WordPress administrator login notifications on your phone.

Get a push notification every time an administrator signs in to your WordPress site, with the IP address, so you notice a login that wasn't you.

login.adminWebsitesSecurity
How it works

Three steps to your first push

STEP 01

Install the recipe

One click in Studio gives you a personal webhook URL.

STEP 02

Paste your URL into WordPress

Add it as a webhook for Administrator login.

STEP 03

Get a push on your phone

With the text, sound and buttons from the recipe.

Setup

How to set up the WordPress administrator login webhook

  1. Click Install in Studio and sign in. The recipe is added to your account and you get a personal webhook URL.
  2. Copy the PHP snippet from the setup notes below. It already contains your endpoint URL.
  3. Save it as a new .php file in wp-content/mu-plugins/ on your site (create the folder if it doesn't exist).
  4. WordPress loads it automatically. Trigger a Administrator login to test.
  5. WordPress doesn't send webhooks by itself, so this recipe comes with a small **must-use plugin**. Save the code below as `wp-content/mu-plugins/justpush-admin-login.php` (create the `mu-plugins` folder if it doesn't exist). WordPress loads files there automatically; there's nothing to activate.
  6. ```php
  7. <?php
  8. /**
  9. Plugin Name: JustPush — Administrator login
  10. Description: Sends a push through JustPush Studio when an administrator signs in.
  11. */
  12. add_action('wp_login', function ($user_login, $user) {
  13. // Only accounts that can change the site's settings.
  14. if (!user_can($user, 'manage_options')) {
  15. return;
  16. }
  17. // Behind a proxy or CDN this is the proxy's address, not the visitor's.
  18. $ip = isset($_SERVER['REMOTE_ADDR']) ? sanitize_text_field(wp_unslash($_SERVER['REMOTE_ADDR'])) : '';
  19. wp_remote_post('your webhook URL', array(https://••••••••/•••••••• your personal URL, shown after install
  20. 'blocking' => false, // don't slow the page down waiting for JustPush
  21. 'timeout' => 3,
  22. 'headers' => array('Content-Type' => 'application/json'),
  23. 'body' => wp_json_encode(array(
  24. 'event' => 'login.admin',
  25. 'site' => get_bloginfo('name'),
  26. 'user' => $user->display_name,
  27. 'ip' => $ip,
  28. 'url' => admin_url('users.php'),
  29. )),
  30. ));
  31. }, 10, 2);
  32. ```
  33. If your site is behind a proxy or CDN (such as Cloudflare), the IP address will be the proxy's, not the visitor's.
  34. To stop the notifications, delete the file.
The code

What runs when the webhook arrives

Studio calls handleRequest(request) with the incoming webhook and sends the message it returns. It's yours after install; change anything.

transform.js
1// WordPress → administrator login
2// Fires when the "JustPush — Administrator login" mu-plugin (see INSTALL.md) reports a
3// "login.admin" event. WordPress has no webhooks of its own, so the snippet sends them.
4
5// The snippet sends plain strings; treat blanks as missing.
6function text(value) {
7 return typeof value === "string" && value.trim() ? value.trim() : null
8}
9
10// Only link to real http(s) URLs.
11function link(url, cta) {
12 return typeof url === "string" && /^https?:\/\//.test(url) ? [{ cta, url }] : []
13}
14
15function handleRequest(request) {
16 const event = request.body
17
18 // Guard: only handle this recipe's event, so other snippets on this integration stay quiet.
19 if (event?.event !== "login.admin") {
20 console.log(`Ignoring WordPress event "${event?.event ?? "unknown"}"`)
21 return null
22 }
23
24 const who = text(event.user) ?? "An administrator"
25 const site = text(event.site) ? ` to ${text(event.site)}` : ""
26 const from = text(event.ip) ? ` from ${text(event.ip)}` : ""
27
28 return {
29 title: "🔐 Administrator signed in",
30 message: `${who} signed in${site}${from}`,
31 topic: "WordPress",
32 priority: 0, // Normal — you'll recognise your own logins; a stranger's is worth the ping
33 buttons: link(event.url, "View users"),
34 }
35}
Payload

The WordPress login.admin webhook

This is what WordPress sends to your URL for administrator login. It is a sample, trimmed to the fields recipes use.

login.admin · sample.json
1{
2 "ip": "203.0.113.7",
3 "url": "https://example.com/wp-admin/users.php",
4 "site": "My Site",
5 "user": "Jane Doe",
6 "event": "login.admin"
7}
FAQ

WordPress administrator login notifications: questions

Does this work on iPhone and Android?

Yes. Install the JustPush app from the App Store or Google Play and sign in. Every phone signed in to your account gets the notification.

Do I need to write code?

No. Install the recipe in Studio, paste your webhook URL into WordPress and you are done. The code is there if you want to change the text, the sound or the buttons.

Can I change what the notification says?

Yes. After install the recipe's code is yours. Edit it in Studio and test it against the sample payload before you save.

What does it cost?

JustPush is free for 30 days. After that it's $19.99 a year, or $39.99 once. There is no extra charge for recipes.

Ready when you are

WordPress on your phone in two minutes.

Install the recipe, paste one URL, done. Free for 30 days, no credit card required.