IronWall · A security add-on for WordPress membership sites

Logins that can't be phished.
Messages that can't be leaked.

IronWall adds heightened security to WordPress membership sites - available first for the Memberium family. TOTP two-factor with a code length you set, phishing-resistant passkeys, and end-to-end encrypted messaging. These layers protect logins and private conversations, and they run on your own server.

TOTP 2FA Passkeys Encrypted messaging Self-hosted
6–10
Maximum Strength 2FA
RSA-4096
Asymmetric keys per message
0
Plaintext secrets at rest
8
Encrypted recovery codes

Figures from the IronWall product spec. TOTP code length is configurable from 6 to 10 digits; GhostDrop seals each message to an RSA-4096 public key.

TOTP two-factor authentication

Codes you control, at the length you choose

IronWall generates standards-based TOTP codes from any RFC 6238 authenticator app, including Google Authenticator, Authy, 1Password, or the app built into your phone. Code length is configurable from six to ten digits, so you can trade a little convenience for a much wider brute-force margin. Five failed challenges stop the flow cold, and every member gets eight one-time recovery codes, stored encrypted, so a lost phone does not mean a lost account.

  • Code length configurable from 6 to 10 digits
  • Standards-based (RFC 6238) · works with any authenticator app
  • Five failed challenges · lockout
  • Eight one-time recovery codes · encrypted

Passkeys (WebAuthn)

Log in without a password to steal

Passkeys replace passwords with credentials bound to your site and to your members’ devices, unlocked with Touch ID, Face ID, Windows Hello, a security key, or a phone prompt. Because a passkey only works on the site it was created for, a fake login page cannot capture it. Members register, rename, and remove their own passkeys from their profile, and passkey login works from the standard WordPress screen or any frontend login form.

  • Phishing-resistant by design
  • Bound to your site · a fake page cannot capture it
  • Works on the standard screen and frontend forms
  • Registered and managed by the member

GhostDrop · zero-knowledge messaging

Messages only the recipient can read

GhostDrop lets members send each other messages your server can never read. Each message is encrypted to the recipient’s RSA-4096 public key before it leaves the sender’s device, so your server holds only the encrypted result. The recipient’s private key never leaves their device, so even a full database dump yields nothing readable. And because the plugin is self-hosted, the encryption and the keys live on infrastructure you control.

  • RSA-4096 · sealed to the recipient’s public key
  • Server stores only encrypted messages
  • Private keys stay on the member’s device
  • Self-hosted end to end

GhostDrop · the sealed channel between clients and staff

What clients tell you, in confidence

The things a client most needs to tell you - real financials, a personal situation, an account problem, a sensitive detail - are the things neither of you wants sitting in an inbox or a database where they could be found or leaked. GhostDrop seals those exchanges: each message is encrypted to the recipient’s key on the sender’s own browser before it’s sent, so nothing readable is ever left on the server. These are the situations where a sealed, staff-facing channel changes what your membership can safely handle.

  1. 01

    The numbers a client shares with their advisor

    The financial details that matter most are the last thing a client will put in a thread. They won’t post real positions, returns, or a profit-and-loss figure where anyone in the group could read them. So the conversation that would help most - with the advisor they’re paying for - is the one they can never have in the open.

    GhostDrop gives that client a sealed line to their advisor. The numbers are encrypted to the advisor’s key on the client’s own browser before they’re sent; the server carries the message but can’t read it, and nothing readable lands in a database a breach could expose. The client sends the real figure, the advisor gives real guidance, and the exchange is never left lying around.

  2. 02

    The question a client won’t ask in the open

    Clients come for help, and the help that matters is often personal. A client dealing with a health issue, a family problem, or a financial hole won’t lay it out in a thread the whole community can read - so they ask a watered-down version, take it to a stranger, or stay silent. The question that most needs an answer is the one that never gets asked publicly.

    GhostDrop gives that client a private line to the person who can help. The message is sealed to that person’s device before it leaves the client’s browser; the server can’t read it, index it, or hand it over. For a membership built on support, the ability to speak honestly to the right person - with nothing left on the record - is the whole point.

  3. 03

    The information that shouldn’t sit in an email

    Running an account sometimes means a client has to hand over information they’d rather not leave lying around - an account number, a tax detail, the terms of a contract, a piece of business information. Email is where it usually goes, and email is exactly where it stays: copied to an inbox, backed up to an archive, searchable by anyone who later gains access.

    GhostDrop is the channel for that information instead. Typed on the client’s device and sealed to the staff member’s key before it’s sent, it never exists in plaintext on the server, and there’s no mailbox or archive holding a copy a leak could surface. The details reach the person who needs them and no further.

