NHR Secure – Login Security, Firewall, 2FA & Audit Log
A lightweight WordPress security plugin to protect your admin area with a custom login URL, hide debug logs, limit login attempts, and add 2FA.
Solid choice
NHR Secure is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 4 days ago, and scores 64/100 on our health check.
- Actively developed — last update 4 days ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where NHR Secure stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| 2FA | >100 |
| Debug log | >100 |
| hide admin | >100 |
| login protection | >100 |
| security | >100 |
About NHR Secure
From the official readme · v1.3.3Description
Keep your WordPress site safe with minimal effort. NHR Secure helps you:
- Hide or protect your admin area from unauthorized access.
- Limit login attempts to prevent brute-force attacks.
- Hide debug logs to prevent sensitive information disclosure.
- Add 2FA to your WordPress site.
- Scan core files, plugins, and themes for known vulnerabilities.
- Monitor site health with one-click security recommendations.
- Protect against SQL injection, XSS, and LFI attacks.
- Block malicious IPs and entire countries.
Features at a glance:
🔒 Limit Login Attempts
Stop brute-force attacks by temporarily blocking IPs after repeated failed login attempts.
– Configurable attempt limit (1-20, default: 5)
– Blocks based on IP + Username combination
– Auto-unblock after 2 hours
🔐 Custom Login Page
Hide wp-login.php and use a custom login URL.
– Default custom URL: /hidden-access-52w
– Blocks direct access to wp-login.php and wp-admin for guests
🛡️ Protect Debug Log File
Blocks direct access to /wp-content/debug.log
– Returns 403 Forbidden for all users
⚙️ Modern Settings Page
Configure everything from a beautiful React-powered interface.
– Located under Tools → NHR Secure
– Dark Mode support for comfortable viewing
– Enable/disable each feature
🔐 Two-Factor Authentication (2FA)
Enable two-factor authentication for users.
– Support for Authenticator Apps and Email OTP
– Enforce 2FA for specific user roles (e.g., Administrators)
– Recovery Codes for emergency access
– QR code setup for Authenticator Apps
🛡️ Vulnerability Checker
Automatically scan your installed plugins, themes, and WordPress core against a known vulnerability database.
– Daily automatic scans
– Alerts for critical security issues
– Check file integrity
🖥️ User Session Management
Monitor and control active user sessions to prevent unauthorized access.
– View Active Sessions: See IP, location, device, and login time for all logged-in users.
– Remote Logout: Instantly log out suspicious sessions or all other devices.
– Idle Timeout: Automatically log out inactive users after a set period.
🧱 Hardening & Firewall
Essential security hardening to lock down your WordPress site.
– Disable XML-RPC: Prevent remote attacks and brute-force attempts.
– Disable File Editor: Stop file modifications from the dashboard.
– Hide WP Version: Obscure your WordPress version from attackers.
– Block User-Agents: Prevent bad bots and scrapers from accessing your site.
– Disable User Enumeration: Stop attackers from harvesting usernames via REST API.
📝 Activity Audit Log
Keep a record of important security events on your site.
– Tracks logins, failed attempts, file changes, and settings updates.
– View user, IP, and event details.
– Configurable log retention policy.
🏥 Security Health Check & One-Click Secure
Get an instant overview of your site’s security posture.
– Security Score: View your overall protection percentage and grade (A+ to F).
– Health Dashboard: See which security features are active and which need attention.
– One-Click Secure: Apply recommended security settings instantly.
– 11 Security Checks: Comprehensive analysis of your security status.
🛡️ Advanced Firewall (IPS)
Proactive intrusion prevention system that blocks malicious requests in real-time.
– SQL Injection Protection: Detect and block SQLi attacks automatically.
– XSS Prevention: Stop cross-site scripting attempts.
– LFI Protection: Prevent local file inclusion attacks.
– Pattern Matching: Advanced regex-based detection for common attack vectors.
– Automatic Blocking: Suspicious requests are blocked before they reach WordPress.
🌍 IP & Country Management
Control access to your site with granular IP and geographic filtering.
– IP Whitelist: Allow trusted IPs to bypass all security filters.
– IP Blacklist: Block malicious IPs permanently from your site.
