WordPress login protection
Limit repeated sign-in attempts on the native WordPress login form and optionally require a human check. Review recorded decisions when a legitimate user has trouble signing in.
Loading…
Gate House · WordPress security plugin
Gate House helps protect WordPress from automated login attempts, unwanted registrations and form spam. Choose local attempt limits, independent account abuse checks and optional human verification from one place in your dashboard.
Where Gate House helps
A public form is useful to your visitors—and available to automated traffic. Gate House lets you choose checks for each supported form, so a busy comment section and an administrator sign-in don’t have to use the same settings.
Limit repeated sign-in attempts on the native WordPress login form and optionally require a human check. Review recorded decisions when a legitimate user has trouble signing in.
Add attempt limits and optional human verification to native registration. Independent account abuse protection checks supported sign-ups for combined generated-profile and repeated-identity patterns.
Reduce repeated reset requests on supported native forms with configurable attempt limits. Add a human check where you want visitors to verify before submitting a request.
Require human checks on WordPress comments and Contact Form 7 submissions. Manage these forms beside your account protection instead of configuring a separate provider for each area.
Three checks, different jobs
Choose the controls that address the activity you see. Each check has its own purpose.
Set limits for repeated requests on supported forms. Light, Balanced, Strict and Custom let you adjust thresholds without changing which forms have checks enabled. Review normal activity on your site before deciding how tight those limits should be.
Use one supported provider at a time: Cloudflare Turnstile, Google reCAPTCHA or hCaptcha. A successful connection test confirms a real challenge can be verified from your server. Your forms still need their own successful and rejected submission tests.
The independent guard combines supported profile signals and repeated identities. An unusual name, missing field or shared business address alone does not trigger a match. A passed human check does not override an account abuse block. Start by observing matches and review them before choosing to block.
WordPress security checklist
Begin on a staging copy and keep an administrator session open while testing sign-in.
Follow the full installation guide →List the login, registration, reset, comment and contact forms visitors use. Check Coverage for recognized adapters and identify any custom or membership-plugin routes that need separate assessment.
Install Gate House on the individual site and use Observe to review decisions. Choose the forms and attempt limits you want to enable; account abuse protection has its own Observe and blocking choices.
Register the exact site hostname with your chosen provider, save matching site and secret keys and pass the browser connection test. Then explicitly enable human checks for selected forms.
Try sign-in from a private window, create a test account and submit the reset and contact forms you use. Confirm that legitimate visitors can finish and that rejected requests show a useful message.
After a theme, form or protection-rule change, revisit Coverage and repeat affected journeys. Use Activity and Diagnostics to investigate unexpected results before adjusting your rules.
Before you install
Understand the checks, the limits and what to test on your own site.
Get help with your setupYes. WordPress login, registration, password-reset and comment protection work without WooCommerce. The Contact Form 7 adapter is available when that plugin is active.
No. Local attempt limits and independent account abuse checks work without a CAPTCHA provider. Human verification is optional; connect Cloudflare Turnstile, Google reCAPTCHA v2 checkbox or v3, or standard hCaptcha, pass the connection test and enable it for the forms you choose.
No. Gate House focuses on bot and account abuse at supported forms. It does not scan files for malware or provide a web application firewall. Maintain your software, backups, access controls and hosting protections alongside it. See the official WordPress hardening guide for broader security practices.
A fresh installation starts in Observe. You can review activity before turning on local protection or choosing individual rules. Saving provider keys alone does not enable human checks. Existing settings are preserved when you upgrade.
Yes. Activity records local decisions and their reasons, and lets you mark suspected false positives for review. The plugin does not log passwords, raw challenge tokens or complete addresses. Use Diagnostics to investigate provider and configuration issues.
An administrator with trusted server access can temporarily enable recovery mode in wp-config.php or use the supported WP-CLI recovery command. There is no public bypass URL. Follow the recovery instructions in the setup guide, correct the settings and test before leaving recovery mode.
Review the plans, check your forms and get help from the people who build Gate House.