S
by laceous 5 (1 reviews)

Semisecure Login Reimagined

"Re-imagined" version of Semisecure Login that uses public and secret-key encryption to encrypt passwords when logging in.

Semisecure Login Reimagined ranks #18,324 among WordPress.org plugins with 70+ active installations, is #424 of 1,588 in the Authentication category, a 5/5 rating from 1 reviews, and was last updated Jul 15, 2011. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 3.1 (Current: 7.1.1)
vtrunk Current Version vtrunk
Updated 15 years ago Last Update on 15 Jul, 2011
Refreshed 7 hours ago Last Refreshed on
#424 of 1,588 in Authentication Top 25% by installs No update in over a year
View on WordPress.org
Rank
#18,324
+52 this week
Active Installs
70+
-6.7%
KW Avg Position
66
No change
Downloads
51.3K
+2 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (1 reviews)

Next Milestone 80

Total Progress 50%
70+ 80+
1,355
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 5 more installs to reach 80+

Rank Changes

18,311 18,334 18,358 18,381 18,404 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
18,241 18,286 18,332 18,377 18,422 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
Current #18,324
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
0 10 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
1 reviews
Overall 100%
5
1 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Semisecure Login Reimagined

A user attempts to log in via the login page. If JavaScript is enabled, a secret-key is generated and used to encrypt the password along with a nonce, the public-key encrypts the secret-key, and the original (unencrypted) password is not sent. The server decrypts the secret-key with the private-key which is used to decrypt the password+nonce. The nonce is verified before handing the password over to WordPress for verification. If JavaScript is not enabled, the password is sent in cleartext just like normal. This is inherently insecure over plaintext channels, but it is the default behavior of WordPress.
When the login form is displayed, the message "Semisecure Login is enabled" will appear underneath the Username and Password fields. If for some reason it isn't working (i.e., if JavaScript is not enabled, or you're running a browser that doesn't support certain necessary JavaScript functions), the message will read, "Semisecure Login is not enabled! Please enable JavaScript and use a modern browser to ensure your password is encrypted." Note: v2.0 adds support for encrypting passwords on the user administration pages. In this case, the message "Semisecure Login is enabled" will only appear if the option has been activated (and JavaScript is enabled). If not, then nothing will be displayed.
Short answer: No, but it's better than nothing. Without SSL, you're going to be susceptible to replay attacks/session hijacking no matter what. What this means is that if someone is able to guess or learn the session ID of a logged-in user (which would be trivial to do in an unprotected wireless network), then essentially they could do anything to your WordPress site by masquerading as that user.
The point of this is to prevent your password from being transmitted in the "clear." If someone is in a position where they can learn your session ID, under normal circumstances, they'd also be able to learn your password. The proper use of this plugin removes that possibility.
Use SSL. This means you'll have to have a dedicated IP (which usually costs additional money) and an SSL certificate (which is expensive for a "real" one, but if you're just using this for your own administration purposes, a "self-signed" certificate would probably suffice). Any more detail on these two things is beyond the scope of this document.

Sign In / Register

You need to sign in or register to use this feature.