Polanger Admin Suite is a modular, all-in-one WordPress admin control and security plugin built to help you customize, protect, and manage your website from one place.
Instead of installing separate plugins for admin customization, access control, login protection, firewall security, dashboard management, and activity tracking, Polanger brings these tools together in one clean, modular interface.
Whether you’re a developer, agency, or site owner, Polanger helps you build a cleaner admin experience, stronger access controls, and a safer WordPress installation.
Features
- Modular admin suite: enable only the tools you need and keep wp-admin lightweight.
- Menu Manager with hiding, renaming, reordering, custom icons, custom menu items, URL blocking, and Shield protection indicators.
- Admin Bar, Login Page, Dashboard Center, Activity Log, and admin notice controls from one interface.
- Login hardening with custom login URL, reCAPTCHA, Two-Factor Authentication, recovery keys, trusted devices, and brute-force protection.
- Frontend Content Visibility for role-based access control on posts, pages, and supported custom post types.
- Design System with theme presets, PG Aurora, smart contrast correction, scoped styling, typography, and live preview controls.
- Comment Security Layer and Firewall addons for comment abuse, malicious requests, bot probes, authentication abuse, REST/XML-RPC protection, country blocking, WordPress integrity monitoring, file protection, and safe core recovery.
- WooCommerce Security for store login, registration, lost password, reCAPTCHA, 2FA, and customer authentication rate limiting.
- Polanger Shield for admin page blocking, element hiding, contextual notes, Demo Lock, Global Demo Mode, and safer client/admin demo workflows.
- Maintenance Center for coming soon, maintenance, deployment, preview access, branded public messages, countdowns, and role-based bypass rules.
Why Polanger Admin Suite?
- All-in-One Admin & Security Control – Replace multiple admin, access, and security tools with one modular solution
- Clean & Organized Dashboard – Remove clutter and simplify your workflow
- Layered WordPress Security – Protect authentication, suspicious requests, critical files, WordPress integrity, and geographic access
- Modern UI – Fast, intuitive, and easy to use
- Built for Agencies & Teams – Perfect for multi-user environments
Core Features
Admin Menu Manager
- Hide any admin menu or submenu item
- Role-based visibility control
- Rename menu items and submenus
- Change icons with 200+ Dashicons
- Drag & drop menu reordering
- Block direct URL access to hidden pages
- Visual indicators for hidden and modified items
- Custom admin menu builder (create your own menus)
Admin Bar Customization
- Replace or remove WordPress logo
- Hide unwanted admin bar items
- Add custom links with icons
- Manage frontend and backend admin bar
- Auto-detect plugin and theme items
Login Security & Customization
- Custom login URL (hide wp-login.php)
- Google reCAPTCHA v2 & v3 support
- Custom login page design (logo, colors, background)
- Brute-force protection with configurable login attempt limits and lockouts
- Hardened login flows with safer redirects and protected authentication routes
Email Two-Factor Authentication (2FA)
- Email-based verification codes
- Role-based enforcement
- Recovery keys for backup access
- Configurable expiration times
- Super admin protection
Authenticator App (TOTP)
- Google Authenticator and Microsoft Authenticator support
- Time-based One-Time Password (TOTP) verification
- Multi-user architecture with per-user enrollment
- Mandatory enrollment flow for users in required roles
- Profile page 2FA management (Users → Profile)
- Admin visibility: enrollment status only, no secret access
- Safe secret rotation with pending secret system
- Old authenticator remains active until new setup is verified
- Secure secret storage with AES-256-CBC encryption
- Manual secret entry with provisioning URI support
- One-time recovery keys (10 keys per user, auto-regenerated on rotation)
- Email fallback option when authenticator is unavailable
- Brute-force protection with configurable lockout
- Replay attack prevention with time-slice tracking
- Seamless integration with core 2FA settings (roles, lockout, expiry)
Activity Log
- Track logins, plugin changes, content updates, and more
- Filter by user, action, and date
- Export logs (CSV)
- Email alerts for critical actions
- Privacy-conscious logging with controlled activity data collection
Dashboard Control
- Hide default WordPress widgets
- Hide third-party plugin widgets
- Control admin notices
- Create custom dashboard widgets
- Per-user dashboard visibility
