Replace five plugins with one. Brute-force protection, content locking, AI-crawler blocking, a CPU monitor, and a live-preview login customizer — zero external scripts on your front end.
Stop bolting together a login limiter, a content gate, a bot blocker, a customizer, and a health monitor. WPEPP ships them as one tidy React panel.
Auto-lock any IP after repeated failed logins. Set max attempts and lockout minutes — brute force stops cold.
Invisible trap field catches automated login bots instantly — humans never see it.
Hidden trap on the signup form blocks fake registrations before they hit your database.
Per-IP throttle kills mass signup spam without lifting a finger.
Drop Google reCAPTCHA on login and register forms — bots out before they try.
RFC-6238 two-factor with QR setup, 8 recovery codes, and role-based enforcement.
Every success, failure, and lockout — with IP, user-agent, timestamp, and filtering.
Manually allow trusted IPs or ban abusive ones at the door.
Reject temp-mail signups and whitelist/blacklist whole email domains.
Move wp-login.php to a secret URL. The old one returns 404 — invisible to attackers.
One-click toggle to block GPTBot, CCBot, Google-Extended & more via robots.txt + 403 at the server.
Block or allow visitors by country. Cloudflare header with ipapi.co fallback. Unlimited on Pro.
Shut the xmlrpc.php endpoint bots use for brute-force and DDoS amplification.
Strip the generator tag and version query strings so attackers can’t fingerprint you.
Block /wp/v2/users enumeration to stop username discovery.
Secure one-time login tokens with per-IP rate limiting and auto-expiry pruning.
Hold new registrations for manual admin approval before they can log in.
Gate the whole site behind one shared password with a configurable cookie duration. Admins bypass automatically.
Lock the front end to logged-in users — perfect for staging and intranets.
Lock any post, page, or CPT from the editor — login link, inline form, blurred popup, or redirect.
Restrict content to specific roles — subscribers, members, anything you define.
Show/hide content by login status free; unlock 12 conditions (role, device, time, browser, referrer…) on Pro.
Assign a page template — visitors see a login form, members see the content. Zero config.
Schedule locked content to open automatically at a date and time you set.
Change a color, see it instantly. No save-and-reload loop — every tweak renders in real time.
Solid color, CSS gradient, image, or video with overlay — your login page, your stage.
Upload a logo or use a text logo; style form background, border, width, padding, and shadow.
Control input colors, focus states, button radius, hover — pixel-level, no CSS needed.
The same visual editor for the register and lost-password screens, plus custom CSS.
4 branded password-form designs (2 free), social icons, custom labels & error text.
One-click designs — Minimal, Modern Dark, Corporate, Gradient Wave and more.
Live CPU %, core count, 1/5/15-min load averages, PHP memory and peak usage.
Log DB queries past a threshold you set, with a SAVEQUERIES toggle baked in.
View, run, or delete WP cron events and spot overdue jobs that got stuck.
See which plugins eat the most resources — and deactivate the sluggish ones.
Inspect autoloaded option size and clear expired transients in one click.
Parse and read PHP/WordPress error entries by type, right inside the dashboard.
Toggle WP_DEBUG, WP_DEBUG_LOG & SAVEQUERIES without ever editing a file.
Instant green/yellow/red badge from CPU, memory, and cron status at a glance.
One unified dashboard for login limiting, security hardening, content protection, login styling, and health monitoring. One settings panel. Zero compatibility headaches.
Nothing third-party loads on your front end. Your PageSpeed score stays exactly where it is.
CSS and JS load only on the pages that actually need them. Your visitors never feel it — attackers do.
No confusing settings sprawl. A fast React admin with live preview — change a color and watch it update instantly. Apply a template, done. Every setting saves over the REST API, no page reloads.
A built-in migration system carries every customization across versions — even the v1 → v2 jump. Nothing lost.
Skip the styling work. Import a finished look for your login and password forms, then tweak in live preview.
The free plugin is genuinely useful. Pro unlocks the features agencies and busy owners lean on.
| Feature | Free | Pro |
|---|---|---|
| Limit login attempts + IP lockout | ✓ | ✓ |
| Login & registration honeypots | ✓ | ✓ |
| AI crawler blocker (GPTBot, CCBot…) | ✓ | ✓ |
| Site password + admin-only mode | ✓ | ✓ |
| Login page customizer + live preview | ✓ | ✓ |
| CPU monitor + cron manager | ✓ | ✓ |
| Country restriction | 2 max | Unlimited |
| Conditional display rules | 2 | 12 |
| Password form templates | 3 | 10+ |
| Two-factor authentication (2FA) | — | ✓ |
| reCAPTCHA (login + register) | — | ✓ |
| Hide login page / custom URL | — | ✓ |
| Per-post & role-based content lock | — | ✓ |
| Login activity log + IP allow/block | — | ✓ |
| Register / lost-password styling | — | ✓ |
| Error log viewer + priority support | — | ✓ |
Every plan, one-time or yearly, comes with a 30-day money-back guarantee.
Perfect for a single WordPress site.
Best value for freelancers & agencies.
Every site you build, now and later.
🛡️ 30-Day Money-Back Guarantee · No auto-renewal tricks · Cancel anytime
Just testing the waters? Install the free version →
No. WPEPP loads zero external scripts on the front end. CSS and JS load conditionally — only on pages that need them. The React admin runs solely inside wp-admin, so your public site speed is untouched.
Yes — WP Super Cache, W3 Total Cache, LiteSpeed Cache, WP Rocket and others. Password-protected and member-only pages are excluded from caching in most setups. For site-wide password, exclude the password-check page in your cache plugin.
Yes. Use conditional display on product pages, restrict the shop, or password-protect individual products. The login customizer styles the default WordPress login that WooCommerce also uses.
Yes. A built-in migration system preserves all settings across versions, including the v1.x → v2.0 upgrade. Your customizations, security rules, and styling are never lost.
Yes. WPEPP runs on WordPress multisite networks. Each sub-site keeps its own independent settings, and network-wide activation is supported.
Pro features simply become inactive — your data stays in your database. No lock-in, nothing destroyed. Re-activate any time.
All data lives in your own WordPress database. The only external calls are optional telemetry via the Appsero SDK — and that only runs after you explicitly opt in. No passwords or content are ever collected.
Free users get the WordPress.org support forum. Pro users get priority ticket support with a typical response under 24 hours.
Join 10,000+ owners who replaced five plugins with one — and finally sleep easy.