A majestic castle with a guarded entrance and moat, representing secure access control

Castle Security

Your website is your castle, Your content is valuable, and your digital assets should be protected.

Zero-friction login

Members flow
Attackers hit the wall

Passwordless access for legitimate members. Invisible fraud prevention for everyone else. Remove passwords and catch the bad actors with behavior — no compromises

4min
Average setup time
0
Member passwords to remember
Legitimate users
100%
Self-hostable control

Getting members in

Friction-Free Access

Passwords are the single largest source of login friction and churn at the front door. The answer is to remove the password from the critical path, then guide new members through setup so nobody is left half-configured.

Passwordless access

Magic Links

A magic link is a one-click, passwordless login delivered by URL. A member clicks the link and they are in — no password to remember, no reset flow to trigger. Each token is short-lived by default and can be configured to expire the moment it is used, so a leaked link in an old email stops being useful within minutes. Tokens are stored as one-way hashes rather than plaintext, which means a database leak does not hand attackers working login URLs. Expired and consumed links are pruned automatically on a schedule, and the system can generate them from emails, CRM webhooks, or admin actions — wherever a member identity originates.

  • Time-boxed and single-use capable
  • Hashed at rest (no plaintext tokens)
  • Self-cleaning expired/consumed links
  • Driven by anything (emails, webhooks, admin actions)
Security codes and authentication on a smartphone screen
Passwordless access

Magic Links

Biometric fingerprint sensor on a smartphone
Secure, instant authentication

Passkeys (WebAuthn)

Secure, instant authentication

Passkeys (WebAuthn)

Passkeys are the modern, phishing-resistant replacement for passwords, working the way your members already unlock their devices with Touch ID, Face ID, Windows Hello, a security key, or a phone prompt. A passkey is bound to a specific site, so a fake login page cannot capture it — the credential simply will not work anywhere else. Passkey login is wired into both the standard WordPress login screen and any frontend login form, giving members the same one-tap experience regardless of entry point. Members can register, rename, and remove their own passkeys from their profile, with graceful handling when an authentication is cancelled or fails.

  • Phishing-resistant by design
  • Works everywhere on WordPress
  • Platform and roaming authenticators
  • Managed by the member

Authenticator-based 2FA

TOTP (Authenticator Codes)

For members and sites that prefer an authenticator-app second factor, TOTP delivers the familiar rotating six-digit codes from apps like Google Authenticator, Authy, or 1Password. The system generates standards-based codes compatible with any RFC 6238 app, with built-in tolerance for minor clock drift so a code is not rejected for being a few seconds off. Setup is a scan-and-confirm flow: the member scans a QR code into their app, verifies a code, and they are enrolled. When TOTP is enabled, the member receives a set of one-time recovery codes, so a lost device does not mean a support ticket.

  • Standards-based (RFC 6238)
  • Recovery backup codes
  • QR-code provisioning
  • Clock drift tolerance
Authentication and security codes on a device screen
Authenticator-based 2FA

TOTP (Authenticator Codes)

Guided onboarding and setup process for new members
Secure onboarding for new members

Onboarding Funnel

Secure onboarding for new members

Onboarding Funnel

Removing passwords is only half the job. The other half is ensuring that when a new member first arrives — often created by a CRM webhook or an admin, with no password at all — they are guided through a secure setup instead of landing in a half-working state. The Onboarding Funnel intercepts new members at first contact and routes them through a guided setup before releasing them into the site at large. A member who still needs to complete setup is restricted to the funnel pages and the few endpoints required to finish, unable to wander the protected parts of the site half-configured. When a magic link is generated for a member who still needs onboarding, the link routes them into the funnel rather than dumping them on the homepage, and the handoff is invisible.

  • Catches members at the source
  • Sandboxed until setup complete
  • Hands-off from magic links
  • Extensible gate system

Keeping attackers out

Invisible Fraud Prevention

The hardest fraud to fight is the kind you cannot observe. Account sharing, credential stuffing, and automated scraping can show up as patterns of access — if you can see them. This platform makes access fully observable, then lets you act on what it sees.

Location-based login limiting

Multiple Login Limiting

Every login passes through a checks chain before it is allowed, and one of the most powerful checks targets account sharing directly: if a single account logs in from too many distinct locations inside a rolling window, the login is blocked. The limit counts distinct locations rather than total logins, so a member who travels or uses a couple of devices is not penalized, while an account shared across a dozen households is stopped cold. You set both how long the window is and how many locations are too many, tuned to how your real members behave. The same gate also blocks deleted accounts, tag-based bans, and logins from members without an active membership, so a single check enforces several policies at once.

  • Location-based rather than count-based
  • Configurable window and threshold
  • Layered with other checks
  • Legitimate travel tolerance
Map showing login attempts blocked from multiple locations
Location-based login limiting

Multiple Login Limiting

Login activity log displayed in a security dashboard
Complete visibility into access

Login Log

Complete visibility into access

Login Log

Every successful login is recorded with a timestamp, the member, and the source IP, giving you a complete, searchable history of who got in, when, and from where. Filter by member, email, IP, or time range to investigate a specific account or incident. Each IP is resolved to a city, region, and country right in the log, so answering where a login came from takes a glance rather than a lookup. The same log that powers the admin view is what the multiple-login limit counts against, so detection and investigation draw from one source of truth.

  • Searchable and sortable
  • Geolocation inline
  • Feeds the fraud checks
  • Recent activity focus
Authentication error details on a security screen

Detect brute force and credential stuffing

Login Error Log

Every failed login is recorded with the username tried, source IP, user agent, and reason — exposing brute-force and credential-stuffing patterns at a glance.

  • Captures every failed attempt
  • Reveals attack patterns
  • Self-pruning
  • Recent focus
Web analytics dashboard showing page view tracking

Monitor member behavior

Page View Tracking

Three tracking modes — simple counts, time-on-page, and periodic heartbeats — turn member activity into evidence that exposes scraping and account sharing.

  • Three modes (count, duration, heartbeats)
  • Exposes scraping and sharing
  • Retention-controlled
  • Human behavior detection
Geolocation map showing IP-based location detection

Location intelligence

Reverse IP Lookups

Six geolocation providers turn raw IP addresses into cities, regions, and countries, with caching and automatic fallback for resilience.

  • Six geolocation providers
  • Cached and resilient
  • Everywhere you need it
  • Configurable provider choice

The difference

Why this combination matters

On most platforms, security and friction sit on opposite ends of a dial. Here, the two halves reinforce each other instead of fighting.

🔒

Passwordless access
removes the gate

Magic links and passkeys make the login screen the place where conversions happen, not where members abandon

👁

Fraud caught by behavior,
not gates

Every login, error, and page view is observed, then blocked without making good members jump through hoops

🎯

Onboarding secures day one

The funnel ensures passwordless members complete setup before reaching the site, making removal safe

📋

Everything stays observable

Logs, errors, page views, and geolocation give a complete audit trail so you can investigate, prove, and tune

You don’t have to choose between a login experience members love and a site you can defend.

The login security features deliver both at once — configurable, modular, and ready to fit your member workflows.

Ready to build safer?

The login experience your members love, the security your site needs.

License Memberium and put friction-free access with fraud-proof prevention to work for you.