No Login by Email Address
View on WordPress.orgScores higher than 6% of indexed plugins
About
Removes the ability to login using the email address instead of the username.
What It Does
No Login by Email Address disables WordPress's built-in feature that lets users authenticate by typing their email address, forcing login attempts to use only a username. In practice, anyone visiting /wp-login.php can no longer type an email into the username field; only a matching username will work. It is a narrow, single-purpose security tweak rather than a full login hardening suite.
Who It's For
This plugin fits organizations that mandate username-based authentication for compliance, audit, or policy reasons, such as government portals, financial institutions, healthcare intranets, legal firms, and university staff directories. If your security policy requires that every login attempt be traceable to a known username rather than a personal email, this plugin enforces that at the WordPress layer.
Who Should Skip It
If you run a typical small business blog, membership site, or any site where users expect to log in with the email they registered with, skip this plugin; it will frustrate legitimate users and create avoidable support tickets. You also do not need it if you already enforce single sign-on or a custom login form that controls authentication flow.
The Bottom Line
No Login by Email Address does exactly one thing and does it lightly, which is both its appeal and its limitation for the 1,000 sites using it. With a 59.79/100 quality score, weak support history, and a small install base, it is best suited to organizations with a clear policy reason to disable email login rather than general WordPress users. For most sites, a broader login security plugin will deliver more value.
Related Plugins
Choose this when your real problem is email deliverability, not login method, as it fixes SMTP and transactional email issues at far greater scale.
Pick this if you need SMTP delivery with logging, alerts, and a mobile fallback connection, which is a different problem than restricting login identifiers.
Choose this when you want to harden the login surface by changing the wp-login.php URL, which is a more widely used tactic than disabling email-based login.
This is an email marketing integration and is not a substitute; only consider it if you also need Mailchimp signup forms.
Pick this if you want broader login security such as brute force protection, two-factor authentication, and login attempt logging rather than a single policy switch.