  4. 04

    The advice that stays sold

    Paid coaching is a private conversation by definition. The coach’s advice is their craft - years of experience compressed into guidance that only works because it’s aimed at one client’s situation - and the client’s questions, plans, and numbers are theirs alone. Neither half belongs in a public archive, and neither should sit in a system someone else can read.

    Encrypted end to end, the coaching channel protects both sides. The client’s conversation is sealed to their key and read on their device; the coach’s craft can’t be scraped, re-exported, or reposted without their involvement. When the channel is visibly sealed, the client is buying discretion and the coach is protecting their craft.

  5. 05

    The support line clients don’t have to censor

    Support is the most sensitive conversation a paid membership hosts. A client disputing a charge, recovering account access, or reporting a problem is handing you the private details of their situation - and the public forum is the wrong place for any of it. An email inbox isn’t much better: the exchange lands in a record that lives in a third-party archive and stays searchable.

    For anything about money or access, clients get a private line straight to you. The message is sealed to your device before it leaves theirs; the client isn’t emailing a record that gets backed up, and you aren’t storing a conversation about their account where the whole team can read it. A private, encrypted support line is where confidence and trust get built.

  6. 06

    The first message home

    Every new client gets a first message, and it should come from you. A short welcome, sealed to the new client, shows what the private channel is for before they ever need it. Clients who arrive knowing the channel exists - and that it’s theirs - will use it; those who discover it later rarely do.

    GhostDrop makes that first contact a demonstration. The welcome arrives already encrypted, and the client’s reply is sealed on their device before it reaches you. Leading with a sealed welcome on day one makes clear that discretion is part of the arrangement from the start.

The site owner’s half

GhostDrop does the site owner a favor that is easy to miss. The server never holds a key that can open a message, so the site owner is able to host private conversations without the exposure that usually comes with them: no database field full of member conversations waiting to leak, no copy of the contents to be subpoenaed, no obligation to moderate what you cannot read, so a breach exposes nothing the server could have opened.

GhostDrop is a secure messaging system. Your forum, your email, and your support desk all carry messages you cannot see; GhostDrop is the channel where privacy is the point. Every message is sealed to the recipient’s key before it leaves the sender’s device, so it stays protected no matter what happens to the server that carries it. A leak, a subpoena, or a curious admin still cannot open it. The protection travels with the message rather than depending on the infrastructure.

The difference

Stock WordPress security vs. IronWall

WordPress core keeps the door locked, but it ships no two-factor, no passkeys, and no encrypted messaging. This is what adding IronWall changes.

Capability comparison: stock WordPress vs. IronWall
Capability Stock WordPress The IronWall difference
Two-factor authentication None built in TOTP · 6–10 digit codes, you choose
Passkeys (WebAuthn) None built in Phishing-resistant login
Encrypted member messaging None built in GhostDrop · RSA-4096, sealed end to end
Recovery when a device is lost Password reset 8 one-time codes, encrypted
Where the secrets live Your server Your browser · secrets never leave it

The login strength ladder

Some rungs hold more weight than others

Most membership sites stop at a password. The ones that go further bolt on a second factor, but the rungs are not equal, and two of them are barely a step up. Here is how the common login methods stack up, from the one everyone still uses to the one a phisher cannot touch.

  1. Passwords

    Weak

    A single reusable secret, typed into every site that asks. It can be phished, reused across a dozen sites until one leaks, or simply handed over. The door has one lock, and the key is a secret everyone shares around - sometimes on a sticky note on the monitor.

  2. SMS two-factor

    Weak

    A code texted to the member’s phone. It is a genuine second factor, which is more than a password offers, but the channel itself can be hijacked: a SIM-swap moves the number to an attacker’s device, and the code arrives there instead. NIST stopped recommending SMS for new deployments in 2017.

  3. Magic links

    Stronger

    A one-time login link emailed to the member, no password at all. Removing the password removes an entire class of theft: nothing to phish, reuse, or leak. The trade is that the whole arrangement rides on the email account; whoever has access to that inbox logs in.

  4. Email two-factor

    Stronger

    A password plus a code sent to the member’s inbox, true two-factor, and a real step up from a password alone. The weakness is the window: the code is valid for ten minutes or more, and the inbox it lands in is itself the prize an attacker is after.

  5. TOTP two-factor (authenticator app)

    Strong IronWall’s standard

    A code generated on the member’s own device from a shared secret, rotating every thirty seconds, so a captured code is stale within the minute. The secret never travels again after setup, so there is nothing to intercept. IronWall kicks it up four notches, from the six-digit default to ten, where each added digit widens the brute-force space tenfold, ten thousand times wider at the top setting. Pair that space with rate limiting that caps an account to five guesses a minute, and brute force stops being merely hard - it becomes impossible.

