Authlify
Free on WordPress.org · Authlify Pro from $49/yr
Hide your login, stop the bots, and never get locked out.
Authlify moves your login to an address only you know and checks that nothing gives it away. It adds brute-force lockouts, CAPTCHA, two-factor login, passkeys and a login page designer, all free. Authlify Pro requires two-factor login by role, adds passwordless and social sign-in, and alerts you to suspicious logins.
10+ active installs WordPress 6.4+ · PHP 7.4+ (passkeys need PHP 8.0+) · GPLv2
- CAPTCHA providers, free
- 5
- Cloudflare Turnstile, hCaptcha, reCAPTCHA v2 and v3, and self-hosted ALTCHA
- Login page templates
- 12
- Free, plus "Match my site". Pro adds 22 animated, video, seasonal and industry designs
- Plugins you can import from
- 5
- WPS Hide Login, Limit Login Attempts Reloaded, ASE, and LoginPress or Colorlib designs
- Price of the free plugin
- $0
- Two-factor login, passkeys and the login designer included, with no time limit
See it in action
The free plugin, screen by screen
Every screen here is in the free plugin on WordPress.org.
Features
A complete login security plugin, free
The protections most sites need, and a login page in your own design, are in the free plugin. Brute-force lockouts and the activity log are on from the start; everything else waits until you switch it on.
A custom login URL
Move the login to an address such as /my-door. Visitors who open wp-login.php or /wp-admin/ get your theme's "page not found" page, an "access denied" message or a redirect. It works in PHP, so it runs on Apache, Nginx and managed hosts with no .htaccess edits.
Leak Check
Visits your site as a logged-out visitor and tests the known routes that give a hidden login away, such as /wp-admin/, /login, the Customizer, privacy emails and encoded paths. It shows what passed and how to fix anything that did not, and runs again by itself every week and after the login URL changes.
Brute-force lockouts
Lockouts per IP address and per network, longer for repeat offenders. An account under attack asks for a CAPTCHA instead of locking the real owner out. It also covers XML-RPC, the REST API and application passwords. Allow and block lists, and an "email me an unlock link" option.
The right IP address
Correct visitor addresses behind Cloudflare or your own proxy, and faked forwarding headers are ignored, so a lockout lands on the attacker and not on someone else.
CAPTCHA your way
Turnstile, hCaptcha, reCAPTCHA v2 or v3, or ALTCHA with no third party at all, plus an invisible honeypot. On login, registration, lost password, comments and WooCommerce forms. Show it always or only after failed logins, and try it in test mode first.
Two-factor login and passkeys
Authenticator apps, one-time backup codes and passkeys (Face ID, Touch ID, Windows Hello or a security key), with a "Sign in with a passkey" button. The second step uses your login page design. People who lose their phone can email themselves a recovery link, and admins can reset them.
Login page designer
A visual designer with a live preview on desktop, tablet and phone and 12 templates. "Match my site" builds a design from your theme's colours, font and logo. Login, lost password, reset, registration, two-factor and lockout screens are all styled.
Hardening
Switch off XML-RPC or its multi-password requests, hide usernames from the REST API and ?author= scans, limit application passwords, use generic login errors, or make the whole site private.
Breached-password check
Refuses passwords found in known data breaches when they are set or reset. Only the first five characters of a hash are sent to Have I Been Pwned, never the password.
An activity log you can trust
Logins, failed attempts, lockouts and changes, with IP address, and country when your site is behind Cloudflare. Stored only on your site, with filters, CSV export, a retention period, IP anonymisation and the WordPress privacy tools.
Redirects by role
Send people to the right page after they log in or out, with one address for everyone or a rule for each role.
Never locked out
A new login URL works next to the old one until you confirm it, and it is emailed to you when it changes. If you still lose it, one line in wp-config.php or a WP-CLI command brings back wp-login.php.
Pro
What Authlify Pro adds
For sites with staff, customers or clients: rules instead of requests, more ways to sign in, and a warning when something looks wrong.
Pro
Require two-factor login by role
Choose the roles that must use two-factor login and give them a grace period of a few sign-ins or days. After it, a short setup wizard runs right after the password. Email codes for people without a smartphone, trusted devices, passkey-only roles and a coverage report per role.
Pro
Social login and single sign-on
Google, Microsoft, Apple, GitHub and any OpenID Connect provider, such as Okta, Auth0, Keycloak or Entra ID. Limit a provider to your company's email domains. Administrator accounts are blocked by default, and two-factor login and lockouts still apply.
Pro
Passwordless and temporary access
Let chosen roles sign in with an emailed link or a 6-digit code. Links open a "Log me in" button, so email scanners cannot use them up. Give support staff or a client a temporary login with a role, an expiry and a number of uses; when it ends, the account is deleted or disabled and its sessions end.
