HowTo

How to Change the WordPress Login URL (and Why)

WordPress Login URL – How to Change the WordPress Login URL (and Why)

In this guide: How to change the WordPress login URL: why bots attack login pages, changing the URL with a plugin, limiting login attempts, adding 2FA, and recovery steps.

Every WordPress site has the same login page: yoursite.com/wp-login.php (and /wp-admin/ redirects there). Bots know it too. They constantly try username and password combinations against it — wasting server resources and filling your logs.

Changing the login URL is a simple step that cuts down on this automated noise.

Why bots attack the login page

  • Brute-force attacks: bots try thousands of password combinations.
  • Credential stuffing: bots test usernames and passwords leaked from other websites.
  • Resource drain: each login attempt runs PHP and database queries, which can slow your site.
  • Log noise: security logs full of failed attempts make it harder to spot real threats.

Changing the login URL is security through obscurity — it’s not a replacement for strong passwords or 2FA, but it significantly reduces automated attempts. Combine it with the other steps below.

Changing the login URL

Using a plugin (easiest)

Options include WPS Hide Login (lightweight and focused) or security plugins like Solid Security and All-In-One Security that include a “hide login” feature.

With WPS Hide Login:

  1. Install and activate the plugin.
  2. Go to Settings → General (or the plugin’s settings).
  3. Enter your new login slug — something unique but memorable, like /team-access (avoid obvious choices like /login or /admin).
  4. Set the redirect URL for people who visit /wp-login.php or /wp-admin/ while logged out (often a 404 page).
  5. Save and bookmark your new login URL immediately.

Things to check:

  • Custom login forms (e.g., WooCommerce “My Account”) still work.
  • Caching plugins aren’t caching the new login page — exclude it from cache if needed.
  • Team members know the new URL.
  • Any apps or services that log in to WordPress still work.

Limiting login attempts

Limit how many failed logins are allowed before temporarily blocking an IP:

  • Many security plugins include this (Wordfence, Solid Security, AIOS).
  • Dedicated plugins like Limit Login Attempts Reloaded also work.
  • Some hosts and CDNs offer rate limiting at the server or edge level — even better, since blocked requests never reach WordPress.

Suggested settings:

  • Lock out after 3–5 failed attempts.
  • Increase lockout time for repeat offenders.
  • Get notified of repeated lockouts.
  • Consider CAPTCHA/Turnstile on the login form.

Block username enumeration: attackers can sometimes discover usernames via author archives or the REST API. Many security plugins can prevent this, and using display names different from usernames helps.

Adding 2FA

Two-factor authentication is the most effective protection against stolen or guessed passwords.

  1. Install a 2FA plugin (many security plugins include it, or use a dedicated plugin like Two Factor or WP 2FA).
  2. Require 2FA for administrators and editors.
  3. Each user scans a QR code with an authenticator app.
  4. Save backup codes.

Some plugins and hosts now support passkeys, which are resistant to phishing and very convenient. See Two-Factor Authentication Apps Compared.

Testing and recovery

Test everything:

  • Log out and log in with the new URL.
  • Confirm /wp-login.php and /wp-admin/ no longer show the login form to logged-out visitors.
  • Test password reset.
  • Test from a different browser or device.

If you forget the new URL or get locked out:

  1. Connect via SFTP or your hosting File Manager.
  2. Go to /wp-content/plugins/.
  3. Rename the plugin folder (e.g., wps-hide-login → wps-hide-login-disabled). This deactivates it.
  4. Log in at the default /wp-login.php.
  5. Rename the folder back, reactivate, and check the settings.

If you’re locked out by a login limiter, wait for the lockout to expire, log in from another network, or temporarily deactivate the plugin the same way.

For the complete picture, see WordPress Security: The Complete 2026 Checklist.

Further reading: official WordPress documentation

Key Takeaways: WordPress Login URL

  • Bots constantly attack the default WordPress login page.
  • Changing the login URL reduces automated attempts and server load.
  • Combine it with login limits, CAPTCHA, and 2FA.
  • Bookmark the new URL and know how to recover via SFTP.
Z
zasma171

Writes for Hostreta about the topics covered in this article.

Comments (0)

Your email address will not be published. Required fields are marked *

Recent Comments

No comments to show.
Ad · AdSense
Ad space 300×250
Affiliate links
Tools we recommend
Protect Your Website with Automated Daily Backups
$2.09
Get it
the easiest way to manage all of your social media accounts
$29
Get it
Starter Website Get online, properly
$249
Get it
google workspace Business Starter
$3.75
Get it
Nord Vpn Cybersecurity. Built for Everyday Use
$8.99
Get it

We may earn a commission on purchases made through these links, at no extra cost to you.

Ad · AdSense
Ad space 300×600
Ad · AdSense
Ad space 300×600

$ top hosting picks

affiliate
★★★★★

NovaHost

$2.95/mo,renews at $9.95
  • Free SSL + domain, first year
  • 1-click WordPress install
  • 24/7 chat, sub-5-min response
get this deal →
affiliate link · we may earn a commission
★★★★★

CloudRoot

$4.50/mo,renews at $12.95
  • Built-in CDN + caching
  • Daily backups, 30-day retention
  • Staging environments included
get this deal →
affiliate link · we may earn a commission
★★★★★

ByteForge

$3.75/mo,renews at $10.95
  • NVMe storage on every plan
  • Unlimited bandwidth
  • Free migration from your old host
get this deal →
affiliate link · we may earn a commission

Never miss a new article

Join thousands of developers and builders getting a weekly digest of the best tech articles.