Stop account sharing on your WordPress membership site
One login per account at a time, lockouts after failed attempts, two-factor codes by email or SMS and a hidden WordPress login. Paid access stays with the people who paid.
One account, one person at a time
Cheat Off allows one active login per account. When the same account logs in somewhere else, the earlier session ends.
Block guessing before it works
Security Login blocks an IP address after too many failed attempts. Included in every plan.
A code on top of the password
With Full Package, members enter a code sent by email or SMS after their password.
Keep fake sign-ups out
Hide wp-login.php from visitors
With Full Package, Hidden WP Login sends visitors who open wp-login.php to your own login page instead.
How each tool behaves
So you can explain it to members before they ask.
Questions about login security
Not sure your setup is covered? Search the documentation or try the live demo before you buy.
How do I stop members sharing one account?
Turn on Cheat Off. Each account can be logged in in one place at a time, and a new login ends the earlier session. It’s included in every plan.
Does Cheat Off block the second login?
No. It lets the new login in and logs out the earlier session, then sends that person to a page you choose.
Is there two-factor authentication?
Yes, with Full Package. Members enter a code sent by email, SMS or both after their password.
Which SMS providers can send login codes?
TeleSign, BulkSMS, Messente, InfoBip and ClickSend.
Can I limit failed login attempts?
Yes. Security Login blocks an IP address after the number of failed tries you set, for as long as you set. It’s included in every plan.
Can I stop spam sign-ups?
Yes. Use reCAPTCHA, email verification, an email blacklist and manual approval in every plan. With Full Package, block disposable emails and hide the form from chosen IP addresses.
Keep paid access with the people who paid
One login at a time, lockouts and two-factor codes for your membership site.