Pro
Alerts when something looks wrong
Email people after a login from a new device or country, with a "This wasn't me" link that ends every session and forces a new password. Admins hear about new administrators, application passwords, two-factor turned off and failed-login spikes, by email, Slack, Discord, Telegram, Microsoft Teams or a signed webhook.
Pro
Login by country, hours and a honeypot
Allow or refuse logins from chosen countries using a country database stored on your own server, limit a role to set days and hours, and ban IP addresses that keep guessing wp-login.php or /login. Your own recent logins are never banned.
Also in Authlify Pro
22 premium login designs
Animated, video, seasonal and industry templates (paused for reduced motion), branded emails that match the login page, login and registration blocks, a popup login, a Site Editor login page and a WooCommerce My Account skin.
Session control
Maximum session length and devices at the same time per role, idle logout with a warning, and "log out everywhere" on the profile.
Password policy
Length, character rules, no reuse and expiry for chosen roles, plus a breached-password check at login that forces a reset.
Sudo mode
Ask people to confirm it is them before plugin, theme, user and security changes if they signed in a while ago.
WooCommerce
The second step inside My Account, and a Security tab where customers manage two-factor login, passkeys, devices and connected accounts. A shortcode puts the same page on any site.
Insights and scheduled exports
A country for every log entry from a database on your own server, failed attempts by country, top IP addresses and targeted usernames, a weekly digest and a weekly or monthly CSV of the log by email.
Agency and multisite
White-label with your own plugin name, client handoff so client admins cannot change your settings, per-site overrides with locks on multisite, and design sync between sites.
REST API and WP-CLI
/wp-json/authlify-pro/v1/ for settings, the activity log (JSON or CSV), lockouts and the design, and wp authlify-pro settings and sites commands.
Compare
Free or Pro?
Start free. Upgrade when you need more: nothing you set up is lost.
| Feature | Authlify (free) | Authlify Pro |
|---|---|---|
| Login URL | ||
| Custom login URL, wp-login.php and wp-admin hidden (404, access denied or redirect) | Included | Included |
| Leak Check, confirm-before-apply and page-cache safety | Included | Included |
| Recovery by email, wp-config.php constant or WP-CLI | Included | Included |
| Honeypot login URL that bans IPs guessing the old addresses | Not included | Included |
| Brute force and hardening | ||
| Lockouts per IP, network and targeted account, escalating, email unlock link | Included | Included |
| Cloudflare and proxy-safe IP detection, allow and block lists | Included | Included |
| Lockouts also cover XML-RPC, the REST API and application passwords | Included | Included |
| XML-RPC, username discovery and application-password controls, private site | Included | Included |
| Login by country (local database) and login hours per role | Not included | Included |
| CAPTCHA | ||
| Turnstile, hCaptcha, reCAPTCHA v2/v3, ALTCHA and honeypot | Included | Included |
| Core, comment and WooCommerce forms, after failed logins, test mode | Included | Included |
| Two-factor login | ||
| Authenticator apps, backup codes and passkeys (opt-in per user) | Included | Included |
| Two-factor step in your login design, recovery link by email, admin reset | Included | Included |
| Required by role with grace period and setup wizard, passkey-only roles | Not included | Included |
| Email codes, trusted devices and a coverage report | Not included | Included |
| Sudo mode and two-factor inside WooCommerce My Account | Not included | Included |
| Ways to sign in | ||
| Passwordless login links and sign-in codes by role | Not included | Included |
| Temporary access links for support staff and clients | Not included | Included |
| Google, Microsoft, Apple, GitHub and OpenID Connect login | Not included | Included |
| Passwords and sessions | ||
| Breached-password check when a password is set or reset | Included | Included |
| Password policy, expiry and breached-password check at login | Not included | Included |
| Session length, device limits, idle logout, log out everywhere | Not included | Included |
| Design | ||
| Visual designer, 12 templates, "Match my site", every login screen | Included | Included |
| 22 premium templates with animated and video backgrounds | Not included | Included |
| Branded emails, login blocks, popup login, Site Editor login page, WooCommerce skin | Not included | Included |
| Activity and alerts | ||
| Local activity log, CSV export, retention, IP anonymisation, privacy tools | Included | Included |
| Role redirects after login and logout | Included | Included |
| New-device and new-country alerts with "This wasn't me" | Not included | Included |
| Admin alerts by email, Slack, Discord, Telegram, Teams or webhook | Not included | Included |
| Security audit events, insights, weekly digest, scheduled CSV | Not included | Included |
| Agencies and developers | ||
| Importers, settings export and import, Site Health checks, WP-CLI | Included | Included |
| White-label, client handoff, network overrides and locks, design sync | Not included | Included |
| REST API and bulk WP-CLI commands | Not included | Included |
| Support | Community forum | Email (priority on Agency) |
Pricing
Free forever. Pro from $49 a year, or $129 once.
Every plan includes every Pro feature. Plans differ only in the number of sites and the speed of support.
