ReadyCMS 3.0.63 is live. · Read the changelog
All plugins
Login anomaly detector
Security & Privacy

Login anomaly detector

Detect admin logins from previously unseen IP addresses. A daily security scan flags each new-IP login, optionally sends a rate-limited email digest to your security inbox, and can surface anomalies on the Ready Protect dashboard alongside other security events.

Free v1.0.0 by ReadyCMS
Login anomaly detector - banner
Login anomaly detector - banner
Login anomaly detector - banner
Login anomaly detector - banner

Login Anomaly Detector


Login Anomaly Detector helps your team spot potentially compromised admin accounts by flagging admin logins from IP addresses that have not been seen for that user before.

Scope: ReadyCMS admin accounts only. Customer and website user logins are not monitored.

Key benefits

  • Spot unusual admin activity early. Every admin login is checked against that user's location history. Any first-time IP is flagged for review.
  • Right context, right people. Each flag includes the admin's name, IP address, browser / device, and timestamp — enough for the security team to decide whether to investigate.
  • No inbox flooding. The daily email digest is rate-limited per admin and IP, so someone who legitimately switches offices, works from a hotel, or moves to a new home doesn't spam your security inbox with duplicate alerts.
  • Feeds into Ready Protect. When Ready Protect is active, anomalies appear on its dashboard next to WAF events and other blocked threats — one place for your team's security review, not another separate screen.
  • Focused on sensitive access. Only admin-level accounts are monitored. Customer, storefront, and marketplace-seller logins are outside scope.

Settings you'll see in the plugin

  • Email alerts — turn the daily digest email on or off.
  • Alert email address — where the digest is sent, usually a shared security inbox.
  • Alert email language — pick from nine European languages (English default).
  • Rate-limit window — how many days a single admin / IP combination stays "already alerted" before it can trigger again. Default 30 days. 
  • Feed to Ready Protect — enable or disable the write-through to the Ready Protect dashboard.

How it works

Once a day, the plugin reviews admin logins from the previous 24 hours. For each login, it checks the historical IP addresses used by that admin. If the IP is new, it's flagged as an anomaly.

What happens when an anomaly is detected

  • In-app notification. The admin panel's notification bell shows a flag so your team sees it on their next login.
  • Optional email digest. If email alerts are enabled, a summary is sent to the configured security inbox. Only fresh anomalies are included — anything already alerted within the rate-limit window is filtered out so you don't get repeat emails for the same admin and IP.
  • Optional Ready Protect entry. When Ready Protect is active, the anomaly is added to its dashboard threat table alongside WAF events, IP blocks, and other security signals. Same dashboard, same filters — no separate screen to check.

Rate limiting

The alert dedup window (default 30 days) prevents repeated emails for the same admin / IP combination. If your marketing lead switches to a home-office setup, you get one email — not one every day for a month. Change the window in the plugin settings if your team prefers a longer or shorter memory.

Works better with Ready Protect

Ready Protect is the recommended companion. When both plugins are active, all anomalies surface on the Ready Protect dashboard next to other blocked threats — a single view for your security review instead of two separate screens.

Getting started

  1. Activate Login Anomaly Detector from the ReadyCMS Plugins page. The daily security scan is scheduled automatically.
  2. Open the plugin settings and enter the alert email address — usually a shared security inbox like security@yourcompany.com.
  3. Turn on Email alerts. Pick your alert language and the rate-limit window (30 days works well for most teams).
  4. Optionally activate Ready Protect so anomalies also show up on the security dashboard.
  5. The first scan runs the next day. When an anomaly is detected, the admin bell shows a flag and the digest email arrives on schedule.

FAQ

1. What does Login Anomaly Detector consider an anomaly?

An admin login from an IP address that hasn't been used by that specific admin before. If Anna has only ever logged in from her office network and suddenly a login shows up from a different IP, that login is flagged for review.


2. Does the plugin monitor logins in real time?

No — it's a daily scan. Login activity from the previous 24 hours is reviewed each morning. Real-time monitoring is outside the scope of this plugin.


3. Does it block suspicious logins?

No. The plugin detects and reports; it does not block. If you need automatic blocking on brute-force attempts, activate Ready Protect — its Web Application Firewall handles automatic IP bans on repeated authentication failures.


4. What information is in the email digest?

Each anomaly is listed as a row with the admin's name, email, IP address, timestamp, and browser / device string. Everything you need to scan quickly and decide whether to investigate further.


5. Will I get spammed if an admin genuinely switches locations?

No. The alert dedup window (default 30 days, adjustable from 1 to 365) means the same admin / IP combination emails at most once per window. Someone who moves to a home office or a co-working space triggers one email, not a daily flood.


6. Is Ready Protect required?

No. Login Anomaly Detector works on its own — it identifies anomalies, adds in-app notifications, and sends email digests independently. Activating Ready Protect adds one benefit: anomalies also appear on the security dashboard alongside WAF events, so your team has one place to review everything.


7. What does an anomaly look like on the Ready Protect dashboard?

It appears as a row in the threat table with the admin's IP, the flagged event, and a Moderate severity marker. The row filters and sorts alongside WAF events, so you can review authentication anomalies in the same view as blocked injection attempts, bad user agents, and IP block hits.


8. Does the plugin monitor customer accounts?

No. Only admin logins are scanned. Customer, storefront, and website-user logins are outside scope. If you need to monitor customer login patterns, that's a separate feature request.


9. Can I change the email language?

Yes. The plugin ships with nine European languages: English, Deutsch, Español, Français, Hrvatski, Italiano, Nederlands, Português, Srpski. Pick your preferred language from the plugin settings.


10. What if an admin repeatedly logs in from the same "new" IP?

The first scan flags it. Once flagged, that IP becomes part of the admin's known history, so future scans see it as familiar — no repeat flag. Even if the same anomaly were somehow detected again, the rate-limit window prevents a duplicate email.

Build more with ReadyCMS

Explore the full plugin marketplace or book a demo to see them in action.

Book a demoContact usNo credit card. No commitment.