In this guide: How to change the WordPress login URL: why bots attack login pages, changing the URL with a plugin, limiting login attempts, adding 2FA, and recovery steps.
Every WordPress site has the same login page: yoursite.com/wp-login.php (and /wp-admin/ redirects there). Bots know it too. They constantly try username and password combinations against it — wasting server resources and filling your logs.
Changing the login URL is a simple step that cuts down on this automated noise.
Why bots attack the login page
- Brute-force attacks: bots try thousands of password combinations.
- Credential stuffing: bots test usernames and passwords leaked from other websites.
- Resource drain: each login attempt runs PHP and database queries, which can slow your site.
- Log noise: security logs full of failed attempts make it harder to spot real threats.
Changing the login URL is security through obscurity — it’s not a replacement for strong passwords or 2FA, but it significantly reduces automated attempts. Combine it with the other steps below.
Changing the login URL
Using a plugin (easiest)
Options include WPS Hide Login (lightweight and focused) or security plugins like Solid Security and All-In-One Security that include a “hide login” feature.
With WPS Hide Login:
- Install and activate the plugin.
- Go to Settings → General (or the plugin’s settings).
- Enter your new login slug — something unique but memorable, like
/team-access(avoid obvious choices like/loginor/admin). - Set the redirect URL for people who visit
/wp-login.phpor/wp-admin/while logged out (often a 404 page). - Save and bookmark your new login URL immediately.
Things to check:
- Custom login forms (e.g., WooCommerce “My Account”) still work.
- Caching plugins aren’t caching the new login page — exclude it from cache if needed.
- Team members know the new URL.
- Any apps or services that log in to WordPress still work.
Limiting login attempts
Limit how many failed logins are allowed before temporarily blocking an IP:
- Many security plugins include this (Wordfence, Solid Security, AIOS).
- Dedicated plugins like Limit Login Attempts Reloaded also work.
- Some hosts and CDNs offer rate limiting at the server or edge level — even better, since blocked requests never reach WordPress.
Suggested settings:
- Lock out after 3–5 failed attempts.
- Increase lockout time for repeat offenders.
- Get notified of repeated lockouts.
- Consider CAPTCHA/Turnstile on the login form.
Block username enumeration: attackers can sometimes discover usernames via author archives or the REST API. Many security plugins can prevent this, and using display names different from usernames helps.
Adding 2FA
Two-factor authentication is the most effective protection against stolen or guessed passwords.
- Install a 2FA plugin (many security plugins include it, or use a dedicated plugin like Two Factor or WP 2FA).
- Require 2FA for administrators and editors.
- Each user scans a QR code with an authenticator app.
- Save backup codes.
Some plugins and hosts now support passkeys, which are resistant to phishing and very convenient. See Two-Factor Authentication Apps Compared.
Testing and recovery
Test everything:
- Log out and log in with the new URL.
- Confirm
/wp-login.phpand/wp-admin/no longer show the login form to logged-out visitors. - Test password reset.
- Test from a different browser or device.
If you forget the new URL or get locked out:
- Connect via SFTP or your hosting File Manager.
- Go to
/wp-content/plugins/. - Rename the plugin folder (e.g.,
wps-hide-login→wps-hide-login-disabled). This deactivates it. - Log in at the default
/wp-login.php. - Rename the folder back, reactivate, and check the settings.
If you’re locked out by a login limiter, wait for the lockout to expire, log in from another network, or temporarily deactivate the plugin the same way.
For the complete picture, see WordPress Security: The Complete 2026 Checklist.
Further reading: official WordPress documentation
Key Takeaways: WordPress Login URL
- Bots constantly attack the default WordPress login page.
- Changing the login URL reduces automated attempts and server load.
- Combine it with login limits, CAPTCHA, and 2FA.
- Bookmark the new URL and know how to recover via SFTP.