Free
Unlimited sites
$0
Free forever
The complete login plugin on WordPress.org: custom login URL, lockouts, CAPTCHA, two-factor login, passkeys, the designer and the activity log.
Download freePersonal
1 website
$49/year
Renews yearly · cancel any time
Every Pro feature for one website.
- Every Pro feature
- Two-factor rules by role
- Passwordless and temporary access
- Social login and OpenID Connect
- Login alerts to email, Slack and more
- Sessions, country and hours rules
- 22 premium login designs
- White-label and multisite tools
- Email support
Plus
5 websites
$99/year
Renews yearly · cancel any time
Best value for a business or store with a few sites.
- Every Pro feature
- Two-factor rules by role
- Passwordless and temporary access
- Social login and OpenID Connect
- Login alerts to email, Slack and more
- Sessions, country and hours rules
- 22 premium login designs
- White-label and multisite tools
- Email support
Agency
25 websites
$149/year
Renews yearly · cancel any time
For freelancers, agencies and client sites.
- Every Pro feature
- Two-factor rules by role
- Passwordless and temporary access
- Social login and OpenID Connect
- Login alerts to email, Slack and more
- Sessions, country and hours rules
- 22 premium login designs
- White-label and multisite tools
- Priority support
- 14-day money-back guarantee
- If your licence expires, Pro keeps working (no updates or support)
- Upgrade any time: pay only the difference
- More than 25 sites? Contact us
Prices in USD. Sold by MantraBrain. Refund policy · Terms
FAQ
Questions, answered
Do I need the free plugin to use Pro?
Yes. Authlify on WordPress.org is the base and stays free; Authlify Pro is a separate plugin that adds its features to it.
Are two-factor login and passkeys really free?
Yes. Any user can turn on an authenticator app, backup codes or a passkey from their profile. Pro adds rules: requiring it for chosen roles, email codes, trusted devices and reports. Passkeys need PHP 8.0 or newer and https.
I forgot my login URL. How do I get in?
Check your email: Authlify sends the address to the site admin email whenever it changes. You can also add define( 'AUTHLIFY_DISABLE_HIDE', true ); to wp-config.php, or run wp authlify url get with WP-CLI. If you are locked out after failed attempts, use the email unlock link or wp authlify unlock --all.
Can I switch from another login plugin?
Yes. Authlify imports the login URL from WPS Hide Login, attempts, lockout length and allow and block lists from Limit Login Attempts Reloaded, the login URL from Admin and Site Enhancements, and login page designs from LoginPress and Colorlib Login Customizer. Deactivate the other plugin afterwards.
Does it work with WooCommerce, caching and Cloudflare?
Yes. WooCommerce My Account logins get the same lockouts and CAPTCHA. The login page is never cached, and WP Rocket, LiteSpeed, SiteGround and Breeze exclusions are added automatically. Choose "Through Cloudflare" or "Through my own proxy" so lockouts use the real visitor address.
Is Authlify GDPR friendly?
The activity log stays on your site, is deleted after the retention period you choose, can anonymise IP addresses, and works with the WordPress personal-data export and erase tools. ALTCHA and the honeypot need no third-party service. Pro's country database is downloaded to your server, so lookups never leave it.
Does it work on multisite?
Yes. Network-activated, one set of settings, one login URL and one activity log cover the network. Pro adds per-site overrides with locks, and one Pro licence covers the whole network.
What happens when my Pro licence ends?
Pro keeps working, including two-factor rules, alerts and access rules. You stop receiving one-click updates and support until you renew.
Can I upgrade later?
Yes. Move from Personal to Plus or Agency, or from a yearly plan to lifetime, and pay only the difference.
Is there a money-back guarantee?
Yes. Every Authlify Pro purchase is covered by a 14-day money-back guarantee under the MantraBrain refund policy.
More help: WordPress.org page · Support forum · Reviews · Contact us
Put a proper lock on your WordPress login
Install the free plugin, choose a login address and turn on the protections you want. Add Pro when you need two-factor rules for your team, passwordless or social sign-in, or login alerts: your settings carry over untouched.
14-day money-back guarantee on every Pro plan.
More from MatrixAddons
All products →
Easy Invoice
Plugin · Invoicing & billing
Invoices, quotes, PDF documents and online payments inside WordPress. Pro adds Stripe and five more card gateways, plus 26 addons: recurring billing, a client portal, e-invoicing and team roles.
AdFlow
Plugin · Ads & monetisation
Google AdSense, your own sponsor ads and any ad network in one plugin: placements, ads.txt, Consent Mode v2 and an ad inspector. Pro adds an earnings dashboard, click protection and self-serve ad sales.
Document Engine
Plugin · PDF
Document library for WordPress: instant search and filters, a private PDF viewer that never calls Google, and post to PDF, all free. Pro adds access control, a secure viewer, an audit log and policy acknowledgements.