=== LyoGate — Login Security ===
Contributors: andresitaly
Tags: login, security, captcha, brute force, custom login
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

A modern, hardened WordPress login page with captcha, honeypot and brute-force protection — fully customizable, no third-party services.

== Description ==

LyoGate replaces the default WordPress login page with a modern, protected one. Everything is configured from **Settings → LyoGate**. No external accounts, no third-party services: everything runs on your own site.

**Security**

* **Arithmetic captcha** — a simple sum is required before signing in, backed by an HMAC-signed token with expiry (10 minutes): the answer never travels in clear text and is never stored in the database.
* **Per-IP brute-force lockout** — after N failed attempts (default 5) the IP address is locked out for X minutes (default 15). Wrong captcha and honeypot hits count too; a successful login resets the counter. The lockout applies even with correct credentials.
* **Honeypot** — a field hidden from humans: whoever fills it in is a bot and gets rejected without hints.
* **Unified error messages** — no username enumeration: "unknown user" and "wrong password" produce the same generic message.
* **Reduced attack surface** — XML-RPC disabled, X-Pingback header removed, public REST user endpoints removed (they remain available to users who can edit posts, for the block editor), and `?author=N` requests plus author archives redirect to the home page: no username scraping.

**Customizable appearance**

* Title, subtitle and footer message
* Custom logo from the media library, with a configurable clickable link (empty = site home)
* Two Google Fonts to choose from: Syne, Instrument Sans, Inter, Space Grotesk, Manrope, DM Sans, Outfit, Sora, Archivo, Playfair Display and JetBrains Mono (one for headings, one for body text)
* Three colors: background, text and accent (buttons and focus)

**Compatibility**

* The security gate runs as a late filter on the `authenticate` flow: captcha and lockout always take precedence over valid credentials. The gate only acts on the wp-login.php form: XML-RPC is disabled entirely while LyoGate is active, and application password / REST requests follow the normal WordPress flow (should another plugin re-enable XML-RPC, its authentication is not intercepted by the captcha).
* All settings live in a single database option; on uninstall, options and transients are removed (also on multi-site).

== Installation ==

1. Upload the `lyogate` folder to `/wp-content/plugins/`, or install the ZIP via Plugins → Add New → Upload Plugin.
2. Activate the plugin.
3. Go to **Settings → LyoGate** to pick title, logo, fonts and colors.
4. Open your login page: the new look and the protection are already active.

== Frequently Asked Questions ==

= Can I disable the captcha? =

Yes: in **Settings → LyoGate** untick "Anti-robot captcha". Honeypot and brute-force lockout stay active.

= Am I locked out myself? =

The lockout is per IP address and expires on its own (default 15 minutes). A successful login resets the counter immediately. With WP-CLI: `wp transient delete --all` also clears lockouts.

= Does it work with application passwords or mobile apps? =

Yes: the captcha and lockout only act on the wp-login.php form. XML-RPC is disabled while LyoGate is active, so XML-RPC logins cannot happen at all; requests authenticated via REST or application passwords follow the normal WordPress flow.

= Does it add cookies or interfere with other plugins? =

No. LyoGate only touches the login form authentication flow and the appearance of the login page; no extra cookies, no tracking.

= Does it work on multi-site? =

Yes, and on uninstall it cleans up options on every site in the network.

== Screenshots ==

1. The login page with the default dark theme, captcha and subtitle.
2. The configuration screen in Settings → LyoGate.
3. The lockout message after too many failed attempts.

== Changelog ==

= 1.0.0 =
* First public release: arithmetic captcha with HMAC token, honeypot, per-IP brute-force lockout, unified anti-enumeration errors, protected XML-RPC and REST user endpoints, customizable appearance (logo, fonts, colors) under Settings → LyoGate.