Academy LMS 4.0 IS LIVE

00
Days
:
00
Hours
:
00
Minute
:
00
Second

Gemsecurity Integration

GemSecurity is a free, separate plugin from the same team as Academy LMS. Once it’s active, three of its modules automatically protect Academy’s own login and registration forms in addition to the standard WordPress login page: brute-force lockouts, two-factor authentication, and social login.

Note: GemSecurity does not add CAPTCHA to Academy’s login or registration forms. If you want CAPTCHA there, configure reCAPTCHA in Academy Pro’s own settings instead.

Brute-force login protection

This works automatically, with nothing to set up on Academy’s side. GemSecurity’s Login Security page has a Limit login attempts toggle under Brute-force protection, with Max attempts (default 5) and Lockout duration (default 30 minutes). 

Once this is on, Academy’s own login form shares the exact same IP ban ledger as the standard WordPress login page: too many failed attempts on either one locks that IP out of both, with the message “Access temporarily blocked. Too many failed login attempts. Please try again in %d minutes.”

GemSecurity login securit

Two-Factor Authentication

On GemSecurity’s Two-Factor page:

Two-factor system: the Enable two-factor authentication toggle turns the feature on for the whole site. “Users still choose to enroll unless required below.”
Require two-factor by role: turn on a role (Administrator, Editor, Author, and so on) to force a second step at login for everyone with that role. “Users without an app get an emailed code automatically.”

Each user sets up their own second factor from the My two-factor card at the top of the same page: Set up authenticator app (a QR code plus a manual key, verified with a 6-digit code) or Use email codes instead.

Enable 2 factor authentication

GemSecurity’s own two-factor challenge normally only covers the standard wp-login.php page. Academy’s own login form is a REST request, so Academy LMS has its own integration that runs the same second-factor challenge there too. In practice this means: once two-factor is required for a role, a user with that role is challenged for it whether they sign in through the standard WordPress login page or through Academy’s own login form.

Social Login

On GemSecurity’s Social Login page:

Social login
Enable social login: “Shows the configured provider buttons on the WordPress login form.”
Authorized redirect URI: paste this exact URL into each provider’s OAuth app settings.
Account behavior: Allow new account registration (create a WordPress account the first time someone signs in with a provider), Link to existing accounts by email (match an existing user by email instead of creating a duplicate), and a Default role for new accounts.
Four providers, each with its own on/off switch and Client ID / Client secret fields: Google, Facebook, GitHub, and X (Twitter).

Academy LMS has its own integration here too: once a provider is enabled, the same sign-in buttons appear on Academy’s own frontend login form as well as the standard WordPress login page.