Login Dongle
The bookmark to login nobody but you. Simple and secure.
Consider an alternative
Login Dongle shows warning signs in 2026 — compare the alternatives below before installing. It runs on 40+ sites, is rated 4.5/5 and was last updated 12 years ago, and scores 30/100 on our health check.
- Small user base (40+ active installs)
- Very few reviews so far
- No update in 12 years
- Only tested up to WordPress 4.0 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Login Dongle stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| answer | >100 |
| challenge | >100 |
| ddos | >100 |
| response | >100 |
| security question | >100 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 4.5 from 2 reviews
About Login Dongle
From the official readme · v1.5.2Description
Login Dongle protects your login by means of a security question
(AKA challenge/response) as an extra security layer. A bookmark is your login dongle.
How it works
- Go to your standard login page, fill in the form as usual, and click the bookmark.
- A prompt asks the challenge. Fill in the response, and accept.
https://www.youtube.com/watch?v=9zejJewYVi4
Why it works
- Under the hood, the bookmark submits login data, together with the challenge and response.
- If both challenge and response validate on the server, the login process goes on as usual, otherwise it dies.
- The login page stays exactly the same as usual, so attackers won’t know how to guess challenge and response.
- Only you know the response to the challenge, so nobody but you will be able to use the bookmarlet.
- People using your PC won’t be able to login even if your browser fills in the login form with your password.
Login Dongle is compatible with any other login plugin.
For more info, please refer to the FAQ
and the user’s instructions you’ll find on the settings page after activating the plugin.
User Guides
- Dutch: http://www.wpsitemaken.nl/login-dongle
- English: http://www.itechdestiny.com/wordpress-security-with-login-dongle-plugin/
- English: http://www.shoutmeloud.com/secure-wordpress-login.html
- French: http://neosting.net/comment-securiser-acces-login-wordpress-2-etapes
- German: https://wordpress.org/support/topic/excellent-plugin-110
- Japanese: http://wp.8jimeyo.info/plugin/login-dongle/
- Turkish: http://hakanertr.wordpress.com/2012/07/24/login-dongle/
Quick Reviews
- http://forum.ait-pro.com/forums/topic/compatibility-question-for-custom-login/
- http://webscripts.softpedia.com/script/Modules/WordPress-Plugins/Login-Dongle-80067.html
- https://wordpress.org/support/topic/plugin-login-dongle-clever-plugin
- http://www.evohosting.co.uk/blog/web-development/wordpress-web-development/6-of-the-best-wordpress-security-plugins/
- http://www.labnol.org/internet/improve-wordpress-security/24639/
- https://www.linkedin.com/groups/Security-suggestions-1482937.S.199139568#commentID_110730071
- http://www.practicalwp.com/login-dongle-login-bookmarklet-for-wordpress/
- http://www.wtfdiary.com/2012/08/8-ways-to-secure-your-wordpress-blog.html
Available translations
- English (Andrea Ercolino)
- Serbian (Borisa Djuraskovic)
- Spanish (Andrea Ercolino)
- Turkish (Hakan Er)
NOTE: Here ‘bookmark’ and ‘bookmarklet’ are used interchangeably.
Uninstall Instructions
- Click the Delete button in the Plugins/Installed Plugins list.
If you manually removed the login-dongle plugin directory, or if your version was prior to 1.4.0,
some garbage is left into your database. It’s harmless, but if you still want to clean it up, access
the options table and remove all the rows whose option_name column start with login_dongle.
If your version was prior to 1.1.0, edit the wp-login.php file in the root
directory of your blog and remove the line that begins with do_action('login-start');
Banner
From Rusty door, taken by
fotologic on August 14, 2010 in Penbryn, Wales, GB.
Installation
- Upload the login-dongle directory to your wp-content/plugins directory.
- Click on Activate from the Plugins menu.
- Configure.
Configuration
- Edit your site settings (from the Settings/Login Dongle menu), choose a message for intruders, and save.
- Edit your profile (from the Users/Your Profile menu), choose both challenge and response, check the flag Send on next update, and save.
- Drag-and-drop your new bookmark into the bookmarks bar of your browser.
https://www.youtube.com/watch?v=eY6O1zwddYE
Upgrading from any version prior to 1.3.0
Before version 1.3.0, Login Dongle was site-wide available, and all users essentially shared the
same bookmark as their login dongle. Starting from version 1.3.0, any user has her own login
dongle. Upgrading from previous versions to 1.3.0 is done by automatically associating to each user
a login dongle with the same challenge >> response as the one that was already site-wide set.
This makes it possible to upgrade hassle free, even if your blog had other users. Anyway, if that
is not what you want, you can configure the login dongle of each user from the Users/All Users
menu.
Changelog
Remember to refresh the bookmarked login dongle by grabbing it again from your profile page.
1.5.2
- Added the Serbian translation (thanks to Borisa Djuraskovic).
- Changed ‘bookmarklet’ to ‘bookmark’, easier to understand for most users.
- Added links to installation videos, User Guides and Quick Reviews.
1.5.1
- Added the Turkish translation (thanks to Hakan Er).
1.5.0
- Added support for XML-RPC, such that the backdoor used by mobile apps and offline editing tools is now secured.
- Optimized code.
- Improved documentation.
1.4.3
- Added a banner to the plugin page in the wordpress site.
- Made explicit the license, now required into the readme.
- Improved documentation.
1.4.2
- Added the Turkish translation (thanks to Hakan Er).
1.4.1
- Changed the way context is addded to translations. Now using _x() instead of vertical bars.
- Fixed a bug causing the option for a deleted user to stay put.
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Login Dongle alternatives
All answer plugins →FAQ
Login Dongle: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 2, 2026
Is Login Dongle free?
Yes. Login Dongle is free to download and use from the official WordPress.org plugin directory.
Is Login Dongle safe to use in 2026?
Login Dongle shows warning signs in 2026 — compare the alternatives below before installing. It runs on 40+ sites, is rated 4.5/5 and was last updated 12 years ago, and scores 30/100 on our health check.
How many websites use Login Dongle?
Login Dongle is active on 40+ WordPress websites and has been downloaded 26,070 times since it launched in February 2012. It was downloaded 77 times in the last 30 days.
Does Login Dongle work with WordPress 7.1?
Login Dongle is officially tested up to WordPress 4.0.38, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
When was Login Dongle last updated?
The latest version, 1.5.2, was released on October 1, 2014 (12 years ago).
Who makes Login Dongle?
Login Dongle is developed and maintained by Andrea Ercolino.
What are the best alternatives to Login Dongle?
The most popular alternatives to Login Dongle are Yes/No Chart (2K+ installs), FAQ Block (500+ installs) and Question answer (100+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card