3.0.0 – Modify Login is now Authlify
Modify Login is now Authlify: an all-in-one login security plugin. Your login URL, settings and log carry over, and new protections stay off until you switch them on.
New
- Rebuilt hidden login URL. WordPress no longer reveals the secret address through /wp-admin/, /login, /admin, /dashboard, wp-signup.php, the Customizer, privacy emails or encoded paths. It works on Nginx and managed hosts, with no rewrite rules.
- Leak Check tests about 40 routes on your own site. Also new: a confirm-before-apply step for new login URLs, a login-URL email, WP-CLI commands and wp-config recovery constants.
- Brute-force lockouts per IP, network and targeted account, with escalating lockouts, trusted-proxy IP detection, allow and block lists, and email unlock links.
- CAPTCHA: Cloudflare Turnstile, hCaptcha, reCAPTCHA v2/v3 and self-hosted ALTCHA on core, comment and WooCommerce forms, plus a honeypot.
- Two-factor login and passkeys: authenticator apps, backup codes and passkey sign-in.
- Breached-password check using the privacy-preserving Have I Been Pwned range API.
- Login page designer with 12 templates, "Match my site" and a live preview of every login screen.
- Activity log with filters, CSV export, retention, IP anonymization and privacy tools.
- Per-role redirects; XML-RPC, username-discovery and application-password controls; private-site mode; and settings import/export.
- Importers for WPS Hide Login, Limit Login Attempts Reloaded, ASE and LoginPress.
- Built-in documentation under Authlify → Docs.
Security
- Closed two ways to reach the login page without the custom URL.
- Fixed a fatal error when reCAPTCHA could not be reached.
- Visitor IPs are no longer sent to a third-party location service.
Requirements
WordPress 6.4+ and PHP 7.4+. Passkeys need PHP 8.0+.
Authlify Pro adds two-factor rules by role, social login and SSO, passwordless and temporary access, alerts, session and password policies, 22 premium designs and agency tools. See https://matrixaddons.com/plugins/authlify/