WordPress login alert plugin

Know every login. Stop the wrong one.

A WordPress login alert plugin that emails you on each login, with a one-click button to log the user out and suspend them.

WordPress login alert plugin login history with IP, location, device and actions
A login alert email with user and login details

Email alerts

A WordPress login notification email, with buttons

Who, when, where and on what device. Force Logout & Suspend, or Mark as Safe.

  • Signed links
  • Expire in 10–60 min
  • Rate-limited
  • Custom subject
Login alert email with Force Logout & Suspend and Mark as Safe

History

Full WordPress login history

Every login with role, IP, city, device and the action taken. Search and filter by role.

  • IP and location
  • Device and browser
  • Retention 7 days to 1 year
Login history table with filters

Rules

Alerts only for the logins you care about

Pick roles to watch, exclude others, and mark people as trusted or high-risk.

  • By role
  • Trusted users
  • High-risk users
  • Several recipients
Secure Login Monitor settings

Built in

Force logout and suspend a WordPress user in seconds

Ends every session

All the user's sessions are destroyed at once.

Blocks sign-in

Suspended users cannot log back in.

Suspended users page

See and lift suspensions in one place.

Signed action links

HMAC-SHA256 tokens that expire.

Optional geolocation

City and country for each login.

Bulk actions

Suspend or unsuspend from the Users list.

Pricing

Free to use

Secure Login Monitor

Free

  • Login alert emails
  • One-click logout and suspend
  • Login history with filters
  • Role and per-user rules
  • Self-hosted on your WordPress
Get Secure Login Monitor

FAQ

WordPress login alert plugin FAQ

How do I get an email when someone logs into WordPress?

Install Secure Login Monitor, add the recipient emails in Secure Login → Settings, and choose which roles to watch.

What happens when I click Force Logout & Suspend?

Every session of that user ends and the account is suspended, so they cannot sign in again until you lift it.

Are the email links safe?

Each link is signed with HMAC-SHA256 using your site's salt and expires after 10 to 60 minutes.

Will I get flooded with emails?

No. Alerts are rate-limited per user, and you can skip roles or mark people as trusted.

Does it record login history?

Yes. Each login is logged with role, IP, device and, optionally, location. Old records are deleted after the period you choose.

Is it free?

Yes. The plugin is free.

Catch the login that isn't theirs