OWASP User Location Check

Sends warning notification to user's email if someone logs in to user's account from another country within 2 hours of last login session.

Author:Off-Site Services, Inc. (profile at wordpress.org)
WordPress version required:3.0.1
WordPress version tested:5.7.11
Plugin version:1.1
Added to WordPress repository:04-01-2016
Last updated:07-04-2021
Warning! This plugin has not been updated in over 2 years. It may no longer be maintained or supported and may have compatibility issues when used with more recent versions of WordPress.
Rating, %:0
Rated by:0
Plugin URI:
Total downloads:880
plugin download
Click to start download

How does it work?
Every time when user attempts to log in to WordPress CMS, OWASP security plugin receives and stores information about the user’s country. That information comes from ipinfo.io, an external service which provides available information on user’s IP address and does not in any way compromise WordPress security. Once the country of attempted login is identified, the plugin compares current locations with that of the previous successful CMS login within the last 2 hours. If country is different, the plugin flags it as unauthorized login attempt and sends notification to OWASP manager, with recommendation to change CMS password. Email address for OWASP manager is identified in plugin settings as “Notification email”.


ChangeLog