This plugin hasn’t been tested with the latest 3 major releases of WordPress. It may no longer be maintained or supported and may have compatibility issues when used with more recent versions of WordPress.

Barbwire Security


This plugin enhances the WordPress security.
Effective such as the brute force attack.
Includes the following specific functions.

1.Google reCaptcha v3 protect login screen from bot attacks.

2.Change the URL of the login screen, to avoid attacks on the login screen.
You can ward off tying for try to login for cracking, such as Brute-force attack.
Adding parameter to login URL so that default login url will hidden.

3.Block the display of author archive page
WordPress leaks your login id because of redirect author archive page by author id to login id.
(If you enter “your-site-url/?author=1”, you can try it.)
Simply hideing author archive page so that block to leak login id.

4.To limiting the part of the XML-RCP feature prevents the attack.
Block DDOS attacks against other sites with yor WordPress site, pingback enabled.
Block login via XML-RPC.

5.Disable the REST API function and reduce the risk of receiving external attacks.
You can disable all REST APIs and you can partially disable them.
(This feature will be removed in version 2.1.)

These features will be able to choose whether or not to enable.

This plug-in does not change the .htaccess
You can use with confidence.
Also it works in both Apache and nginx.

(photo by Keoni Cabral


  • Setting

  • Setting

  • Help


  1. Install and activate the plugin through the ‘Plugins’ menu in WordPress.
  2. Go to Settings > Barbwire Security.
  3. Perform the necessary settings and press the Save button.


April 27, 2020
ダミーurlにnoindexがついてないので、被リンクされると、サイト内検索と同等のSEOリスクがある。 当方重たいSEO系プラグインは使わないので、noindex追加が欲しいところ。
Read all 2 reviews

Contributors & Developers

“Barbwire Security” is oopbron sagteware. Die volgende mense het bygedra tot die ontwikkeling van hierdie uitbreiding:


“Barbwire Security” has been translated into 1 locale. Thank you to the translators for their contributions.

Translate “Barbwire Security” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.



fix error message to be displayed once even when the reCaptcha key was correct.
update disabling only XML-RCP pingback to disabling pingback and login.
fix typo


add Google reCaptcha v3 protect login screen from bot attacks.


add parameter to logout url

update renew readme.txt and plugin file header.
update move the translation from mo files to Polyglots

fix From version, part of the login URL change function was not working properly.
update do refactor
fix documentation

update remove unused code.

update replace deprecated action hook.

fix bug for subdirectory type WordPress.


update For WordPress 5.3

fix Fetal error.


fix Bug prevent access to password-protected content.


fix Error when the version of WordPress does not support REST API.


fix Error on setting screen in Version 4.6.x or earlier.


change Possible to finely set the restriction of REST API
change Move menu to submenu of option
fix Remove Notice Error in setting page
add Link to setting page to plugin list page
Specify support for version 4.9




fix settings page duplication
Specify support for version 4.8.2


Add new function, Disable the REST API
Refactor source codes


fix readme.txt


fix disnable pingback function was not working
add function block the display of author archive page
add help documentation


fix login page will divulge, when using Permalink settings
Thanks to @nyarocom pointed out.(


fix php warning message


fix error error of removing the plugin


First release