
The Perimeter Defense & Routing configuration.
A fully white-labeled, secure login portal with dynamic contrast text.
A fully white-labeled, secure login portal with dynamic contrast text.

安装

  1. Upload the 24tt-login-security-and-brander directory to the /wp-content/plugins/ directory via FTP, or upload the zipped file directly through the WordPress plugins screen.
  2. Activate the plugin through the ‘Plugins’ menu in WordPress.
  3. Navigate to Settings > 24TT Security to configure your secret login slug, branding colors, and client redirects.
  4. Important: If you set a custom login slug, remember it! You will need it to log back in.

常见问题

I forgot my secret login slug and am locked out! What do I do?

Simply access your site via FTP or a File Manager. Navigate to /wp-content/plugins/ and temporarily rename the 24tt-login-security-and-brander folder to something else (e.g., disabled-24tt). This will safely deactivate the plugin, and you can log in normally via wp-login.php. Once logged in, rename the folder back, reactivate the plugin, and check your settings.

Will this slow down my website?

Absolutely not. The admin settings interface only loads in the backend, and the security rules are designed to intercept attacks at the earliest possible hook (init and authenticate), saving your server from processing heavy WordPress database queries.

评价

Excellent performance and Easy to Use

teddyug 2026 年 6 月 12 日
We tested this plugin and it performs excellently. We are using on some of our sites and plan to activate on all our sites. We loved the branding customisation.
阅读所有1条评价

贡献者及开发者

「24TT Login Security and Brander」是开源软件。 以下人员对此插件做出了贡献。

贡献者
  • 24 Tech Time
  • Johnious Tumusiime

帮助将「24TT Login Security and Brander」翻译成简体中文。

对开发感兴趣吗?

您可以浏览代码,查看SVN仓库,或通过RSS订阅开发日志。

更新日志

1.0.2

  • Minor version bump for repository resubmission.

1.0.1

  • Minor version bump for repository resubmission.

1.0.0

  • Initial Release: The fortress is sealed.

额外信息

  • 版本 1.0.2
  • 最后更新:2 月前
  • 活跃安装数量 不到10
  • WordPress 版本 5.8 或更高版本
  • 已测试的最高版本为 7.0.1
  • PHP 版本 7.4 或更高版本
  • 语言
    English (US)
  • 标签
    Brute Forcecustom loginhide loginsecurityWhite Label
  • 高级视图

评级

5 星(最高 5 星)。
  • 1 条 5 星评价 5 星 1
  • 0 条 4 星评价 4 星 0
  • 0 条 3 星评价 3 星 0
  • 0 条 2 星评价 2 星 0
  • 0 条 1 星评价 1 星 0

Your review

查看全部评论

贡献者

  • 24 Tech Time
  • Johnious Tumusiime

支持

有话要说吗?是否需要帮助?

查看支持论坛

  • 关于
  • 新闻
  • 主机
  • 隐私
  • 陈列窗
  • 主题
  • 插件
  • 区块样板
  • 学习
  • 支持
  • 开发者
  • WordPress.tv ↗︎
  • 参与
  • 活动
  • 捐赠 ↗
  • 未来五分计划
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

China 简体中文

  • 关注我们的 X(原 Twitter)账号
  • 访问我们的 Bluesky 账号
  • 关注我们的 Mastodon 账号
  • 访问我们的 Threads 账号
  • 访问我们的 Facebook 公共主页
  • 关注我们的 Instagram 账号
  • 关注我们的 LinkedIn 主页
  • 访问我们的 TikTok 账号
  • 访问我们的 YouTube 频道
  • 访问我们的 Tumblr 账号
代码如诗
The WordPress® trademark is the intellectual property of the WordPress Foundation.