

Security Dashboard with health score ring, star rating, stats grid, activity chart, recommendations.
ZA Creative Login Shield is a comprehensive enterprise-grade security platform that protects your WordPress site against brute force attacks, unauthorized access, credential stuffing, file tampering, and known vulnerabilities. It provides 28 integrated security features with an intuitive dashboard.
Weighted security score (0-100) with star rating (⭐⭐⭐⭐⭐) and detailed check breakdown. 23 automated checks including 2FA, rate limiting, password policy, SSL, file integrity, vulnerability scanning, admin username, XML-RPC, debug mode, and more.
Email OTP and Google Authenticator (TOTP) support with per-role enforcement. Force 2FA for administrators, editors, or any custom role.
Support for Windows Hello, Face ID, Touch ID, Android Passkeys, and physical security keys. Users can register multiple credentials from their profile page.
Apply all recommended security settings with one click: 2FA, rate limiting, password policy, email notifications, custom login URL, session timeout, device tracking, and more.
Professional analytics with login activity charts, browser distribution, operating systems, 24-hour attack timeline, top attackers, country statistics, success/failure rates, and most attacked usernames. AJAX-loaded with period switching.
Five-factor risk scoring engine evaluating IP reputation, new device detection, failed attempt history, TOR/VPN detection, and geolocation changes. Scores classify logins as Low, Medium, High, or Critical.
View all active sessions with user, device, browser, country, and last activity. Terminate individual sessions or force logout all sessions.
Recognize trusted devices via browser fingerprinting. Unknown devices trigger email verification before allowing access.
One-click lockdown disables all logins, XML-RPC, REST API authentication, and new user registration. Whitelist IPs for emergency access. Full audit trail logging.
Scan WordPress core files, plugins, themes, wp-config.php, and .htaccess for unauthorized changes. Detects modified, missing, and new files with hash verification.
Connects to WPScan API and GitHub vulnerability feeds to check installed plugins and themes against known security vulnerabilities. Severity ratings (Critical, High, Medium, Low).
Detects suspicious PHP patterns including base64 encoded payloads, eval() execution, shell_exec() calls, and recently modified files during file integrity scans.
Enforce minimum length, uppercase, lowercase, numbers, special characters, password expiration (days), password history (prevent reuse), and block 26+ common passwords.
Smart daily briefing generating natural-language security summaries: “You had 53 login attempts. 43 blocked. 8 from Russia. 2 from China.” Contextual recommendations based on real-time activity.
Customize login page with custom logo image, logo URL, logo title, background color, form background, text color, primary button color, custom CSS, header HTML, and footer HTML.
Six professional HTML email templates with inline CSS: login notification, blocked IP alert, scheduled report, device verification, OTP code, and default template. Dark-mode compatible.
In-WordPress notification system with dismiss functionality and unread counts. Alerts for blocked attacks, new IPs, plugin updates, and 2FA changes. Stored per user.
Complete action log for all security events: settings changes, IP blocks, lockdown activation, user sessions, file scans, vulnerability scans, report generation, and wizard actions.
Daily, weekly, or monthly email reports delivered in beautiful HTML format. Includes login statistics, blocked IPs, top attackers, and country breakdown. PDF download available.
Export login logs, blocked IPs, and comprehensive security reports in CSV, JSON, and PDF formats. One-click download from any admin page.
Eight REST API endpoints under zacls/v1: get stats, get logs, get blocked IPs, get analytics, get health score, get reports, enable lockdown, and disable lockdown.
Monitor memory usage, database size, cron job status, database query count, and per-table row counts for all plugin tables. Memory usage indicator with percentage.
Automatically delete old login logs, audit logs, expired sessions, and risk scores. Configurable frequency (daily, weekly, monthly) and retention period (7-365 days).
This plugin stores the following information:
All data is stored locally inside the WordPress database.
Country information may be retrieved via ip-api.com if GeoIP is enabled (opt-in, disabled by default). Cloudflare API requests (manual admin action) send no visitor data. WPScan API requests send installed plugin slugs and versions.
Site administrators are responsible for complying with local privacy laws.
Full data removal on uninstall (all database tables and options cleaned up).
This plugin uses the following external services: