Skip to content

Authlify

Free on WordPress.org · Authlify Pro from $49/yr

Hide your login, stop the bots, and never get locked out.

Authlify moves your login to an address only you know and checks that nothing gives it away. It adds brute-force lockouts, CAPTCHA, two-factor login, passkeys and a login page designer, all free. Authlify Pro requires two-factor login by role, adds passwordless and social sign-in, and alerts you to suspicious logins.

10+ active installs WordPress 6.4+ · PHP 7.4+ (passkeys need PHP 8.0+) · GPLv2

Authlify dashboard: protection checklist and this week's logins, failed attempts and lockouts
CAPTCHA providers, free
5
Cloudflare Turnstile, hCaptcha, reCAPTCHA v2 and v3, and self-hosted ALTCHA
Login page templates
12
Free, plus "Match my site". Pro adds 22 animated, video, seasonal and industry designs
Plugins you can import from
5
WPS Hide Login, Limit Login Attempts Reloaded, ASE, and LoginPress or Colorlib designs
Price of the free plugin
$0
Two-factor login, passkeys and the login designer included, with no time limit

See it in action

The free plugin, screen by screen

Every screen here is in the free plugin on WordPress.org.

Login URL settings with a passed Leak Check
A hidden login that stays hidden. Move the login to your own address; Leak Check tests the known routes that could give it away.
Two-factor setup on a user profile with an authenticator QR code and passkeys
Two-factor login and passkeys. Authenticator apps, passkeys and backup codes, set up by each user on their profile.
Branded passkey sign-in and two-factor screens
A second step that matches your design. Sign in with a passkey, and a two-factor screen styled by the login designer.
Login page designer with templates and a live preview
Design your login page visually. Live preview on desktop, tablet and phone; start from a template or Match my site.
Three free login page templates
Login pages in one click. Three of the 12 free templates: Glass over photo, Split image right and Soft gradient.
Import settings from other login plugins
Switch from your old login plugin. Copy settings from WPS Hide Login, Limit Login Attempts Reloaded and others in one click.

Features

A complete login security plugin, free

The protections most sites need, and a login page in your own design, are in the free plugin. Brute-force lockouts and the activity log are on from the start; everything else waits until you switch it on.

A custom login URL

Move the login to an address such as /my-door. Visitors who open wp-login.php or /wp-admin/ get your theme's "page not found" page, an "access denied" message or a redirect. It works in PHP, so it runs on Apache, Nginx and managed hosts with no .htaccess edits.

Leak Check

Visits your site as a logged-out visitor and tests the known routes that give a hidden login away, such as /wp-admin/, /login, the Customizer, privacy emails and encoded paths. It shows what passed and how to fix anything that did not, and runs again by itself every week and after the login URL changes.

Brute-force lockouts

Lockouts per IP address and per network, longer for repeat offenders. An account under attack asks for a CAPTCHA instead of locking the real owner out. It also covers XML-RPC, the REST API and application passwords. Allow and block lists, and an "email me an unlock link" option.

The right IP address

Correct visitor addresses behind Cloudflare or your own proxy, and faked forwarding headers are ignored, so a lockout lands on the attacker and not on someone else.

CAPTCHA your way

Turnstile, hCaptcha, reCAPTCHA v2 or v3, or ALTCHA with no third party at all, plus an invisible honeypot. On login, registration, lost password, comments and WooCommerce forms. Show it always or only after failed logins, and try it in test mode first.

Two-factor login and passkeys

Authenticator apps, one-time backup codes and passkeys (Face ID, Touch ID, Windows Hello or a security key), with a "Sign in with a passkey" button. The second step uses your login page design. People who lose their phone can email themselves a recovery link, and admins can reset them.

Login page designer

A visual designer with a live preview on desktop, tablet and phone and 12 templates. "Match my site" builds a design from your theme's colours, font and logo. Login, lost password, reset, registration, two-factor and lockout screens are all styled.

Hardening

Switch off XML-RPC or its multi-password requests, hide usernames from the REST API and ?author= scans, limit application passwords, use generic login errors, or make the whole site private.

Breached-password check

Refuses passwords found in known data breaches when they are set or reset. Only the first five characters of a hash are sent to Have I Been Pwned, never the password.

An activity log you can trust

Logins, failed attempts, lockouts and changes, with IP address, and country when your site is behind Cloudflare. Stored only on your site, with filters, CSV export, a retention period, IP anonymisation and the WordPress privacy tools.

Redirects by role

Send people to the right page after they log in or out, with one address for everyone or a rule for each role.

Never locked out

A new login URL works next to the old one until you confirm it, and it is emailed to you when it changes. If you still lose it, one line in wp-config.php or a WP-CLI command brings back wp-login.php.

Pro

For sites with staff, customers or clients: rules instead of requests, more ways to sign in, and a warning when something looks wrong.

