Site icon Hostreta

How to Change the WordPress Login URL (and Why)

WordPress Login URL – How to Change the WordPress Login URL (and Why)

In this guide: How to change the WordPress login URL: why bots attack login pages, changing the URL with a plugin, limiting login attempts, adding 2FA, and recovery steps.

Every WordPress site has the same login page: yoursite.com/wp-login.php (and /wp-admin/ redirects there). Bots know it too. They constantly try username and password combinations against it — wasting server resources and filling your logs.

Changing the login URL is a simple step that cuts down on this automated noise.

Why bots attack the login page

Changing the login URL is security through obscurity — it’s not a replacement for strong passwords or 2FA, but it significantly reduces automated attempts. Combine it with the other steps below.

Changing the login URL

Using a plugin (easiest)

Options include WPS Hide Login (lightweight and focused) or security plugins like Solid Security and All-In-One Security that include a “hide login” feature.

With WPS Hide Login:

  1. Install and activate the plugin.
  2. Go to Settings → General (or the plugin’s settings).
  3. Enter your new login slug — something unique but memorable, like /team-access (avoid obvious choices like /login or /admin).
  4. Set the redirect URL for people who visit /wp-login.php or /wp-admin/ while logged out (often a 404 page).
  5. Save and bookmark your new login URL immediately.

Things to check:

Limiting login attempts

Limit how many failed logins are allowed before temporarily blocking an IP:

Suggested settings:

Block username enumeration: attackers can sometimes discover usernames via author archives or the REST API. Many security plugins can prevent this, and using display names different from usernames helps.

Adding 2FA

Two-factor authentication is the most effective protection against stolen or guessed passwords.

  1. Install a 2FA plugin (many security plugins include it, or use a dedicated plugin like Two Factor or WP 2FA).
  2. Require 2FA for administrators and editors.
  3. Each user scans a QR code with an authenticator app.
  4. Save backup codes.

Some plugins and hosts now support passkeys, which are resistant to phishing and very convenient. See Two-Factor Authentication Apps Compared.

Testing and recovery

Test everything:

If you forget the new URL or get locked out:

  1. Connect via SFTP or your hosting File Manager.
  2. Go to /wp-content/plugins/.
  3. Rename the plugin folder (e.g., wps-hide-login → wps-hide-login-disabled). This deactivates it.
  4. Log in at the default /wp-login.php.
  5. Rename the folder back, reactivate, and check the settings.

If you’re locked out by a login limiter, wait for the lockout to expire, log in from another network, or temporarily deactivate the plugin the same way.

For the complete picture, see WordPress Security: The Complete 2026 Checklist.

Further reading: official WordPress documentation

Key Takeaways: WordPress Login URL

Exit mobile version