Vegestic – Users Login Limit

Changelog

1.0.1

  • Security: Geo-location transients are now only created for valid, publicly routable IP addresses. Private, reserved, and localhost IP addresses are resolved as “Local Network” without writing a transient, preventing any transient-flooding vector via spoofed request headers.
  • Improvement: Reduced geo-location transient lifetime from 24 hours to 12 hours, limiting stale cache exposure while preserving the lookup-reduction benefit.
  • Compliance: Updated ipwho.is and freeipapi.com third-party legal URLs to their current canonical forms in the readme.

1.0.0

  • Initial public release.
  • Session limiting per user with configurable limit.
  • Login history tracking (up to 50 records per user).
  • IP address logging on each login event.
  • Location detection via free public geo-IP APIs (ipapi.co, ipwho.is, freeipapi.com, ip-api.com).
  • Active sessions view with force-logout option.
  • Custom login block message editor.
  • CSV export of login history.
  • GDPR-compliant privacy data exporter and eraser.
  • Full i18n support with translatable strings.

Plugin Website
Visit website

Version:
1.0.1
Last Updated
July 9, 2026
Requires
WordPress 5.8
Tested Up To
WordPress 7.0
Requires PHP
7.4

Share Post

Join our newsletter.

Get insights into what’s happening at ChangelogWP right in your inbox. We don’t believe in spam.