DoLogin Security icon

DoLogin Security

by WPDO

View on WordPress.org
78 Quality Score
Active Installs
17/30

With roughly 7,000 active installs, DoLogin is a niche tool, dwarfed by the million-install alternatives in the same category, though its popularity score gets a boost from holding a focused, specific feature set.

Update Freshness
25/25

The plugin was updated on June 11, 2025 and is confirmed tested against WordPress 6.8.5, which signals an actively maintained codebase despite the small user base.

User Rating
14/15

A 90 out of 100 score from 13 ratings is excellent on paper, but the sample size is small enough that the rating carries less statistical weight than ratings on plugins with hundreds or thousands of reviews.

Support Health
8/15

Only one support thread exists in the record, and it is unresolved, which makes it hard to judge responsiveness or depth of help from the developer.

WP Compatibility
15/15

Requiring WordPress 4.0 or higher gives DoLogin one of the widest compatibility ranges in the category, but the missing PHP version requirement is a documentation gap worth flagging.

Scores higher than 66% of indexed plugins

About

Login security: KeyLockr SSO scan login, 2FA, passwordless login, Cloudflare Turnstile, GeoLocation/IP limits, whitelist and blacklist.

Active Installs 7k+
Rating ★★★★½ 4.5/5
Last Updated 2026-08-16 2:23am GMT
Requires WordPress 4.4+
Tested Up To 7.1
Requires PHP 5.6+

Security History

5 known vulnerabilities, all patched
2 High 3 Medium

Most recent: July 7, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

DoLogin Security adds a layer of protection to the WordPress login screen through three main features: two-factor authentication, passwordless login, and CAPTCHA options including Cloudflare Turnstile and reCAPTCHA. It also lets administrators restrict or block login attempts based on visitor geography (continent, country, or city) and IP range, which helps reduce brute force and credential stuffing attacks from targeted regions.

Who It's For

This plugin fits small to mid-sized WordPress sites that need more than a basic limit-login-attempts tool but do not want the bloat of a full security suite, especially sites serving a defined geographic audience where blocking logins from unneeded countries makes sense. It is a reasonable fit for membership sites, internal portals, or any operator who wants 2FA and CAPTCHA without paying for a premium solution.

Who Should Skip It

If you already run a full security plugin like Wordfence, Defender, or All-In-One Security, adding DoLogin is redundant because those tools ship with 2FA, CAPTCHA, and brute force protection out of the box. Sites needing firewall-level WAF rules, malware scanning, or a security team behind the plugin should look elsewhere.

The Bottom Line

DoLogin Security delivers a focused feature set at a fair overall quality score of 64.54 out of 100, and its high user rating is encouraging even if the sample is small. The biggest concerns are the tiny install base and the unresolved support thread, which means you are betting on a less proven developer. For sites that need exactly its feature mix and nothing more, it is a workable choice, but most administrators will be better served by one of the larger, better supported alternatives above.

Tags

2fa-login Cloudflare turnstile limit login attempts login security passwordless login