– CIDR Support: Use CIDR notation for blocking entire IP ranges (e.g., 192.168.1.0/24).
– Country Blocking: Block access from 90+ countries using GeoIP lookup.
– Smart Caching: GeoIP lookups are cached for 24 hours for optimal performance.
– Private IP Detection: Automatically skip local/private IPs.
⚡ Lightweight & Minimal
Designed to deliver maximum security with minimal code. No bloat, no complexity.
– Compatible with most WordPress themes and plugins.
External Services
This plugin utilizes the WPVulnerability API to check for vulnerabilities.
– Service: WPVulnerability
– Data: Only plugin slugs and versions are sent. No personal data is collected.
Installation
- Upload the
nhrrob-secureplugin folder to your/wp-content/plugins/directory. - Activate the plugin through the ‘Plugins’ menu in WordPress.
- Navigate to Tools → NHR Secure to configure settings.
Frequently asked questions
How do I access the settings page?
Navigate to Tools → NHR Secure in your WordPress admin dashboard.
Does it limit login attempts?
Yes. Repeated failed login attempts from the same IP will be temporarily blocked to prevent brute-force attacks. You can configure the limit (1-20 attempts) from the settings page.
What is the default custom login URL?
The default custom login URL is /hidden-access-52w. You can change this in the settings page under Tools → NHR Secure.
How does 2FA work?
2FA (Two-Factor Authentication) adds an extra layer of security to your WordPress site. When enabled, users must enter a code from their 2FA app (e.g., Google Authenticator, Authy) in addition to their username and password to log in.
Can I disable specific features?
Yes. You can enable or disable each feature from the settings page under Tools → NHR Secure.
Changelog
This is the initial release. Feel free to share any feature request at the plugin support forum page.
1.3.3 – 25/09/2026
- WordPress tested up to version is updated to 7.1
1.3.2 – 09/05/2026
- WordPress tested up to version is updated to 7.0
- Few minor bug fixes & improvements
1.3.1 – 07/02/2026
- Fixed: Forced logout issue for 2FA users
1.3.0 – 28/01/2026
- Added: Security Health Check with scoring system (A+ to F grade)
- Added: One-Click Secure feature to apply recommended settings instantly
- Added: Advanced Firewall (IPS) with real-time protection against SQL Injection, XSS, and LFI attacks
- Added: IP Management with Whitelist and Blacklist (CIDR support)
- Added: Country Blocking for 90+ countries using GeoIP lookup with caching
- Improved: Dark mode styling for all components
- Improved: Overall security dashboard UI/UX
1.2.0 – 17/01/2026
- Added: User Session Management (View active sessions, remote logout, idle timeout)
- Added: Hardening & Firewall (Disable XML-RPC, File Editor, Version Hiding, User Enumeration)
- Added: User-Agent Blocking
- Added: Audit Logs for security events
- Fixed: Dark mode improvements
- Improved: UI enhancements
1.1.0 – 13/01/2026
- Added: Vulnerability Checker
- Added: File Scanner to check file integrity
- Improved: UI for scan results
- Few minor bug fixing & improvements
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best NHR Secure alternatives
All 2FA plugins →FAQ
NHR Secure: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 29, 2026
Is NHR Secure free?
Yes. NHR Secure is free to download and use from the official WordPress.org plugin directory.
Is NHR Secure safe to use in 2026?
NHR Secure is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 4 days ago, and scores 64/100 on our health check.
How many websites use NHR Secure?
NHR Secure is active on <10 WordPress websites and has been downloaded 863 times since it launched in December 2025. It was downloaded 130 times in the last 30 days.
Does NHR Secure work with WordPress 7.1?
Yes. The developer has tested NHR Secure up to WordPress 7.1.2, the latest release. It requires WordPress 6.0 or newer.
What PHP version does NHR Secure need?
NHR Secure requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was NHR Secure last updated?
The latest version, 1.3.3, was released on September 25, 2026 (4 days ago).
Who makes NHR Secure?
NHR Secure is developed and maintained by Nazmul Hasan Robin.
What are the best alternatives to NHR Secure?
The most popular alternatives to NHR Secure are Wordfence Security (5M+ installs), Really Simple Security (3M+ installs) and Limit Login Attempts Securi… (1M+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card








