# WordPress administrator login notifications on your phone

> Get a push notification every time an administrator signs in to your WordPress site, with the IP address, so you notice a login that wasn't you.

- Company: WordPress (https://www.justpush.io/recipes/wordpress)
- Event: `login.admin` (Administrator login)
- Tags: Websites, Security
- Install: https://studio.justpush.io/recipes/wordpress/admin-login
- Web page: https://www.justpush.io/recipes/wordpress/admin-login

## Setup

1. Click Install in Studio and sign in. The recipe is added to your account and you get a personal webhook URL.
2. Copy the PHP snippet from the setup notes below. It already contains your endpoint URL.
3. Save it as a new .php file in wp-content/mu-plugins/ on your site (create the folder if it doesn't exist).
4. WordPress loads it automatically. Trigger a Administrator login to test.
5. WordPress doesn't send webhooks by itself, so this recipe comes with a small **must-use plugin**. Save the code below as `wp-content/mu-plugins/justpush-admin-login.php` (create the `mu-plugins` folder if it doesn't exist). WordPress loads files there automatically; there's nothing to activate.
6. ```php
7. <?php
8. /**
9. Plugin Name: JustPush — Administrator login
10. Description: Sends a push through JustPush Studio when an administrator signs in.
11. */
12. add_action('wp_login', function ($user_login, $user) {
13. // Only accounts that can change the site's settings.
14. if (!user_can($user, 'manage_options')) {
15. return;
16. }
17. // Behind a proxy or CDN this is the proxy's address, not the visitor's.
18. $ip = isset($_SERVER['REMOTE_ADDR']) ? sanitize_text_field(wp_unslash($_SERVER['REMOTE_ADDR'])) : '';
19. wp_remote_post('your webhook URL (shown in Studio after install)', array(
20. 'blocking' => false, // don't slow the page down waiting for JustPush
21. 'timeout'  => 3,
22. 'headers'  => array('Content-Type' => 'application/json'),
23. 'body'     => wp_json_encode(array(
24. 'event' => 'login.admin',
25. 'site'  => get_bloginfo('name'),
26. 'user'  => $user->display_name,
27. 'ip'    => $ip,
28. 'url'   => admin_url('users.php'),
29. )),
30. ));
31. }, 10, 2);
32. ```
33. If your site is behind a proxy or CDN (such as Cloudflare), the IP address will be the proxy's, not the visitor's.
34. To stop the notifications, delete the file.

## Code

Studio calls `handleRequest(request)` with the incoming webhook (`{ method, headers, body, query, raw }`) and sends the message object it returns. Returning `null` sends nothing.

```js
// WordPress → administrator login
// Fires when the "JustPush — Administrator login" mu-plugin (see INSTALL.md) reports a
// "login.admin" event. WordPress has no webhooks of its own, so the snippet sends them.

// The snippet sends plain strings; treat blanks as missing.
function text(value) {
    return typeof value === "string" && value.trim() ? value.trim() : null
}

// Only link to real http(s) URLs.
function link(url, cta) {
    return typeof url === "string" && /^https?:\/\//.test(url) ? [{ cta, url }] : []
}

function handleRequest(request) {
    const event = request.body

    // Guard: only handle this recipe's event, so other snippets on this integration stay quiet.
    if (event?.event !== "login.admin") {
        console.log(`Ignoring WordPress event "${event?.event ?? "unknown"}"`)
        return null
    }

    const who = text(event.user) ?? "An administrator"
    const site = text(event.site) ? ` to ${text(event.site)}` : ""
    const from = text(event.ip) ? ` from ${text(event.ip)}` : ""

    return {
        title: "🔐 Administrator signed in",
        message: `${who} signed in${site}${from}`,
        topic: "WordPress",
        priority: 0, // Normal — you'll recognise your own logins; a stranger's is worth the ping
        buttons: link(event.url, "View users"),
    }
}
```

## WordPress login.admin webhook payload (sample)

```json
{
  "ip": "203.0.113.7",
  "url": "https://example.com/wp-admin/users.php",
  "site": "My Site",
  "user": "Jane Doe",
  "event": "login.admin"
}
```

## FAQ

### Does this work on iPhone and Android?

Yes. Install the JustPush app from the App Store or Google Play and sign in. Every phone signed in to your account gets the notification.

### Do I need to write code?

No. Install the recipe in Studio, paste your webhook URL into WordPress and you are done. The code is there if you want to change the text, the sound or the buttons.

### Can I change what the notification says?

Yes. After install the recipe's code is yours. Edit it in Studio and test it against the sample payload before you save.

### What does it cost?

JustPush is free for 30 days. After that it's $19.99 a year, or $39.99 once. There is no extra charge for recipes.
