GemSecurity is a free, separate plugin from the same team as Academy LMS. Once it’s active, three of its modules automatically protect Academy’s own login and registration forms in addition to the standard WordPress login page: brute-force lockouts, two-factor authentication, and social login.
Note: GemSecurity does not add CAPTCHA to Academy’s login or registration forms. If you want CAPTCHA there, configure reCAPTCHA in Academy Pro’s own settings instead.
Brute-force login protection
This works automatically, with nothing to set up on Academy’s side. GemSecurity’s Login Security page has a Limit login attempts toggle under Brute-force protection, with Max attempts (default 5) and Lockout duration (default 30 minutes).
Once this is on, Academy’s own login form shares the exact same IP ban ledger as the standard WordPress login page: too many failed attempts on either one locks that IP out of both, with the message “Access temporarily blocked. Too many failed login attempts. Please try again in %d minutes.”
Two-Factor Authentication
On GemSecurity’s Two-Factor page:
Each user sets up their own second factor from the My two-factor card at the top of the same page: Set up authenticator app (a QR code plus a manual key, verified with a 6-digit code) or Use email codes instead.
GemSecurity’s own two-factor challenge normally only covers the standard wp-login.php page. Academy’s own login form is a REST request, so Academy LMS has its own integration that runs the same second-factor challenge there too. In practice this means: once two-factor is required for a role, a user with that role is challenged for it whether they sign in through the standard WordPress login page or through Academy’s own login form.
Social Login
On GemSecurity’s Social Login page:
Academy LMS has its own integration here too: once a provider is enabled, the same sign-in buttons appear on Academy’s own frontend login form as well as the standard WordPress login page.








