Stop account sharing on your WordPress membership site

One login per account at a time, lockouts after failed attempts, two-factor codes by email or SMS and a hidden WordPress login. Paid access stays with the people who paid.

Login security for paid content
Cheat Off One account, one person
Laptop · 9:02Account: maya@example.comLogged out
Phone · 9:15Account: maya@example.comLogged in
A new login ended the earlier session and sent it to your notice page.
How it works
RuleOne login at a time per account
Earlier sessionLogged out
Sent toA page you choose
PlanEvery plan
Security Login Lock out guessing
Failed attempts allowed3
Lock time2 hours
Locks before a longer block3
Blocked IP addresses2 on the list
The settings behind it
After too many triesThe IP address is blocked
You setTries, lock time and repeat locks
MessagesYour own wording
Two-Factor Authentication Enter your login code We sent a code to your phone ending in 42.
481207
Verify and log in
The settings behind it
Codes byEmail, SMS or both
SMS throughTeleSign, BulkSMS, Messente, InfoBip or ClickSend
Code expiry10 minutes to 1 hour
PlanFull Package
Account sharing

One account, one person at a time

Cheat Off allows one active login per account. When the same account logs in somewhere else, the earlier session ends.

Logins per account1 at a time
When someone else logs inThe earlier session ends
The logged-out person seesYour notice page
Session lengthYour cookie time
Failed logins

Block guessing before it works

Security Login blocks an IP address after too many failed attempts. Included in every plan.

Tries before a lockChoose how many failed attempts an IP address gets.
Lock timeChoose how long a lock lasts, and how many locks lead to a longer one.
IP blacklistAddresses on your list can’t log in at all.
Your messagesWrite what people see after a failed try, a lock and a longer lock.
Two-factor login

A code on top of the password

With Full Package, members enter a code sent by email or SMS after their password.

Full PackageEmail, SMS or bothYou choose how codes are sent.
Full PackageFive SMS providersTeleSign, BulkSMS, Messente, InfoBip or ClickSend.
Full PackageCodes that expireSet a lifetime from 10 minutes to 1 hour, and limit how many new codes a member can ask for.
Sign-up protection

Keep fake sign-ups out

Every planreCAPTCHAGoogle reCAPTCHA on your register and login forms.
Every planEmail verificationNew members confirm their address before their account counts.
Every planEmail blacklistBlock the addresses you don’t want from registering.
Full PackageDisposable emailsBlacklist Disposable Emails blocks throwaway addresses from a built-in list, and you can add more.
Full PackageRegistration by IPIP Registration hides the sign-up form from the IP addresses you list.
Every planManual approvalNew sign-ups wait as pending until you approve them.Learn more
WordPress login

Hide wp-login.php from visitors

With Full Package, Hidden WP Login sends visitors who open wp-login.php to your own login page instead.

Visitor opens /wp-login.php→ Your login page
Your office IPWordPress login as usual
PlanFull Package
Good to know

How each tool behaves

So you can explain it to members before they ask.

Straight answers
Cheat Off ends the earlier session when a new login happens. It doesn’t stop the new login. Two-factor codes go by email or SMS. Authenticator apps aren’t supported. Hidden WP Login sends visitors to your login page. It doesn’t give WordPress a new login address. IP Registration hides the sign-up form. It doesn’t block logins from those addresses.
FAQ

Questions about login security

Not sure your setup is covered? Search the documentation or try the live demo before you buy.

How do I stop members sharing one account?

Turn on Cheat Off. Each account can be logged in in one place at a time, and a new login ends the earlier session. It’s included in every plan.

Does Cheat Off block the second login?

No. It lets the new login in and logs out the earlier session, then sends that person to a page you choose.

Is there two-factor authentication?

Yes, with Full Package. Members enter a code sent by email, SMS or both after their password.

Which SMS providers can send login codes?

TeleSign, BulkSMS, Messente, InfoBip and ClickSend.

Can I limit failed login attempts?

Yes. Security Login blocks an IP address after the number of failed tries you set, for as long as you set. It’s included in every plan.

Can I stop spam sign-ups?

Yes. Use reCAPTCHA, email verification, an email blacklist and manual approval in every plan. With Full Package, block disposable emails and hide the form from chosen IP addresses.

Cheat Off in every plan

Keep paid access with the people who paid

One login at a time, lockouts and two-factor codes for your membership site.

14-day money-back guarantee Unlimited members