This product was not featured by Product Hunt yet.
It will not be visible on their landing page and won't be ranked (cannot win product of the day regardless of upvotes).

Product upvotes vs the next 3

Waiting for data. Loading

Product comments vs the next 3

Waiting for data. Loading

Product upvote speed vs the next 3

Waiting for data. Loading

Product upvotes and comments

Waiting for data. Loading

Product vs the next 3

Loading

AuthDock

Login Security, 2FA, Social Login & Brute Force Protection

AuthDock is one authentication plugin instead of five: social login from 10 providers, single sign-on, magic links, passkeys, 2FA, brute-force and bot protection, session control, wp-admin access rules and a tamper-evident audit log — one log, one idea of the visitor's IP, one score out of 100 telling you where you stand. Every feature ships switched off. Nothing phones home — no telemetry, no licence check, and with everything off, no outbound request at all. Free, GPLv2, no paid tier.

Top comment

Hi Product Hunt 👋 I'm Rakib. I build WordPress tools at Degird, and AuthDock is the one I most needed myself. Here's the problem it came from. A WordPress site that wants proper authentication ends up with four or five plugins that don't know about each other: one for social login, one for 2FA, one for brute-force, one for logging. They duplicate settings, they disagree about who the visitor even is — each reads the client IP its own way, and behind Cloudflare at least one of them is wrong — and none of them can tell you whether the site is actually protected. AuthDock is all of it in one plugin, with one audit log, one idea of the visitor's address, and a score out of 100 that says how you're doing. Four decisions I'd defend, and would genuinely like to be argued with about: 🔸 Everything ships switched off. Activating changes nothing about how your site logs people in. Upgrading never turns anything on. Turning a feature on is your decision, every time. 🔸 Nothing phones home. No telemetry, no usage reporting, no licence check. With every feature off, the plugin makes no outbound request at all. Risk scoring, breach checking (by k-anonymity — five characters of a hash, never the password), geolocation and analytics all run on your own server. Ten features can contact a third party, each only when you switch it on and supply your own credentials, and all ten are listed by name in the readme. 🔸 Every control that can lock you out has a documented way back in — a wp-config.php constant, a `wp authdock` command, and a recovery route that needs no database access. AUTHDOCK_SAFE_MODE lifts hardening wholesale, and it fails open on hardening and never on authentication: it admits nobody who couldn't get in before, and a second factor somebody chose to set up still applies. The dashboard nags at you the whole time a control is lifted, because an emergency measure nobody removes is a permanent hole. 🔸 A protection that can't run fails open, and says so. A CAPTCHA provider outage, an unreachable breach service, a corrupt geolocation database — each lets the request through and writes the outage to the audit log. A login outage is worse than a missed check. (The audit log itself is tamper-evident, not tamper-proof: anyone holding the database *and* the salts can rebuild the chain. What it defeats is somebody deleting the row that names them.) The last release, 2.1.6, was a full pre-release audit of every module, and I'd rather show you the uncomfortable part than bury it: several controls reported themselves as protecting a site while doing nothing. Location rules and bot protection both refused *before* WordPress checks the password, and core discards an earlier refusal once it's handed a valid username and password — so a correct password beat both. The GeoLite2 reader resolved pointers sixteen bytes early, so every lookup said "no data", and a rule with no data allows everyone, which made the failure completely silent. It's all written up finding by finding in the changelog, alongside the internal audits in docs/fix-and-improve/ — including findings I decided not to fix, and why. It's free and GPLv2. Not freemium, not a free tier — there is no paid version and no upsell in the UI. I'll be here all day. The most useful thing you can leave me is the setup that breaks it: an odd reverse proxy, a page cache doing something clever with the login URL, a multisite network, an OIDC provider whose discovery document isn't quite to spec. Bug reports over compliments, please. 🙏 (One ask: if you find an actual vulnerability, please don't post it here — there's a private advisory route in the security policy, and I'll credit you in the release notes.)

About AuthDock on Product Hunt

Login Security, 2FA, Social Login & Brute Force Protection

AuthDock was submitted on Product Hunt and earned 3 upvotes and 1 comments, placing #35 on the daily leaderboard. AuthDock is one authentication plugin instead of five: social login from 10 providers, single sign-on, magic links, passkeys, 2FA, brute-force and bot protection, session control, wp-admin access rules and a tamper-evident audit log — one log, one idea of the visitor's IP, one score out of 100 telling you where you stand. Every feature ships switched off. Nothing phones home — no telemetry, no licence check, and with everything off, no outbound request at all. Free, GPLv2, no paid tier.

On the analytics side, AuthDock competes within WordPress and Security — topics that collectively have 24.5k followers on Product Hunt. The dashboard above tracks how AuthDock performed against the three products that launched closest to it on the same day.

Who hunted AuthDock?

AuthDock was hunted by RAKIBUZZAMAN. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.

For a complete overview of AuthDock including community comment highlights and product details, visit the product overview.