Multisite Control
- Network-wide default settings for multisite installations
- Site-level override controls for supported modules
- Lock system for Menu Manager, Admin Bar, Login Security, Activity Log, and Dashboard Center
- Network-aware addon activation support
- Developer-friendly effective settings filter architecture
Access Control
- Restrict plugin access to specific users
- Read-only mode support
- Prevent unauthorized access
- Super admin safety protection
Design System
- Token-based admin theming system for consistent and scalable customization
- Customize colors across admin UI (sidebar, admin bar, background, text, surfaces)
- Sidebar background, text color, and menu item styling
- Admin bar background, text color, submenu background, and submenu text color
- Built-in presets (e.g. Dark, Minimal, Default) with one-click application
- Automatic CSS generation with cache-friendly performance
- Enhanced Smart Contrast uses WCAG-aware ratios, gradient sampling, dynamic admin-surface monitoring, icon correction, and late theme guards while preserving colors that are already readable
- Typography controls including font family and basic shape settings
- Scoped styling to avoid conflicts with WordPress core and plugins
- Extensible architecture for future themes, layouts, and design packs
Frontend Content Visibility
- Per-content frontend access control for posts, pages, and supported custom post types
- Visibility modes for public, logged-in users only, selected roles only, or hidden-from-selected-roles workflows
- Multiple denied behaviors including login redirect, 404, access denied message, and custom redirect
- Theme-friendly replacement mode or dedicated access denied page for stricter template control
- Optional hiding from archives, search results, public REST responses, and WordPress XML sitemaps
- Rich-text access denied messages with TinyMCE, HTML, and shortcode support
reCAPTCHA Protection
- Centralized Google reCAPTCHA key management (v2 and v3)
- All reCAPTCHA configuration consolidated in one dedicated addon
- Login form protection
- Registration form protection
- Lost password form protection
- Comment form protection (works with Comment Security addon)
- Configurable v3 score threshold
- Badge position customization for v3
- Automatic script loading only when needed
Firewall
- WordPress-aware Firewall with request protection, file integrity monitoring, malware behavior detection, and safe recovery tools
- Monitor Only, Safe Protection, and Strict modes for observation, everyday protection, or more aggressive protection during attacks
- Blocks common bot probes, exposed-file scans, traversal attempts, suspicious request patterns, unsafe methods, and other high-risk traffic
- Native WordPress login, registration, and lost-password rate limiting with identity and IP-based protection
- REST API and XML-RPC hardening with compatibility-aware controls for anonymous requests, user enumeration, multicall abuse, and pingbacks
- Request scoring combines multiple suspicious signals before making monitoring or blocking decisions
- IP allowlist and denylist rules with IPv4/IPv6 CIDR support, trusted proxy handling, and temporary cooldowns for repeated abusive traffic
- Country Access Control blocks visitors from selected countries using a compact local DB-IP Country Lite database without sending visitor IP addresses to a remote geolocation API
- Country data is prepared only when countries are selected, checked periodically for updates, and removed when the country policy is cleared
- Security response headers, WordPress Application Password controls, and username enumeration protection
- Official WordPress core integrity verification detects modified, missing, and unauthorized core files using exact-version and locale checksums
- Supported WordPress.org plugins are verified against official package manifests, while premium and custom plugins/themes use safer executable-file change monitoring instead of being treated as malware
- Incremental executable monitoring detects unexpected PHP and other executable changes across
wp-contentwhile recognizing normal WordPress core, plugin, theme, and translation updates - Upload protection detects executable/PHP-bearing media files and can prevent PHP execution inside uploads on supported Apache environments
- High-confidence malware behavior detection looks for combined indicators such as encoded execution chains, request-driven command execution, suspicious includes, and similar dangerous behaviors
- Strict Extended Server Hardening can protect supported Apache/LiteSpeed sites against sensitive-file exposure, development metadata leaks, backup/log access, directory browsing, and unsafe server-level requests before WordPress/PHP handles them
