Title: DCI Admin Security
Author: DreamCode Infotech
Published: <strong>2026년 10월 1일</strong>
Last modified: 2026년 10월 1일

---

플러그인 검색

![](https://ps.w.org/dci-admin-security/assets/banner-772x250.png?rev=3723214)

![](https://ps.w.org/dci-admin-security/assets/icon-128x128.png?rev=3723214)

# DCI Admin Security

 작성자: [DreamCode Infotech](https://profiles.wordpress.org/dreamcodeinfotech/)

[다운로드](https://downloads.wordpress.org/plugin/dci-admin-security.1.0.0.zip)

 * [세부사항](https://ko.wordpress.org/plugins/dci-admin-security/#description)
 * [평가](https://ko.wordpress.org/plugins/dci-admin-security/#reviews)
 *  [설치](https://ko.wordpress.org/plugins/dci-admin-security/#installation)
 * [개발](https://ko.wordpress.org/plugins/dci-admin-security/#developers)

 [지원](https://wordpress.org/support/plugin/dci-admin-security/)

## 설명

Protect WordPress login and wp-admin with IP allowlisting, custom login URLs, email
OTP, rate limiting, CAPTCHA, logging and alerts.

### Features

 * Allow exact IPv4/IPv6 addresses and CIDR ranges.
 * Accept IPv4 shorthand such as `171.61`, stored as `171.61.0.0/16`.
 * Change the WordPress login URL.
 * Protect the normal `wp-login.php` endpoint.
 * Restrict `wp-admin` by IP while keeping `admin-ajax.php` available.
 * Optional Cloudflare `CF-Connecting-IP` detection.
 * Optional trusted `X-Forwarded-For` detection for known reverse-proxy setups.
 * Optional localhost/loopback bypass for local development.
 * Brute-force rate limiting and temporary lockouts.
 * Email OTP verification for administrators, delivered to each administrator’s 
   WordPress profile email address.
 * Administrator-configured emergency fallback code for environments where email
   cannot be delivered.
 * Optional Google reCAPTCHA v2, reCAPTCHA v3 or hCaptcha on the WordPress login
   form.
 * Security event logging with an administrator viewer and configurable retention.
 * Optional email and Slack alerts for repeated blocked-IP or brute-force events.

### Important

Keep at least one known administrator IP in the allowlist before enabling IP protection.

Only enable Cloudflare IP detection when the site is actually behind Cloudflare.
Only enable trusted `X-Forwarded-For` when the server is behind a trusted reverse
proxy that sets that header.

On localhost, PHP commonly sees `127.0.0.1` or `::1` rather than the browser’s public
VPN address. Use a publicly reachable staging site for an end-to-end VPN IP test.

The emergency fallback code is stored as a password hash and is never displayed 
after saving.

### External Services

This plugin can optionally communicate with third-party CAPTCHA verification services
when CAPTCHA is enabled:

 * Google reCAPTCHA: the login page loads Google reCAPTCHA assets and sends the 
   submitted CAPTCHA token to Google’s verification endpoint. See https://policies.
   google.com/privacy and https://policies.google.com/terms.
 * hCaptcha: the login page loads hCaptcha assets and sends the submitted CAPTCHA
   token to hCaptcha’s verification endpoint. See https://www.hcaptcha.com/privacy
   and https://www.hcaptcha.com/terms.

The plugin does not contact these services when CAPTCHA is disabled.

### IP access examples

Exact IP: `186.189.26.220`

IPv4 /16 shorthand: `171.61`

CIDR: `171.61.0.0/16`

### Email OTP

After a successful WordPress administrator password check, a six-digit OTP is generated
and sent to that administrator’s WordPress profile email address.

If email delivery is unavailable, an administrator-configured emergency fallback
code can be used.

## 스크린샷

[[

[[

[[

## 설치

 1. Upload the plugin ZIP from Plugins > Add New > Upload Plugin.
 2. Activate DCI Admin Security.
 3. Open Settings > DCI Admin Security.
 4. Add at least one IP address or CIDR range that should be allowed to reach the protected
    login/admin area.
 5. Set the custom login slug.
 6. Save the General settings.
 7. Test the custom login URL before enabling strict IP protection on a production 
    site.
 8. Configure Email OTP, CAPTCHA, rate limiting and alerts as required.