Two-factor policies: required roles, grace period, email codes and trusted devices

Pro

Require two-factor login by role

Choose the roles that must use two-factor login and give them a grace period of a few sign-ins or days. After it, a short setup wizard runs right after the password. Email codes for people without a smartphone, trusted devices, passkey-only roles and a coverage report per role.

Social login providers: Google, Microsoft, Apple, GitHub and OpenID Connect

Pro

Social login and single sign-on

Google, Microsoft, Apple, GitHub and any OpenID Connect provider, such as Okta, Auth0, Keycloak or Entra ID. Limit a provider to your company's email domains. Administrator accounts are blocked by default, and two-factor login and lockouts still apply.

Passwordless settings: email login links and sign-in codes by role

Pro

Passwordless and temporary access

Let chosen roles sign in with an emailed link or a 6-digit code. Links open a "Log me in" button, so email scanners cannot use them up. Give support staff or a client a temporary login with a role, an expiry and a number of uses; when it ends, the account is deleted or disabled and its sessions end.

Login alerts for users and site admins

Pro

Alerts when something looks wrong

Email people after a login from a new device or country, with a "This wasn't me" link that ends every session and forces a new password. Admins hear about new administrators, application passwords, two-factor turned off and failed-login spikes, by email, Slack, Discord, Telegram, Microsoft Teams or a signed webhook.

Access rules: login by country, login hours and a honeypot login URL

Pro

Login by country, hours and a honeypot

Allow or refuse logins from chosen countries using a country database stored on your own server, limit a role to set days and hours, and ban IP addresses that keep guessing wp-login.php or /login. Your own recent logins are never banned.

Also in Authlify Pro

22 premium login designs

Animated, video, seasonal and industry templates (paused for reduced motion), branded emails that match the login page, login and registration blocks, a popup login, a Site Editor login page and a WooCommerce My Account skin.

Session control

Maximum session length and devices at the same time per role, idle logout with a warning, and "log out everywhere" on the profile.

Password policy

Length, character rules, no reuse and expiry for chosen roles, plus a breached-password check at login that forces a reset.

Sudo mode

Ask people to confirm it is them before plugin, theme, user and security changes if they signed in a while ago.

WooCommerce

The second step inside My Account, and a Security tab where customers manage two-factor login, passkeys, devices and connected accounts. A shortcode puts the same page on any site.

Insights and scheduled exports

A country for every log entry from a database on your own server, failed attempts by country, top IP addresses and targeted usernames, a weekly digest and a weekly or monthly CSV of the log by email.

Agency and multisite

White-label with your own plugin name, client handoff so client admins cannot change your settings, per-site overrides with locks on multisite, and design sync between sites.

REST API and WP-CLI

/wp-json/authlify-pro/v1/ for settings, the activity log (JSON or CSV), lockouts and the design, and wp authlify-pro settings and sites commands.

Compare

Free or Pro?

Start free. Upgrade when you need more: nothing you set up is lost.

Authlify: features in the free and Pro versions
Feature Authlify (free) Authlify Pro
Login URL
Custom login URL, wp-login.php and wp-admin hidden (404, access denied or redirect) Included Included
Leak Check, confirm-before-apply and page-cache safety Included Included
Recovery by email, wp-config.php constant or WP-CLI Included Included
Honeypot login URL that bans IPs guessing the old addresses Not included Included
Brute force and hardening
Lockouts per IP, network and targeted account, escalating, email unlock link Included Included
Cloudflare and proxy-safe IP detection, allow and block lists Included Included
Lockouts also cover XML-RPC, the REST API and application passwords Included Included
XML-RPC, username discovery and application-password controls, private site Included Included
Login by country (local database) and login hours per role Not included Included
CAPTCHA
Turnstile, hCaptcha, reCAPTCHA v2/v3, ALTCHA and honeypot Included Included
Core, comment and WooCommerce forms, after failed logins, test mode Included Included
Two-factor login
Authenticator apps, backup codes and passkeys (opt-in per user) Included Included
Two-factor step in your login design, recovery link by email, admin reset Included Included
Required by role with grace period and setup wizard, passkey-only roles Not included Included
Email codes, trusted devices and a coverage report Not included Included
Sudo mode and two-factor inside WooCommerce My Account Not included Included
Ways to sign in
Passwordless login links and sign-in codes by role Not included Included
Temporary access links for support staff and clients Not included Included
Google, Microsoft, Apple, GitHub and OpenID Connect login Not included Included
Passwords and sessions
Breached-password check when a password is set or reset Included Included
Password policy, expiry and breached-password check at login Not included Included
Session length, device limits, idle logout, log out everywhere Not included Included
Design
Visual designer, 12 templates, "Match my site", every login screen Included Included
22 premium templates with animated and video backgrounds Not included Included
Branded emails, login blocks, popup login, Site Editor login page, WooCommerce skin Not included Included
Activity and alerts
Local activity log, CSV export, retention, IP anonymisation, privacy tools Included Included
Role redirects after login and logout Included Included
New-device and new-country alerts with "This wasn't me" Not included Included
Admin alerts by email, Slack, Discord, Telegram, Teams or webhook Not included Included
Security audit events, insights, weekly digest, scheduled CSV Not included Included
Agencies and developers
Importers, settings export and import, Site Health checks, WP-CLI Included Included
White-label, client handoff, network overrides and locks, design sync Not included Included
REST API and bulk WP-CLI commands Not included Included
Support Community forum Email (priority on Agency)

Pricing

Free forever. Pro from $49 a year, or $129 once.

