Fully branded login
Swap the WordPress logo for yours, set a background colour, gradient or image, and match your fonts, colours and layout — with a live preview and ready-made style presets to start from.
Give the WordPress login screen your logo, colours and layout — then protect it with brute-force lockouts, a bot honeypot, a self-hosted CAPTCHA, passwordless magic-link sign-in and two-factor authentication — plus a full login history. All from your WPStack panel, no extra plugin, nothing sent to third parties.
Everything you’d reach for a page-builder and two security plugins to do — styling, brute-force protection and redirects — in one module.
Swap the WordPress logo for yours, set a background colour, gradient or image, and match your fonts, colours and layout — with a live preview and ready-made style presets to start from.
Lock out an IP after too many failed logins for a window you choose, so password-guessing bots hit a wall.
A hidden trap field catches automated spam sign-ins and blocks them without ever bothering a real visitor.
Show one generic error instead of revealing whether the username or the password was wrong, and switch off XML-RPC.
Send people exactly where they should land after signing in — globally or per role — and choose where logout goes too.
Let users sign in from a one-time email link — no password to type or reset. Single-use, short-lived and hashed; administrators are opt-in.
Opt-in TOTP with any authenticator app (Google Authenticator, Authy, 1Password). QR setup on the profile, single-use recovery codes, and it protects the magic link too.
Stop bots on the login, registration and lost-password forms with a simple question or an invisible proof-of-work — verified on your own server, no Google or Cloudflare.
A running log of every sign-in across all users — the method (password, magic link, XML-RPC), the IP, the device and the time, with failed attempts flagged.
Styling is a small inline stylesheet on the login screen only; the rest is admin-side. Your public pages are untouched.
Style, Security and Login/out — set once and your login page runs itself.
Flip Login on in WPStack → Modules. A Login screen appears in the WPStack menu.
Set your logo, background, colours, typography and layout in the Style tab — the preview updates as you go.
In Security, switch on attempt limits, a CAPTCHA, two-factor and magic-link as you like — then set your login/logout redirects.
The Security tab hardens the exact page attackers target. Lockouts throttle brute-force attempts, the honeypot quietly traps bots, and generic errors stop giving away which field was wrong.
Login restyles the standard WordPress login screen — the URL is unchanged, so bookmarks, SSO links and password managers keep working.
No. It restyles and protects the standard WordPress login screen — the address stays the same, so nothing else in your setup needs to change.
Brute-force lockouts (limit login attempts per IP), a silent bot honeypot, generic error messages that don’t reveal which field was wrong, and an optional switch to disable XML-RPC.
Only temporarily, and only after repeated failed attempts from your IP. You set the attempt limit and the lockout minutes, and it clears itself when the window expires.
It closes a common attack surface, but the WordPress mobile app and some Jetpack features use XML-RPC. It’s off by default — only enable the switch if you don’t rely on those.
Yes. Set a global after-login destination (dashboard, home or a custom URL) plus per-role overrides, and choose where logout sends people too.
Yes — turn on magic-link login and users can request a one-time sign-in link by email. The link is single-use, expires quickly, and is stored only as a hash. Administrator accounts are opt-in, since a compromised inbox is a bigger risk for them.
Yes — the Login History tab records every sign-in across all users: the method (password, magic link, XML-RPC), the IP, the device and the time, with failed attempts flagged. You can filter and clear it anytime.
Yes — opt-in TOTP that works with any authenticator app. Users scan a QR on their profile, get single-use recovery codes, and are asked for a 6-digit code after their password (or magic link). It’s all in-module — no external service.
No — it’s fully self-hosted, so nothing is sent to Google, Cloudflare or any third party. Choose a simple question (accessible, no JavaScript) or an invisible proof-of-work puzzle, on the login, registration and lost-password forms.
Yes — like every WPStack module, Login is included in every plan. Switch it on per project from the modules panel.
One system for logins, forms, fields, bookings, events and everything in between. Activate what you need today.
No credit card to explore the demo · Cancel anytime