## 후기

이 플러그인에 대한 평가가 없습니다.

## 기여자 & 개발자

“DCI Admin Security”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에
기여하였습니다.

기여자

 *   [ DreamCode Infotech ](https://profiles.wordpress.org/dreamcodeinfotech/)

[자국어로 “DCI Admin Security”(을)를 번역하세요.](https://translate.wordpress.org/projects/wp-plugins/dci-admin-security)

### 개발에 관심이 있으십니까?

[코드 탐색하기](https://plugins.trac.wordpress.org/browser/dci-admin-security/)는,
[SVN 저장소](https://plugins.svn.wordpress.org/dci-admin-security/)를 확인하시거나,
[개발 기록](https://plugins.trac.wordpress.org/log/dci-admin-security/)을 [RSS](https://plugins.trac.wordpress.org/log/dci-admin-security/?limit=100&mode=stop_on_copy&format=rss)
로 구독하세요.

## 변경이력

#### 1.0.0

 * Resolved Plugin Check database-query and nonce warnings.
 * Sanitized emergency fallback-code input.
 * Added explicit versions to CAPTCHA provider scripts.
 * Kept IP allowlist, email OTP, and WordPress.org compatibility fixes from 1.0.0.

#### 1.0.0

 * Removed the obsolete TOTP/two-factor authentication implementation and related
   files.
 * Fixed WordPress coding-standard issues in IP handling, AJAX actions, CAPTCHA 
   output and custom database queries.
 * Added proper login CAPTCHA script enqueueing and a CAPTCHA nonce.
 * Improved PHP 7.4 compatibility by removing PHP 8-only string helper usage.
 * Updated documentation and feature list for the email OTP implementation.

#### 2.4.10

 * Improved IP allowlist matching and localhost development controls.
 * Added IP diagnostics and test tools.

#### 2.4.6

 * Added explicit trusted proxy handling for `X-Forwarded-For`.
 * Normalized IPv4-mapped IPv6 client addresses.

#### 2.0.0

 * Added brute-force rate limiting, CAPTCHA, security logging and alerts.
 * Added administrator email OTP verification.

#### 1.0.0

 * Initial release with IP allowlist and custom login URL protection.

## 기초

 *  버전 **1.0.0**
 *  최근 업데이트: **3일 전**
 *  활성화된 설치 **10보다 적음**
 *  워드프레스 버전 ** 6.0 또는 그 이상 **
 *  다음까지 시험됨: **7.1.2**
 *  PHP 버전 ** 7.4 또는 그 이상 **
 *  언어
 * [English (US)](https://wordpress.org/plugins/dci-admin-security/)
 * 태그:
 * [admin security](https://ko.wordpress.org/plugins/tags/admin-security/)[custom login](https://ko.wordpress.org/plugins/tags/custom-login/)
   [ip whitelist](https://ko.wordpress.org/plugins/tags/ip-whitelist/)[login security](https://ko.wordpress.org/plugins/tags/login-security/)
   [security](https://ko.wordpress.org/plugins/tags/security/)
 *  [고급 보기](https://ko.wordpress.org/plugins/dci-admin-security/advanced/)

## 평점

아직 제출된 리뷰가 없습니다.

[Your review](https://wordpress.org/support/plugin/dci-admin-security/reviews/#new-post)

[모든  리뷰 보기](https://wordpress.org/support/plugin/dci-admin-security/reviews/)

## 기여자

 *   [ DreamCode Infotech ](https://profiles.wordpress.org/dreamcodeinfotech/)

## 지원

할 말 있으신가요? 도움이 필요하신가요?

 [지원 포럼 보기](https://wordpress.org/support/plugin/dci-admin-security/)

## 기부

이 플러그인이 발전하도록 도우시겠습니까?

 [ 이 플러그인에 기부하기 ](https://ko-fi.com/dreamcodeinfotech)