A WordPress admin plugin to Customize and secure your WordPress dashboard
Almost all WordPress security is reactive, and for good reason: it counts failed attempts, blocks after the fifth, warns you once something has happened. That works, but it always starts from an attack already under way on your site. You take the first attempt, and the tenth: only then does the system respond. Meanwhile that same IP address has already tried two hundred passwords on another WordPress site. That site knows. You don't.
Every time you install Deskmode it blocks people who try to log in. It knows where they are coming from. If you look at these blocks one by one they do not tell you much: an address, a date and a site.. When you put them all together they become something that no single site can figure out on its own, like which addresses are trying to attack WordPress sites right now.
With this release Deskmode Pro Suite collects all this information. A day the plugin sends the addresses it has blocked to our service and gets a list of addresses that other sites have reported. On the Login Security screen you get a list that shows the country where the addresss from, how many sites have reported it and when it was last seen. You also get a chart that shows what happened over the seven days.
This is what we mean by being proactive: we are not just talking about a word we are talking about doing something before it’s too late. If you get the information before the bad address tries to log in to your site you do not even have to deal with the attempt.
The reason is that if we make a mistake it can cause problems. What if a companys VPN or a host that many customers use gets on the list by mistake? It would be blocked everywhere. You would not even know what is going on until you start getting phone calls.
So we show you the shared list of addresses and you can decide what to do. We give you a Block button next to each address. You get to choose. Getting the information early is helpful. We do not want to make the decision for you.
We also have a rule that an address has to be reported by least three different sites within thirty days before it gets on the shared list. Each site only gets one vote no matter how times it reports the same address.
This way we make sure that one site that is not set up right or has been compromised cannot put an address on the list. It might take a little longer for the list to fill up. When an address does get on the list it is because many sites have agreed that it is bad.
The only thing that leaves your site is the IP addresses that you have already blocked. We do not collect any content, visitor data or usernames. Your site is identified by a code that is based on your domain so our service knows how many sites have reported an address, but not which sites.
This feature is turned off by default. You have to tick the box on the Login Security screen before it starts working. This is how all our features work: if they need to reach outside your site they are turned off until you say it is okay.
We believe in reciprocity: the list only works because the sites that use it also help to make it. If you do not want to be part of it you can just leave the box and everything will work just like it did before. You just will not get the list.
We made a list that’s just for WordPress sites because general lists that collect reports from everywhere can be too broad. They might have information about all kinds of attacks. It is not always relevant to you. Our list is different: it only comes from WordPress sites. It only shows attempts to log in to WordPress sites. If an address has just tried to log in to another site, with two hundred passwords that is something you want to know about before it tries to log in to your site.. That is something you might not find on a general list because it gets lost in all the other information.
For general background on protecting WordPress, WordPress.org’s
hardening guide remains the starting reference.