Protect privileged access

Defend the login—and what happens after it.

Nexus combines authentication pressure detection, enumeration controls, administrator email 2FA, role protection and optional session-risk checks across the privileged-access lifecycle.

Login Attack ModeDistributed spray detectionAdmin email 2FARole protection
IDENTITY DEFENCEGUARD ACTIVE
Password sprayingRepeated identity targeted across sources
VerificationAdministrator code required
Role protectionRisky promotion rejected

Login Attack Protection

Detect concentrated and distributed authentication pressure with identity-aware context.

Administrator 2FA

Add a deliberate email verification step after the correct password for administrator access.

Privilege protection

Make hidden administrator creation and suspicious role promotion harder to conceal.

Beyond failed-login counters

One attacker identity can move across many IP addresses.

Nexus watches the account being targeted, the source distribution and the surrounding authentication surfaces instead of relying only on a simple per-IP limit.

  • Per-IP and multi-source login pressure
  • User-enumeration and safer login-error controls
  • Compatibility-aware XML-RPC protection
  • Optional administrator session-risk checks
Capability map

Identity-aware WordPress defence.

The module covers entry pressure, second-step verification and privilege state after login.

Login Attack Mode

Escalate protection during repeated failures and concentrated authentication pressure.

  • Per-IP attempts
  • Temporary mode notices
  • Reviewable events

Distributed password spraying

Correlate repeated targeting of the same username or email across multiple source addresses.

  • Identity target context
  • Multi-source window
  • Reduced per-IP blind spot

Administrator email 2FA

Send a one-time code after the password step for administrators when explicitly enabled.

  • Delivery test first
  • Administrator-only scope
  • Visible readiness state

Administrator Role Protection

Evaluate account creation and role-promotion context before accepting a high-risk administrator change.

  • Approved admin flows
  • Suspicious promotion rejection
  • Event evidence
Operational flow

Protect entry, verification and privilege state.

Authentication security continues after the password has been accepted.

01

Watch

Login failures, identity targets and legacy authentication routes are observed.

02

Escalate

Nexus activates temporary protection when the pattern crosses configured confidence.

03

Verify

Administrators complete the optional second verification step.

04

Guard

Role changes, hidden administrators and sensitive session actions remain visible.

What Nexus does

Make privileged access harder to steal and hide.

  • Track repeated identities across sources
  • Test email delivery before 2FA enforcement
  • Keep advanced session controls optional
  • Preserve role-change evidence
What Nexus avoids

Create a new lockout problem.

  • Force 2FA before delivery is verified
  • Apply administrator friction to customers by default
  • Disable XML-RPC blindly where it is required
  • Treat every legitimate admin action as privilege escalation
Feature questions

What buyers usually want to know.

Does email 2FA replace the password?

No. The normal WordPress password is verified first, then the administrator completes the additional email-code step.

Is 2FA forced on every user role?

The current administrator email 2FA is focused on the highest-risk administrator role.

Can Nexus detect hidden administrator accounts?

The scanner and administrator-protection workflows inspect role and capability data directly, including persistence patterns that malicious filters may try to hide.

Is Admin Session Guard enabled by default?

No. It is an advanced optional control because sensitive-action checks can be compatibility-dependent.

Lumiverse Nexus PRO

Protect the identity that controls the whole site.

Login Guard, administrator 2FA and privilege protection are included in Nexus PRO.