A WordPress admin plugin to Customize and secure your WordPress dashboard
Deskmode Pro Suite features
Deskmode Pro Suite protects your WordPress admin. It shows you exactly where an attack came from and, with proactive security, tells you who is already attacking other sites before they even reach yours. It also includes login hardening, two-factor authentication, geofencing, activity and mail logs, networking and IP lookup tools, database controls, backups, and a themed dark-mode dashboard.You get all of these features in one installation.
Every screen exists because a live site needed it, not to make a feature list look longer.
Stop using a lot of single-purpose plugins that overlap, conflict with each other and slow down your dashboard.
Deskmode defends the login, the sessions and the database sitting behind them.
You can see the IP address, country, network owner, user and timestamp for every event. This means you can find the origin of an attack, in a few seconds.
Deskmode Pro Suite is a set of WordPress admin tools that lets you manage WordPress from one plugin instead of many. Built for the way you work, without compromising on style.
Limits on failed attempts, hourly block counters, lockouts by IP, anti-lockout protection for you, and a record of every rejected sign-in.
Learn moreCustom login URL, branded sign-in screen, session length, and the small settings that remove the easy targets.
Learn moreApp-based 2FA per role or per single user, with recovery codes. No extra plugin, no external service, no monthly fee. Two captcha services are available.
Learn moreAllow or block sign-in by country, applied at page level before WordPress even prints the form. Search-as-you-type country picker.
Learn moreDisable the file editor and XML-RPC, hide version data, close the openings automated scanners try first.
Learn moreEmail notifications for the events that matter: blocked sign-ins, new administrator accounts, plugin and theme changes.
Learn moreServer details, Whois, DNS records, AS number and IP data at a glance, inside the dashboard. No second diagnostic plugin just to answer a support question.
Learn moreTake any IP from a log and get country, network owner, AS and hostname without leaving the admin, then block it, or block its whole country, in one step.
Learn moreWho signed in, what they changed, from which IP and country. Filter by user, action or date and reconstruct an incident minute by minute.
Learn moreMissing URLs, hit counts and requesting IPs. A broken internal link and a vulnerability scan look completely different here, and one of them needs blocking.
Learn moreEvery message the site sends, with sender, recipient, originating form and IP. Works with Contact Form 7, WPForms, Gravity Forms, Elementor and hand-coded forms alike.
Learn moreSpeed trends, health score history and a Task Manager view of every plugin, database time, SQL queries and hooks registered. Your admin finally reads like an analytics tool.
Learn moreClear expired transients, spot the largest tables, review autoloaded options and delete them with a two-step confirmation.
Learn moreSerialization-aware migration for URLs and paths, with a mandatory preview before a single row is written.
Learn moreFull-site backups to S3-compatible storage or FTP, download and restore from the same screen.
Learn moreA branded holding page with the correct HTTP status while you work, with role and access control so your team keeps going.
Learn moreTurn the bare default 404 into a page that keeps visitors on the site, with search, suggested links and your own design.
Learn moreBlocked attempts, recent sign-ins and open warnings on the dashboard, visible the moment you log in.
Learn moreRestyle the whole admin with 12 one-click accent colours, refined typography and your own logo. Clients notice immediately.
Learn moreA true dark admin that respects coloured panels, the editor and third-party plugins, with a one-click toggle and a preference saved per user.
Learn moreCollect upsell notices, review nags and promo banners into one collapsible panel, attributed to the plugin that printed them. Real errors stay visible.
Learn moreReorder, rename or hide admin menu items per role, and keep long menus compact so clients only see what concerns them.
Learn moreRemove or duplicate entries in Appearance → Menus with one click, using native WordPress actions so nothing breaks.
Learn moreEnglish, Italian, Spanish, French and German, chosen per user from the admin bar without touching anyone else's account.
Learn moreThe whole interface - settings, logs, warnings and inline help - is translated into five languages. The choice is per user, stored in the WordPress user profile, so an Italian agency and a German client can work in the same site each in their own language.
Deskmode Pro Suite features: Proactive Security
Every site running Deskmode blocks login attempts, and knows which address they came from. Put together, those blocks become something no single site can know on its own: who is going around WordPress sites right now.
Shared reputation is one of the reasons you can manage WordPress from one plugin instead of stacking a security plugin, a log plugin and a blocklist service on every site you look after.
When the feature is on, once a day the plugin sends our service the addresses it has blocked and receives the ones reported by everyone else. On the Login Security screen you get a list showing the address, how many different sites reported it, and when it was last seen.
Reported addresses are never blocked on their own: they appear in a list with a Block button next to each one, and you decide. That is a deliberate choice. An address that ends up on the list by mistake - a company VPN, a shared host - would be turned away on every site at once, and you would find out from the phone calls.
General reputation services collect reports from any source, for any kind of attack. This list comes from WordPress sites and from attempts against WordPress logins: an address that has just tried two hundred passwords on another site is exactly what you want to know about before it reaches you.
Proactive security
Proactive means moving that moment earlier. An address currently trying passwords on other WordPress sites has already given itself away, just not to you. If that information reaches you before the address knocks on your door, you never take the first attempt at all.
That is what shared reputation does: every participating site reports the addresses it has blocked, and receives the ones reported by everyone else. No single site can know who is going around WordPress sites right now; thousands of sites together can.
Proactive does not mean automatic. Shared addresses do not walk into your blocklist on their own: they appear in a list with a Block button beside them, and you decide. Getting the information early is useful; handing over the decision is another matter entirely, and one wrong report would cost you dearly.
If you would rather not take part, leave the 'Deskmode Pro Suite features' checkbox off: everything else works exactly as before. Sites that contribute get the list, and that is the only reason the list exists.
Does everything switch itself on once the plugin is installed?
A long list of WordPress admin tools might make you wonder: will all of this slow down my website? Not with Deskmode Pro Suite.Each feature is completely separate and only runs when you enable it. Don't use a feature? Its code stays inactive. The result is simple: Deskmode only does what you need, without wasting resources on features you don't use.
What you gain when you manage WordPress from one plugin. Every module can be switched off from outside the dashboard by defining a constant in wp-config.php, which takes precedence over any setting stored in the database. That is the way out for when something goes wrong and you can no longer sign in, the thing you want to find at eleven at night, on a client’s site.