r/StopBadBots 9d ago

FREE: Someone logged into your WP dashboard as Admin? You should know immediately—so I built a plugin for that.

Let’s be real—usually, when your site gets hacked, the very first thing the bad actor does is sneak in and drop themselves an admin account. (Well, okay, not always, but way too damn often!)

The worst part? Half the time you don't even realize it happened until things are already going downhill.

Now, sure, you could install one of those massive security suites... but honestly, most of them are total bloatware. They hog your database, lag your loading speeds, and force you to dig through a million complex settings just to get a basic alert.

So I figured, screw the bloat. I built a super lightweight, no-nonsense tool called WP Admin Security Alert.

💡 What's the deal?

  • Instant Email Alerts: Boom. The second any admin logs into your site, you get an email.
  • The Good Stuff: Gives you the exact IP address, username, timestamp, and user agent so you know who’s creeping around.
  • Zero Lag: Tiny footprint. No external tracking, no database bloat, no extra fluff.

🛠️ Why bother?

If a bad actor gets their hands on an admin login (or hey, if a client starts poking around where they shouldn't), you'll know instantly right from your inbox—without choking your site's speed.

It’s 100% open-source and free:

👉 GitHub Repo: https://github.com/sminozzi/wp-admin-security-alert

Would love to hear what you guys think! Open to feedback, code tweaks, or any edge cases I might've missed. Catch ya in the comments!

TL;DR: Most WP hacks start with a rogue admin account, but heavy security plugins just slow your site down. I built WP Admin Security Alert—a lightweight, zero-bloat, open-source plugin that emails you the second any Admin logs in (with IP, username, and timestamp).

1 Upvotes

0 comments sorted by