Accessed from the “Security & Auth” tab, you can enable a range of additional security measures.

“Email-Only Login” requires a user’s email address to be used instead of their username. As usernames can be revealed via blog posts or the REST API, enforcing an email address makes one part of the login credentials harder to guess.

“Password Reset Protection” returns the same success message regardless of the user account or email address existing or not. This adds an additional roadblock to brute force attempts by preventing a known response to valid accounts.

“Block REST API User Endpoints” will prevent calls to the API to retrieve a list of user accounts.

“Allowed Admin Email Domains” controls which email domains are allowed for new admin users, and will trigger a scheduled email alert if a user with admin level capabilities is found whose domain isn’t on that list. For sites under you managed service, blocking a new admin account from Off-Shore SEO Agency could prevent unintended site breakages or client take over. From a security perspective, scripted attacks using a malicious link and a disposable email account would also be blocked.

“Require Human Verification” includes an additional check when creating admin user accounts.