Login module

Brand your login. Lock out the bots.

Give the WordPress login screen your logo, colours and layout — then protect it with brute-force lockouts, a bot honeypot, a self-hosted CAPTCHA, passwordless magic-link sign-in and two-factor authentication — plus a full login history. All from your WPStack panel, no extra plugin, nothing sent to third parties.

Included in every plan Same login URL
Username or Email
Password
Log In
Lost your password?
© Serene Spa & Wellness
Your branding
Brute-force blocked
Included in every planNo add-on or upsell
Your data stays on your siteNo external login service
Set up in minutesStyle, protect and redirect — no code
Why it’s different

A login page that’s on-brand and locked down

Everything you’d reach for a page-builder and two security plugins to do — styling, brute-force protection and redirects — in one module.

Fully branded login

Swap the WordPress logo for yours, set a background colour, gradient or image, and match your fonts, colours and layout — with a live preview and ready-made style presets to start from.

Brute-force protection

Lock out an IP after too many failed logins for a window you choose, so password-guessing bots hit a wall.

Silent bot honeypot

A hidden trap field catches automated spam sign-ins and blocks them without ever bothering a real visitor.

Fewer clues for attackers

Show one generic error instead of revealing whether the username or the password was wrong, and switch off XML-RPC.

Smart login/out redirects

Send people exactly where they should land after signing in — globally or per role — and choose where logout goes too.

Passwordless magic link

Let users sign in from a one-time email link — no password to type or reset. Single-use, short-lived and hashed; administrators are opt-in.

Two-factor authentication

Opt-in TOTP with any authenticator app (Google Authenticator, Authy, 1Password). QR setup on the profile, single-use recovery codes, and it protects the magic link too.

Self-hosted CAPTCHA

Stop bots on the login, registration and lost-password forms with a simple question or an invisible proof-of-work — verified on your own server, no Google or Cloudflare.

Login history

A running log of every sign-in across all users — the method (password, magic link, XML-RPC), the IP, the device and the time, with failed attempts flagged.

Nothing heavy to load

Styling is a small inline stylesheet on the login screen only; the rest is admin-side. Your public pages are untouched.

How it works

Three tabs, done

Style, Security and Login/out — set once and your login page runs itself.

01

Activate the module

Flip Login on in WPStack → Modules. A Login screen appears in the WPStack menu.

02

Style your login page

Set your logo, background, colours, typography and layout in the Style tab — the preview updates as you go.

03

Harden & redirect

In Security, switch on attempt limits, a CAPTCHA, two-factor and magic-link as you like — then set your login/logout redirects.

Built-in protection

Stop password-guessing and spam bots

The Security tab hardens the exact page attackers target. Lockouts throttle brute-force attempts, the honeypot quietly traps bots, and generic errors stop giving away which field was wrong.

  • Lock out an IP after N failed attempts
  • Auto-expiring lockout window you control
  • Hidden honeypot field blocks spam bots
  • Self-hosted CAPTCHA — question or invisible proof-of-work
  • Two-factor authentication (TOTP + recovery codes)
  • Passwordless magic-link login (admins opt-in)
  • One generic “invalid credentials” message + optional XML-RPC switch-off
  • A login history log across all users
Login
Style
Security
Login/out
Security
Harden the login form against brute-force and bot attacks.
Limit login attempts
Lock out an IP after too many failed logins
Blocks brute-force attempts for a set window
Max attempts
5
Lockout (minutes)
15
Login honeypot
Silently blocks spam bots with a hidden trap field
Generic error messages
Hide whether the username or the password was wrong
Disable XML-RPC
Close a common attack surface
Save Settings
WordPress6.0+ (6.5+ recommended)
PHP7.4+ (8.1+ recommended)
ThemesWorks with any theme
Front endStyles the login screen only

Login restyles the standard WordPress login screen — the URL is unchanged, so bookmarks, SSO links and password managers keep working.

FAQ

Login, answered

No. It restyles and protects the standard WordPress login screen — the address stays the same, so nothing else in your setup needs to change.

Brute-force lockouts (limit login attempts per IP), a silent bot honeypot, generic error messages that don’t reveal which field was wrong, and an optional switch to disable XML-RPC.

Only temporarily, and only after repeated failed attempts from your IP. You set the attempt limit and the lockout minutes, and it clears itself when the window expires.

It closes a common attack surface, but the WordPress mobile app and some Jetpack features use XML-RPC. It’s off by default — only enable the switch if you don’t rely on those.

Yes. Set a global after-login destination (dashboard, home or a custom URL) plus per-role overrides, and choose where logout sends people too.

Yes — turn on magic-link login and users can request a one-time sign-in link by email. The link is single-use, expires quickly, and is stored only as a hash. Administrator accounts are opt-in, since a compromised inbox is a bigger risk for them.

Yes — the Login History tab records every sign-in across all users: the method (password, magic link, XML-RPC), the IP, the device and the time, with failed attempts flagged. You can filter and clear it anytime.

Yes — opt-in TOTP that works with any authenticator app. Users scan a QR on their profile, get single-use recovery codes, and are asked for a 6-digit code after their password (or magic link). It’s all in-module — no external service.

No — it’s fully self-hosted, so nothing is sent to Google, Cloudflare or any third party. Choose a simple question (accessible, no JavaScript) or an invisible proof-of-work puzzle, on the login, registration and lost-password forms.

Yes — like every WPStack module, Login is included in every plan. Switch it on per project from the modules panel.

Stop juggling plugins. Start with WPStack.

One system for logins, forms, fields, bookings, events and everything in between. Activate what you need today.

No credit card to explore the demo · Cancel anytime