Shared-network-aware Login Guard
Separate public-IP pressure from browser and target-account evidence so one carrier-grade NAT address is not treated as one human identity.
Nexus combines shared-network-aware login protection, administrator TOTP two-factor authentication, recovery controls and privilege-state monitoring across the WordPress admin lifecycle.
Separate public-IP pressure from browser and target-account evidence so one carrier-grade NAT address is not treated as one human identity.
Administrators can verify a time-based one-time password before TOTP is activated, with recovery codes available for controlled recovery.
Administrator creation, role changes and suspicious privilege state remain part of the security evidence rather than disappearing after login.
Nexus considers the targeted account, browser continuity, failed-authentication evidence and network pressure separately. This is especially important on mobile and shared networks where many legitimate users can appear behind one public address.
Protect the password boundary, strengthen administrator verification and retain evidence around privilege changes.
Escalate temporary protection from real failed authentication evidence rather than ordinary page navigation.
Use privacy-preserving browser continuity alongside public-IP pressure so mobile and CGNAT users can remain independent.
Verify an authenticator-app code before activation and provide recovery codes for safe account recovery.
Keep sensitive administrator creation and role changes visible to the wider Nexus evidence system.
Authentication security should remain careful even when network conditions are messy.
Real login failures, targets and browser/network context are recorded.
Temporary restrictions are applied to the most defensible identity scope first.
Administrators can complete TOTP or the configured second-factor flow.
Recovery codes, administrative reset and evidence-preserving controls keep lockout risk manageable.
Yes. Nexus PRO supports administrator TOTP using standard authenticator apps, with verification before activation and recovery codes.
Nexus separates public-IP pressure from browser and target-account evidence, so one noisy actor does not automatically turn every user behind that address into the same attacker.
Yes where configured. TOTP is the stronger authenticator-app option, while email-code verification remains a separate supported path rather than a silent fallback.
Recovery codes and administrative reset controls are provided for controlled recovery.
Login Guard and administrator two-factor authentication are included in Nexus PRO.