Castle Security
Your website is your castle, Your content is valuable, and your digital assets should be protected.
Zero-friction login
Members flow
Attackers hit the wall
Passwordless access for legitimate members. Invisible fraud prevention for everyone else. Remove passwords and catch the bad actors with behavior — no compromises
Getting members in
Friction-Free Access
Passwords are the single largest source of login friction and churn at the front door. The answer is to remove the password from the critical path, then guide new members through setup so nobody is left half-configured.
Passwordless access
Magic Links
A magic link is a one-click, passwordless login delivered by URL. A member clicks the link and they are in — no password to remember, no reset flow to trigger. Each token is short-lived by default and can be configured to expire the moment it is used, so a leaked link in an old email stops being useful within minutes. Tokens are stored as one-way hashes rather than plaintext, which means a database leak does not hand attackers working login URLs. Expired and consumed links are pruned automatically on a schedule, and the system can generate them from emails, CRM webhooks, or admin actions — wherever a member identity originates.
- Time-boxed and single-use capable
- Hashed at rest (no plaintext tokens)
- Self-cleaning expired/consumed links
- Driven by anything (emails, webhooks, admin actions)
Magic Links
Passkeys (WebAuthn)
Secure, instant authentication
Passkeys (WebAuthn)
Passkeys are the modern, phishing-resistant replacement for passwords, working the way your members already unlock their devices with Touch ID, Face ID, Windows Hello, a security key, or a phone prompt. A passkey is bound to a specific site, so a fake login page cannot capture it — the credential simply will not work anywhere else. Passkey login is wired into both the standard WordPress login screen and any frontend login form, giving members the same one-tap experience regardless of entry point. Members can register, rename, and remove their own passkeys from their profile, with graceful handling when an authentication is cancelled or fails.
- Phishing-resistant by design
- Works everywhere on WordPress
- Platform and roaming authenticators
- Managed by the member
Authenticator-based 2FA
TOTP (Authenticator Codes)
For members and sites that prefer an authenticator-app second factor, TOTP delivers the familiar rotating six-digit codes from apps like Google Authenticator, Authy, or 1Password. The system generates standards-based codes compatible with any RFC 6238 app, with built-in tolerance for minor clock drift so a code is not rejected for being a few seconds off. Setup is a scan-and-confirm flow: the member scans a QR code into their app, verifies a code, and they are enrolled. When TOTP is enabled, the member receives a set of one-time recovery codes, so a lost device does not mean a support ticket.
- Standards-based (RFC 6238)
- Recovery backup codes
- QR-code provisioning
- Clock drift tolerance
TOTP (Authenticator Codes)
Onboarding Funnel
Secure onboarding for new members
Onboarding Funnel
Removing passwords is only half the job. The other half is ensuring that when a new member first arrives — often created by a CRM webhook or an admin, with no password at all — they are guided through a secure setup instead of landing in a half-working state. The Onboarding Funnel intercepts new members at first contact and routes them through a guided setup before releasing them into the site at large. A member who still needs to complete setup is restricted to the funnel pages and the few endpoints required to finish, unable to wander the protected parts of the site half-configured. When a magic link is generated for a member who still needs onboarding, the link routes them into the funnel rather than dumping them on the homepage, and the handoff is invisible.
- Catches members at the source
- Sandboxed until setup complete
- Hands-off from magic links
- Extensible gate system
Keeping attackers out
Invisible Fraud Prevention
The hardest fraud to fight is the kind you cannot observe. Account sharing, credential stuffing, and automated scraping can show up as patterns of access — if you can see them. This platform makes access fully observable, then lets you act on what it sees.
Location-based login limiting
Multiple Login Limiting
Every login passes through a checks chain before it is allowed, and one of the most powerful checks targets account sharing directly: if a single account logs in from too many distinct locations inside a rolling window, the login is blocked. The limit counts distinct locations rather than total logins, so a member who travels or uses a couple of devices is not penalized, while an account shared across a dozen households is stopped cold. You set both how long the window is and how many locations are too many, tuned to how your real members behave. The same gate also blocks deleted accounts, tag-based bans, and logins from members without an active membership, so a single check enforces several policies at once.
- Location-based rather than count-based
- Configurable window and threshold
- Layered with other checks
- Legitimate travel tolerance
Multiple Login Limiting
Login Log
Complete visibility into access
Login Log
Every successful login is recorded with a timestamp, the member, and the source IP, giving you a complete, searchable history of who got in, when, and from where. Filter by member, email, IP, or time range to investigate a specific account or incident. Each IP is resolved to a city, region, and country right in the log, so answering where a login came from takes a glance rather than a lookup. The same log that powers the admin view is what the multiple-login limit counts against, so detection and investigation draw from one source of truth.
- Searchable and sortable
- Geolocation inline
- Feeds the fraud checks
- Recent activity focus
Detect brute force and credential stuffing
Login Error Log
Every failed login is recorded with the username tried, source IP, user agent, and reason — exposing brute-force and credential-stuffing patterns at a glance.
- Captures every failed attempt
- Reveals attack patterns
- Self-pruning
- Recent focus
Monitor member behavior
Page View Tracking
Three tracking modes — simple counts, time-on-page, and periodic heartbeats — turn member activity into evidence that exposes scraping and account sharing.
- Three modes (count, duration, heartbeats)
- Exposes scraping and sharing
- Retention-controlled
- Human behavior detection
Location intelligence
Reverse IP Lookups
Six geolocation providers turn raw IP addresses into cities, regions, and countries, with caching and automatic fallback for resilience.
- Six geolocation providers
- Cached and resilient
- Everywhere you need it
- Configurable provider choice
The difference
Why this combination matters
On most platforms, security and friction sit on opposite ends of a dial. Here, the two halves reinforce each other instead of fighting.
Passwordless access
removes the gate
Magic links and passkeys make the login screen the place where conversions happen, not where members abandon
Fraud caught by behavior,
not gates
Every login, error, and page view is observed, then blocked without making good members jump through hoops
Onboarding secures day one
The funnel ensures passwordless members complete setup before reaching the site, making removal safe
Everything stays observable
Logs, errors, page views, and geolocation give a complete audit trail so you can investigate, prove, and tune
You don’t have to choose between a login experience members love and a site you can defend.
The login security features deliver both at once — configurable, modular, and ready to fit your member workflows.
Ready to build safer?
The login experience your members love, the security your site needs.
License Memberium and put friction-free access with fraud-proof prevention to work for you.