- Strict server rules use isolated, transactional
.htaccessmanagement with verification, health checks, automatic rollback, and safe cleanup without modifying WordPress or third-party markers - Safe WordPress Core Repair can restore verified modified or missing official core files and quarantine unauthorized core files without automatically deleting ambiguous custom code
- No-reload Scan Now performs a detailed integrity scan with live progress, chunked asynchronous processing, safe locking, and WP-Cron continuation if the browser tab closes
- Low-impact scheduled integrity scans and automatic post-update verification help detect later file changes without requiring constant full scans
- Integrity findings are separated into Critical, Review, and Notice levels so package differences and custom code are not automatically presented as malware
- Compact integrity reports group findings by component, provide a quick preview, and offer a filtered paginated viewer for larger reports
- Recent Firewall Events use bounded storage to record meaningful security decisions without becoming a heavy full-traffic logger
- Built-in Firewall Diagnostics safely test request protection, rate limits, REST/XML-RPC behavior, IP/CIDR rules, security headers, country access, integrity checks, upload protection, scan scheduling, and Strict server hardening without sending malicious traffic
- Protection presets configure sensible defaults automatically while still respecting administrator-customized settings
WooCommerce Security
- Adds WooCommerce-specific reCAPTCHA locations for customer login, registration, and lost password forms
- Extends the existing Polanger 2FA flow into WooCommerce customer login while preserving My Account and checkout return paths
- Adds customer authentication rate limiting for login failures, account registrations, and lost password requests
- Includes Light, Balanced, and Strict protection profiles so store owners can choose safe limits without tuning every number manually
- Requires WooCommerce and uses dependency-aware loading so the addon does not run in incomplete store environments
- Reuses Polanger’s existing reCAPTCHA and 2FA systems instead of creating a disconnected WooCommerce security stack
Polanger Shield
- Blocks selected wp-admin pages for selected users with optional direct URL blocking
- Hides selected admin interface areas from the real screen using the floating Shield tool
- Adds contextual notes to admin elements so teams can document workflows directly inside wp-admin
- Demo Lock keeps selected admin screens visible while preventing save, publish, AJAX, REST, and destructive changes for demo users
- Global Demo Mode turns wp-admin into a controlled read-only demo environment for eligible administrator accounts
- Safe Mode gives authorized managers a temporary recovery path when reviewing or troubleshooting Shield rules
- Menu Manager integration shows when a menu or submenu item is already protected by Shield, helping avoid duplicate restrictions
- The Shield dashboard provides status/type filters, 25-rule pagination, localized dates and states, bulk actions, and a mobile-safe scroll region so every saved rule remains manageable
Addon Architecture
Polanger Admin Suite includes a modular addon system designed for scalability and clarity.
Core Addons
- Admin Bar
- Dashboard Center
- Admin Activity Log
- Custom Admin Menu Builder
- Multisite Control
- Design System
- Comment Security Layer
- Authenticator (TOTP)
- reCAPTCHA
- Firewall
- Maintenance Center
- WooCommerce Security – WooCommerce customer login, registration, lost password, reCAPTCHA, 2FA, and rate limiting integration
- Polanger Shield – admin page blocking, element hiding, contextual notes, Demo Lock, Global Demo Mode, and Menu Manager protection indicators
3rd Party Addons
- Reserved for future ecosystem integrations
- Addons are managed from the built-in Addons tab
- Core addons and external addons are separated for easier management
Built for Real-World Use
Polanger is designed for:
- Agencies managing client websites
- Developers who need full admin control
- Teams working with multiple user roles
- Site owners who want a cleaner dashboard
Lightweight & Secure
- Built with WordPress coding standards
- Nonce verification for all actions
- Capability checks for all operations
- Sanitized inputs and secure database queries
- Optimized for performance
Available Languages
Polanger Admin Suite currently includes translations for:
- English (default)
- Turkish (tr_TR)
- Arabic (ar)
- Russian (ru_RU)
- Chinese – Simplified (zh_CN)
- Spanish (es_ES)
- German (de_DE)
More information:
