
Developed by ncdLabs.
Control access to a whole WordPress site or only the parts that need protection. Create ordered policies for domain names and URL paths, then decide whether visitors can enter with a shared password, a WordPress login, or both. Everything is managed in WordPress — no web-server rules required.
A practical fit for
- Staging sites and client previews
- Private company or team sites
- Protected sections within an otherwise public site
- Different access requirements for different domain names or URL paths
How policies work
Each request is checked against your enabled policies in order. The first matching policy decides what access is required, so broad rules and narrow exceptions can live together without custom code.
- Choose what to protect: the entire site, an exact or wildcard domain name, or a URL path.
- Choose how visitors enter: a shared password, their WordPress login, or both.
- For WordPress users, optionally allow only selected accounts, roles, or capabilities.
- Use the simulator and analyzer to check which policy will apply, then review activity in the audit log.
Included in Free
- Unlimited policies with drag-and-drop ordering and revision history
- Whole-site, exact domain name, wildcard domain name, and URL path matching
- Shared passwords kept in a reusable password vault
- WordPress login access for selected users, roles, and capabilities
- “Any” or “all” authentication requirements
- Scheduled start and end times, plus observe-only policies
- Secure access sessions, recovery codes, an audit log, a policy simulator, and an analyzer
Premium is optional
Premium is a separate companion plugin for organizations that need passkeys, access groups, custom sign-in screens, SSO/identity providers, SCIM, agency multisite tools, and other advanced controls. The Free plugin is fully usable on its own and does not lock included features behind a license key.
Privacy and external services
By default, the plugin does not contact external services. WordPress handles its normal translation updates. Optional integrations that you configure, such as identity providers, SIEM webhooks, and cloud backups, send only the data needed for that service. Password hashes and private keys are never sent to cloud backups.
Optional deactivation feedback: if an administrator chooses to submit the optional survey when deactivating, the plugin emails the selected reason and comments to ncdLabs via the site’s WordPress mail. A separate unchecked checkbox can include plugin, WordPress, and PHP versions only — never the site URL or admin email. You can skip the survey and deactivate without sending anything.
The plugin supports WordPress’s personal-data export and erasure tools. Audit events are anonymized rather than deleted so the security record remains useful. Shared policies and credentials belonging to other users are not erased.
Screenshots

Visitor challenge — a clean password or WordPress sign-in screen for protected requests.

Policies — realistic ordered rules for a client preview, team area, and documentation path.

Policy wizard — choose scope, sign-in methods, authorized visitors, and behavior in one guided flow.

Policy Simulator — test a visitor request and see the matched policy and outcome before changing live access.

Security Dashboard — review protection health, recommendations, and recent activity from WordPress.