  6. Passkeys

    Gold standard IronWall’s standard

    A credential cryptographically bound to your site and to the member’s device, unlocked by Touch ID, Face ID, or a security key. It cannot be replayed on a fake page, because it refuses to authenticate anywhere but the site it was made for, and the private key that unlocks it never leaves the device. This is the rung a phisher cannot reach.

IronWall ships the top two rungs: TOTP two-factor with a code length you set, and phishing-resistant passkeys. The weaker rungs are the ones it replaces.

How far each key size reaches

Size Matters

Key size is a bet against time, and NIST publishes the odds. The guidance has a definite shape: the size that is respectable today, the size that stops being respectable at the end of the decade, and the size that stays respectable long after.

A bank vault door with a heavy combination dial, standing for the strength of IronWall's RSA-4096 encryption

Sensitive communications never leave the vault

NIST key-size horizons: RSA-2048 acceptable through 2030, RSA-3072 the floor after 2030, RSA-4096 with headroom well past 2030
Key size Strength NIST horizon
RSA-2048 112-bit Acceptable through 2030
RSA-3072 128-bit The floor after 2030
RSA-4096IronWall’s choice ~140-bit Headroom well past 2030

Per NIST SP 800-57 and FIPS 186-5. GhostDrop seals every message with RSA-4096.

Why three defenses

Each one covers what the others cannot

Run together, the three layers stop attacks that any single one would let through.

TOTP stops the shared password

A stolen or shared password no longer opens the door on its own. The second factor stands in the way, and at 10 digits the brute-force margin is ten thousand times wider than at 6.

Passkeys stop phishing outright

A credential that only works on your site cannot be replayed on a fake page. The best phishing email in the world cannot harvest what will not work anywhere else.

GhostDrop keeps conversations private

Encryption at the key level means server-side access and database leaks cannot expose message contents, because the server never holds a key that could decrypt them.

Mini-essay · Two-factor auth

Why a password alone was never enough

A password is a secret you carry in your head, which is exactly why it keeps failing. It can be given away by the person who holds it, typed into a phishing page that looks right, shared with a colleague, or reused across a dozen sites until one of them leaks. The breach is rarely dramatic; usually a password was stolen once and quietly worked forever after.

Two-factor authentication changes the shape of the attack. The password still proves you know something, but the door also demands something you have: a code from an app like Google Authenticator, one that rotates every thirty seconds, so a captured code is stale within the minute. A stolen password is no longer enough on its own, which is why 2FA is the most effective control most sites never turn on.

IronWall takes the standard and makes it tunable. 2FA codes run from six to ten digits, configurable per site: six for the familiar default, ten for a brute-force margin ten thousand times wider. Every member gets eight one-time recovery codes, stored encrypted, so a lost phone costs a minute and a fresh enrollment, not a support ticket.

A stolen password is only dangerous while it is sufficient to open a door. The second factor is what makes it not enough anymore.

IronWall & your site: On a Memberium site, TOTP drops straight into the existing login flow: the same member, the same session, one more step between an attacker and the door.

Mini-essay · Passkeys

The login that cannot be phished

Phishing works because passwords are portable. You type your password into a page that looks like the one you meant to visit, and the attacker now owns a credential that works on the real site, forever. Unlike other theft, which requires breaking into something, phishing simply asks for the credential.

A passkey is the opposite kind of credential. It is cryptographically bound to the site it was created for. It lives on the member’s device, unlocked by Touch ID, Face ID, Windows Hello, or a security key. A passkey created on your site will not authenticate anywhere else. The fake page can ask all it wants; the credential refuses to cooperate, so the attack stops being possible rather than getting harder.

The experience is the part that surprises people. Logging in is one tap on a device they already carry, with no password to remember and no reset flow to trigger. Registration, renaming, and removal are managed by the member from their profile, and passkey login works from the standard WordPress screen and any frontend form alike.

A password can be given away. A passkey can only be lent by the device that holds it, and the device only answers to its owner.

IronWall & your site: IronWall brings the same passkey flow to Memberium sites, so your members trade a remembered secret for a possession they already have.

Rate limiting

The guesser runs out of turns

Every attempt to verify a code is counted against the last sixty seconds, per IP address and per account. That is the sliding window: a rolling count that only sees the attempts made in the last minute, so a quiet stretch lets a member back in without anyone touching a setting. A window that only watched the IP could be dodged by rotating addresses, so the account gets a count of its own. When a limit is hit, the member is told exactly how long to wait.

