Why This Plugin Exists

Neksio Login & File Security was not created as a marketing idea. It was created after recovering a real production WordPress website that experienced a series of serious security-related issues.

The recovery process highlighted operational gaps in traditional monitoring and inspired a practical security workflow focused on visibility, file integrity, investigation, and recovery.

Every security feature inside the plugin exists because it solves a real operational challenge encountered during this recovery.

Read the Full Story →
01 — Authentication

Two-Factor Authentication

Add an extra layer of security to your WordPress login with TOTP (Time-based One-Time Password) authentication. Works with Google Authenticator, Authy, and any compatible authenticator app.

  • TOTP verification with authenticator apps
  • Local QR code generation — no external services
  • Recovery codes for emergency access
💡 Inspired by a real incident

During recovery: Compromised credentials were identified as a primary attack vector. Traditional password protection was not sufficient to prevent unauthorized access. Two-factor authentication was implemented to add a critical security layer that passwords alone could not provide.

🔐
Active
02 — Login Security

Custom Login URL

Hide your WordPress login page behind a custom URL known only to you. Reduce automated brute force attacks and bot scanning targeting default login endpoints.

  • Replace /wp-login.php with a secret URL
  • Reduce automated login attempts by 90%+
  • Full control over your custom login path
💡 Inspired by a real incident

During recovery: The default login page was under constant automated attack. Moving the login endpoint to a custom URL dramatically reduced bot traffic and brute force attempts, providing immediate relief.

🔗
Active
03 — Device Security

Trusted Devices

Know exactly which devices access your WordPress admin. Approve trusted devices and block unknown ones. Maintain a complete history of device access.

  • Device recognition and approval workflow
  • Block unauthorized devices automatically
  • Complete device access history
💡 Inspired by a real incident

During recovery: Unknown devices were accessing the admin area from unfamiliar locations. The ability to identify, approve, and block devices based on trusted status became critical for maintaining control.

📱
Active
04 — Protection

Login Protection

Automatic rate limiting and IP blocking to stop brute force attacks. Lock out suspicious IPs and protect your website from automated login attempts.

  • Automatic rate limiting for login attempts
  • IP blocking after failed attempts
  • Configurable lockout thresholds
💡 Inspired by a real incident

During recovery: Automated brute force attacks were overwhelming the login system. Rate limiting and IP blocking were implemented to stop the attacks and prevent resource exhaustion.

🛡️
Active
05 — Monitoring

File Integrity Monitoring

Real-time monitoring of your most important WordPress files. Detect unauthorized changes to wp-config.php, .htaccess, functions.php, and more.

  • Monitor critical WordPress files in real-time
  • Detect unauthorized modifications instantly
  • Email alerts for file changes
💡 Inspired by a real incident

During recovery: Unexpected changes to .htaccess and wp-config.php made it difficult to distinguish legitimate updates from malicious modifications. This feature provides clear visibility into important file changes.

📁
Active
06 — Management

Security Dashboard

A unified security overview. Everything you need to know about your website's security status at a glance. Security score, recent events, and quick actions.

  • Security score and health overview
  • Recent security events feed
  • Quick access to security features
💡 Inspired by a real incident

During recovery: There was no single place to see the security status of the website. The dashboard was designed to provide a complete view of security posture at a glance.

📊
Active
07 — Alerts

Email Notifications

Get notified instantly when critical security events occur. Login attempts, file modifications, unknown file detection, and more — all delivered to your inbox.

  • Instant email alerts for critical events
  • Customizable notification preferences
  • Approve or reject changes directly from email
💡 Inspired by a real incident

During recovery: Critical file changes went unnoticed for days. Real-time email notifications would have enabled immediate response and prevented escalation.

📧
Active
08 — Recovery

Recovery Codes

Emergency backup codes for when you lose access to your authenticator device. Generate, print, and store recovery codes safely for emergency access.

  • Generate emergency recovery codes
  • Print codes for offline storage
  • One-time use codes for emergency access
💡 Inspired by a real incident

During recovery: Administrators lost access to their authenticator devices during the incident. Recovery codes would have provided immediate emergency access.

🔑
Active
09 — Monitoring

Activity Logs

Complete security event history. Every login attempt, file change, and security event is logged and available for review. Search, filter, and export logs for analysis.

  • Complete security event history
  • Search and filter functionality
  • Export logs for external analysis
💡 Inspired by a real incident

During recovery: Understanding the timeline of events was critical. Comprehensive activity logs enabled the team to understand what happened and when.

📜
Active
10 — Protection

IP Management

Block and manage suspicious IP addresses. Whitelist trusted IPs, block known attackers, and maintain complete control over who can access your WordPress admin.

  • Block suspicious IP addresses
  • Whitelist trusted IPs
  • Complete IP access history
💡 Inspired by a real incident

During recovery: Multiple IP addresses were identified as sources of malicious activity. IP management was essential to prevent further unauthorized access.

🌐
Active

Ready to Secure Your Website?

Join thousands of WordPress administrators who trust Neksio Login & File Security for their security. Free forever.