Protect privileged access

Defend the login—and what happens after it.

Nexus combines shared-network-aware login protection, administrator TOTP two-factor authentication, recovery controls and privilege-state monitoring across the WordPress admin lifecycle.

Login GuardShared-network awareTOTP 2FARecovery codes
IDENTITY DEFENCEGUARD ACTIVE
Login pressureRepeated authentication failures contained
TOTP verifiedAdministrator second factor accepted
Role protectionSensitive privilege state remains visible

Shared-network-aware Login Guard

Separate public-IP pressure from browser and target-account evidence so one carrier-grade NAT address is not treated as one human identity.

Authenticator-app TOTP

Administrators can verify a time-based one-time password before TOTP is activated, with recovery codes available for controlled recovery.

Privilege visibility

Administrator creation, role changes and suspicious privilege state remain part of the security evidence rather than disappearing after login.

Beyond failed-login counters

The IP address is only one part of an authentication story.

Nexus considers the targeted account, browser continuity, failed-authentication evidence and network pressure separately. This is especially important on mobile and shared networks where many legitimate users can appear behind one public address.

  • Shared-network-aware login pressure
  • Target-account and browser evidence
  • Administrator TOTP authenticator-app support
  • Recovery codes and administrative reset controls
  • Email-code verification retained where configured
  • Successful login and manual clearing remove stale pressure state
Capability map

Identity defence for real WordPress operating conditions.

Protect the password boundary, strengthen administrator verification and retain evidence around privilege changes.

Login Guard

Escalate temporary protection from real failed authentication evidence rather than ordinary page navigation.

  • Failed-auth evidence
  • Target-account context
  • Manual clear

Shared-network intelligence

Use privacy-preserving browser continuity alongside public-IP pressure so mobile and CGNAT users can remain independent.

  • Site-scoped identity
  • Network contention
  • Threat confidence separated

Administrator TOTP 2FA

Verify an authenticator-app code before activation and provide recovery codes for safe account recovery.

  • Verification before enable
  • Recovery codes
  • Admin reset

Privilege-state protection

Keep sensitive administrator creation and role changes visible to the wider Nexus evidence system.

  • Role context
  • Admin-state evidence
  • Recovery connection
Operational flow

Protect entry, verification and privilege state.

Authentication security should remain careful even when network conditions are messy.

01

Observe

Real login failures, targets and browser/network context are recorded.

02

Escalate

Temporary restrictions are applied to the most defensible identity scope first.

03

Verify

Administrators can complete TOTP or the configured second-factor flow.

04

Recover

Recovery codes, administrative reset and evidence-preserving controls keep lockout risk manageable.

What Nexus does

Strengthen privileged access without punishing shared networks.

  • Separate browser/account evidence from public-IP pressure
  • Verify TOTP before activation
  • Provide recovery codes
  • Clear stale pressure after successful authentication
What Nexus avoids

Create a new lockout problem.

  • Treat My Account navigation as failed login pressure
  • Block an entire mobile network after one user fails
  • Enable TOTP before verification succeeds
  • Silently fall back to a weaker factor
Feature questions

What buyers usually want to know.

Does Nexus support authenticator apps?

Yes. Nexus PRO supports administrator TOTP using standard authenticator apps, with verification before activation and recovery codes.

What happens on a shared 5G or office network?

Nexus separates public-IP pressure from browser and target-account evidence, so one noisy actor does not automatically turn every user behind that address into the same attacker.

Is email-code 2FA still available?

Yes where configured. TOTP is the stronger authenticator-app option, while email-code verification remains a separate supported path rather than a silent fallback.

Can an administrator recover if TOTP is lost?

Recovery codes and administrative reset controls are provided for controlled recovery.

Lumiverse Nexus PRO

Protect the identity that controls the whole site.

Login Guard and administrator two-factor authentication are included in Nexus PRO.