Anti Session Hijacking
by Martin van Wilderen 0 (0 reviews)

Anti Session Hijacking

Stops session hijacking: signs a user out when their login session is used from a different IP address than the one it started on.

Anti Session Hijacking ranks #58,234 among WordPress.org plugins with 0+ active installations, and was last updated Aug 5, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.6 (Current: 7.1.2)
v0.8.0 Current Version v0.8.0
Updated 1 month ago Last Update on 05 Aug, 2026
Refreshed 9 hours ago Last Refreshed on
View on WordPress.org
Rank
#58,234
No change
Active Installs
0+
-100%
KW Avg Position
4
No change
Downloads
241
+2 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 10

Total Progress 20%
0+ 10+
38,494
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 8 more installs to reach 10+

Rank Changes

47,833 52,741 57,649 62,557 67,465 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
46,437 52,411 58,385 64,359 70,333 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #58,234
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Track This Plugin

Get detailed analytics, keyword tracking, and position alerts delivered to your inbox.

Start Tracking Free

Plugin Details

Version
0.8.0
Last Updated
Aug 05, 2026
Requires WP
6.0+
Tested Up To
7.0.6
PHP Version
7.4 or higher

Support & Rating

Rating
☆ ☆ ☆ ☆ ☆ 0
Reviews
0
Support Threads
0
Resolved
0%

Keywords

Upgrade to Pro

Unlock keyword rankings, search positions, and detailed analytics with a Pro subscription.

Upgrade Now

Frequently Asked Questions

Common questions about Anti Session Hijacking

Yes, and this is the main trade-off to be aware of. Some mobile carriers, corporate proxies, and VPNs rotate a user's IP address mid-session, which is indistinguishable from a hijack as far as the check is concerned. If this is disruptive for a particular group of users, turn the check off for their role under Settings → Anti Session Hijacking. Administrator accounts are usually worth keeping strict.
Yes. Behind a proxy, every request appears to come from the proxy's own address, which would make the check useless. The plugin reads the real visitor IP from the X-Forwarded-For header instead — but only when the request genuinely arrives from a proxy address, so an attacker cannot simply send that header themselves to defeat the check. The trusted proxy ranges default to the usual private networks and can be adjusted with the antisehi_trusted_proxies filter.
No, it complements it. Two-factor authentication protects the act of logging in. It does nothing once a session already exists, which is precisely when a stolen cookie is used. Running both covers the login and the session that follows.
No. Every check happens locally, using data WordPress already stores for the current session. There are no external requests, no telemetry, and no third-party services involved.
Yes, one: a mismatch log recording the username, the IP the session logged in with, the IP that triggered the mismatch, and a timestamp, each time a user is signed out by this plugin. It's viewable under Settings → Anti Session Hijacking → Mismatch Activity. Nothing in it ever leaves your site, and the table — along with the plugin's settings — is removed automatically when you uninstall the plugin.
The mismatch log stores usernames and IP addresses, and IP addresses are considered personal data under the GDPR. They are stored only on your own server, only when a mismatch actually occurs, and are deleted entirely when you uninstall the plugin. If you keep a privacy policy listing what your site records, it's worth mentioning this log.
Yes. When you activate it, it switches on WordPress's own automatic updates for this plugin, so security fixes reach your site without waiting for someone to log in and press update. This is a security plugin, and an out-of-date one protects nobody. It uses the same setting as the Automatic Updates column on your Plugins screen, so nothing is hidden from you: the screen will show auto-updates as enabled, and you can switch them off there exactly like any other plugin. If you do switch them off, that choice sticks — deactivating and reactivating the plugin will not quietly turn them back on. Uninstalling removes the plugin from that list entirely.
No. Only the specific session that failed the check is destroyed. If the same user is logged in on a phone and a laptop, ending the hijacked session leaves the other one signed in.

Sign In / Register

You need to sign in or register to use this feature.