Every plan includes every Pro feature. Plans differ only in the number of sites and the speed of support.

Free

Unlimited sites

$0

Free forever

The complete login plugin on WordPress.org: custom login URL, lockouts, CAPTCHA, two-factor login, passkeys, the designer and the activity log.

Download free

Personal

1 website

$49/year

Renews yearly · cancel any time

Every Pro feature for one website.

  • Every Pro feature
  • Two-factor rules by role
  • Passwordless and temporary access
  • Social login and OpenID Connect
  • Login alerts to email, Slack and more
  • Sessions, country and hours rules
  • 22 premium login designs
  • White-label and multisite tools
  • Email support
Buy Personal
Most popular

Plus

5 websites

$99/year

Renews yearly · cancel any time

Best value for a business or store with a few sites.

  • Every Pro feature
  • Two-factor rules by role
  • Passwordless and temporary access
  • Social login and OpenID Connect
  • Login alerts to email, Slack and more
  • Sessions, country and hours rules
  • 22 premium login designs
  • White-label and multisite tools
  • Email support
Buy Plus

Agency

25 websites

$149/year

Renews yearly · cancel any time

For freelancers, agencies and client sites.

  • Every Pro feature
  • Two-factor rules by role
  • Passwordless and temporary access
  • Social login and OpenID Connect
  • Login alerts to email, Slack and more
  • Sessions, country and hours rules
  • 22 premium login designs
  • White-label and multisite tools
  • Priority support
Buy Agency
  • 14-day money-back guarantee
  • If your licence expires, Pro keeps working (no updates or support)
  • Upgrade any time: pay only the difference
  • More than 25 sites? Contact us

Prices in USD. Sold by MantraBrain. Refund policy · Terms

FAQ

Questions, answered

Do I need the free plugin to use Pro?

Yes. Authlify on WordPress.org is the base and stays free; Authlify Pro is a separate plugin that adds its features to it.

Are two-factor login and passkeys really free?

Yes. Any user can turn on an authenticator app, backup codes or a passkey from their profile. Pro adds rules: requiring it for chosen roles, email codes, trusted devices and reports. Passkeys need PHP 8.0 or newer and https.

I forgot my login URL. How do I get in?

Check your email: Authlify sends the address to the site admin email whenever it changes. You can also add define( 'AUTHLIFY_DISABLE_HIDE', true ); to wp-config.php, or run wp authlify url get with WP-CLI. If you are locked out after failed attempts, use the email unlock link or wp authlify unlock --all.

Can I switch from another login plugin?

Yes. Authlify imports the login URL from WPS Hide Login, attempts, lockout length and allow and block lists from Limit Login Attempts Reloaded, the login URL from Admin and Site Enhancements, and login page designs from LoginPress and Colorlib Login Customizer. Deactivate the other plugin afterwards.

Does it work with WooCommerce, caching and Cloudflare?

Yes. WooCommerce My Account logins get the same lockouts and CAPTCHA. The login page is never cached, and WP Rocket, LiteSpeed, SiteGround and Breeze exclusions are added automatically. Choose "Through Cloudflare" or "Through my own proxy" so lockouts use the real visitor address.

Is Authlify GDPR friendly?

The activity log stays on your site, is deleted after the retention period you choose, can anonymise IP addresses, and works with the WordPress personal-data export and erase tools. ALTCHA and the honeypot need no third-party service. Pro's country database is downloaded to your server, so lookups never leave it.

Does it work on multisite?

Yes. Network-activated, one set of settings, one login URL and one activity log cover the network. Pro adds per-site overrides with locks, and one Pro licence covers the whole network.

What happens when my Pro licence ends?

Pro keeps working, including two-factor rules, alerts and access rules. You stop receiving one-click updates and support until you renew.

Can I upgrade later?

Yes. Move from Personal to Plus or Agency, or from a yearly plan to lifetime, and pay only the difference.

Is there a money-back guarantee?

Yes. Every Authlify Pro purchase is covered by a 14-day money-back guarantee under the MantraBrain refund policy.

More help: WordPress.org page · Support forum · Reviews · Contact us

Put a proper lock on your WordPress login

Install the free plugin, choose a login address and turn on the protections you want. Add Pro when you need two-factor rules for your team, passwordless or social sign-in, or login alerts: your settings carry over untouched.

14-day money-back guarantee on every Pro plan.