The guesser runs out of turns
Scope Limit What it stops
Per IP address 10 attempts per 60 seconds One machine hammering the code
Per account 5 attempts per 60 seconds Targeted guessing that rotates IPs
Per login challenge 5 attempts, then the member starts over A single login that keeps failing

Limits are defaults, tunable per site, and they live in code rather than in the database, so nothing stored there can weaken them. Passkey logins are throttled too, at six requests per IP and five per identifier each minute. Every login has to clear several independent checks at once, and failing any one of them fails the whole login.

What’s inside

A focused security plugin, not a kitchen sink

IronWall ships one job well: defending access and private communication for WordPress membership sites.

Access security

  • TOTP 2FA with configurable 6–10 digit codes
  • Passkeys (WebAuthn): phishing-resistant login
  • Five-attempt challenge lockout
  • Rate limiting per IP and per account
  • Eight one-time recovery codes, encrypted
  • Credentials registered and managed by the member

Encrypted messaging

  • GhostDrop: end-to-end encrypted messages
  • RSA-4096 key pairs per recipient
  • Server stores only encrypted messages
  • Private keys stay on the member’s device

Hardening by default

  • Encrypts secrets at rest with a modern authenticated cipher
  • HKDF-SHA256 per-context subkeys
  • Standards-based: RFC 6238 TOTP, WebAuthn
  • No proprietary formats to lock you in

Self-hosted operations

  • Add-on for WordPress membership sites
  • Runs on your own WordPress server
  • No third-party service required
  • Installs on top of your existing Memberium setup

Setup

From add-on to enabled in three steps

IronWall installs like any WordPress plugin. Most sites are fully locked down inside an hour.

  1. Install the plugin

    Upload IronWall, activate it, and set your global defaults for 2FA, passkeys, and messaging.

  2. Dial in your security level

    Choose optional 2FA, required for admins only, or required for everyone, per membership level.

  3. Hand members the keys

    Publish the enrollment page. Members link an authenticator or create a passkey and walk away.

For developers

Standards under the hood, control on top

IronWall is ported from the Torii membership engine that powers Memberium, so the crypto is battle-tested in production before you see it. It is a bolt-on that hardens WordPress membership sites without touching how they run. No proprietary formats, no opaque magic; the pieces are named, standard algorithms with keys and configuration you own.

  • RFC 6238 TOTP and WebAuthn, with no proprietary formats
  • XChaCha20-Poly1305-IETF with HKDF-SHA256 subkeys at rest
  • Site-wide shared encryption key, with per-context subkeys
  • Recovery codes hashed with bcrypt, one-time use
  • Ported from the Torii engine, built for WordPress

Account activity

Every member gets a security ledger

Each member’s profile logs the events that matter (new devices, new credentials, changed numbers) with time, location, and device, so a member can see the story of their own account.

Sample rows from a member’s IronWall activity ledger.
When Event Location Device
Passkey created Apple iPhone · Safari Austin, TX iPhone 16
2FA enabled Authenticator linked · TOTP 8-digit Austin, TX iPhone 16
Suspicious login blocked Denied at the second factor Warsaw, PL Unknown
Recovery code used One-time code #4 redeemed Austin, TX MacBook Pro

Ledger entries are retained for 18 months. Members see only their own activity.

The password was the weakest link on the web for two decades. IronWall replaces it with something that cannot be phished, and it seals your members’ conversations behind keys your server never sees.

David Bullock Founder · Web Power & Light

FAQ

Straight answers, before you ask

Does IronWall require any new subscriptions or monthly fees?

No. IronWall is a one-time purchase and runs entirely on your own server. There is no third-party service and no per-member fee, now or later.

Will passkeys work for members on older browsers?

Passkeys are a widely supported modern standard: Safari shipped them in September 2022, Chrome and Edge followed in December 2022, and Firefox caught up in January 2024.

On a browser older than that, the passkey button will not appear, and IronWall falls back to TOTP on that device. A member who cannot use a passkey still gets full two-factor protection.

What happens if a member loses their device?

They use one of their eight one-time recovery codes to get back in, then enroll a fresh authenticator from their profile. Codes are stored encrypted, so the file on your server is not a usable list.

Can GhostDrop decrypt my members’ messages?

No. Every message is encrypted to the recipient’s RSA-4096 public key before it leaves the sender’s device. Your server stores only the unreadable encrypted result. The private key that could unlock it never leaves the member’s control. Even with full access to your database, the messages are unreadable.

Can IronWall run alongside my existing Memberium setup?

Yes. IronWall installs on top of Memberium and enhances the existing login and profile flows. Your membership levels, payments, and content rules all keep working as they do today.

Harden your site

Your WordPress, your keys, your data

IronWall is a security add-on for WordPress membership sites. Talk to us about licensing and what heightened security can do for your membership business.