Type something to search...
How to change the default WordPress login URL?

How to change the default WordPress login URL?

The easiest way to change the default WordPress login URL is to install a lightweight plugin such as WPS Hide Login, choose a new slug like /my-team-login/, and save. From then on, /wp-login.php and /wp-admin/ stop showing the login form to logged-out visitors, and only people who know the new address can reach it. It takes about two minutes, and it noticeably cuts down the automated login attempts hitting your site.

Changing the login URL is not a replacement for strong passwords or two-factor authentication, but it is a useful extra layer that reduces noise, server load, and the number of bots guessing at your credentials. In this guide, you'll learn why the default URL is a target, the different ways to change it, how to avoid common pitfalls like caching and lockouts, and how to get back in if you forget your new address.

Why Change the Default WordPress Login URL?

Every WordPress site in the world shares the same login addresses: /wp-login.php and /wp-admin/. Because they are so predictable, automated bots constantly scan the web and hammer these URLs with username and password combinations. This is known as a brute-force or credential-stuffing attack.

Even if those bots never guess a correct password, they still cause problems:

  • Server load: Every login attempt runs PHP and queries the database. Thousands of requests per hour can slow down a small hosting plan.
  • Log noise: Security logs fill up with failed attempts, which makes genuine warning signs harder to spot.
  • Lockout side effects: If you use a plugin that locks accounts after failed attempts, bots can trigger lockouts that affect real users.
  • Credential risk: If any user on your site reuses a leaked password, a bot with a large password list may eventually get lucky.

Moving the login page to a custom slug makes most of these automated scripts fail immediately, because they request /wp-login.php, get a 404 or a redirect, and move on.

Is This Just Security Through Obscurity?

Yes, and that's fine as long as you understand its limits. Hiding the login URL does not fix weak passwords, vulnerable plugins, or a compromised admin account. A determined attacker who targets your site specifically can sometimes discover the new URL, for example through a leaked link or a plugin that exposes it.

Think of it as one layer in a layered defence. The core layers are still:

  1. Strong, unique passwords for every account.
  2. Two-factor authentication for administrators and editors.
  3. Login rate limiting so repeated failures get blocked.
  4. Keeping WordPress, themes, and plugins updated.

A custom login URL sits on top of those and simply reduces how often the other layers get tested.

What Happens When You Change the Login URL?

When you use a reputable plugin to change the login URL, a few things happen behind the scenes:

  1. A new slug is registered: The plugin intercepts requests to your chosen slug (for example /my-team-login/) and serves the normal WordPress login form there.
  2. The old URLs are blocked: Requests to /wp-login.php from logged-out visitors return a 404 page or redirect to a URL you choose.
  3. wp-admin is protected: Logged-out visitors who try /wp-admin/ no longer get redirected to the login page, so they can't use it to discover the new slug.
  4. Login links are filtered: The plugin hooks into the login_url, logout_url, and lostpassword_url filters so that any links WordPress generates point to the new address.

Your WordPress files are not renamed. The wp-login.php file still exists on the server; the plugin just controls who can reach it and under which address. That's important, because renaming or editing core files directly would break on the next WordPress update.

Method 1: Change the Login URL With WPS Hide Login

WPS Hide Login is the most popular single-purpose plugin for this job. It's small, free, and doesn't add extra database tables or settings screens you don't need.

  1. Back up your site: Before any security change that affects logging in, make sure you have a recent backup of your files and database.
  2. Install the plugin: Go to Plugins > Add New Plugin, search for "WPS Hide Login", then click Install Now and Activate.
  3. Open the settings: Go to Settings > General and scroll to the bottom. You'll see a new WPS Hide Login section.
  4. Set your login URL: In the Login url field, enter a slug such as my-team-login. Avoid obvious words like login, admin, signin, or your site name.
  5. Set the redirection URL: In the Redirection url field, choose where people land when they try /wp-login.php or /wp-admin/ while logged out. The default is 404, which is a sensible choice.
  6. Save changes: Click Save Changes. The plugin will show you the new login address at the top of the page.
  7. Bookmark it immediately: Copy the new URL into your password manager and your browser bookmarks before doing anything else.

Now open a private browser window and test both addresses. The new slug should show the login form, and /wp-login.php should show your 404 page or redirect target.

Choosing a Good Login Slug

Your slug doesn't need to be a secret password, but it shouldn't be guessable either. Good slugs are:

  • Unique to you: Something like team-portal-7421 is much better than login.
  • Easy for your team to remember: If people constantly forget it, they'll ask for it over email or chat, where it can leak.
  • Free of special characters: Stick to lowercase letters, numbers, and hyphens so the URL works reliably everywhere.

Method 2: Use a Security Plugin That Includes the Feature

If you already run a full security plugin, check whether it includes a login URL feature before installing another plugin. Running two plugins that both try to control wp-login.php is a common cause of lockouts.

  • Solid Security (formerly iThemes Security): Offers a Hide Backend feature that lets you set a custom login slug and optional redirect.
  • All-In-One Security (AIOS): Includes a Rename Login Page option under its brute-force protection settings.
  • Perfmatters: A performance plugin that also includes a simple custom login URL setting.

The steps are similar in each: enable the feature, enter a slug, save, and test in a private window. The advantage of using a security plugin is that you can combine the new URL with rate limiting, lockouts, and two-factor authentication from one place.

Method 3: Changing It With Code (and Why You Usually Shouldn't)

You'll find tutorials online that suggest copying wp-login.php, renaming it, and doing a find-and-replace inside the file. Don't do this. It modifies WordPress core behaviour in a way that breaks on updates, can leave the original file exposed, and often breaks password reset, logout, and interim login flows.

A correct code-based implementation needs to handle rewrite rules, the login_url and site_url filters, password reset links, logout nonces, multisite, and edge cases like the interim login modal that appears when your session expires in the editor. That's exactly what the maintained plugins already do, so for almost every site, a plugin is the safer choice.

What you can safely do with code is make sure your theme uses the proper WordPress functions for login links, so they always follow whatever URL is configured:

<?php
// In a template file or custom block render callback.
// wp_login_url() respects any plugin that changes the login URL.
if ( ! is_user_logged_in() ) {
    printf(
        '<a href="%s">%s</a>',
        esc_url( wp_login_url( get_permalink() ) ),
        esc_html__( 'Log in', 'mytheme' )
    );
}

If your theme or a custom menu has /wp-login.php hardcoded, replace it with wp_login_url() so it doesn't point visitors at a 404 page.

Things to Check After Changing the Login URL

Once the new URL is live, spend a few minutes checking the areas that most often break.

Caching

Page caching plugins and CDNs can cache the 404 response or even the login form itself. Make sure your new login slug is excluded from caching:

  • Caching plugins: In WP Rocket, LiteSpeed Cache, W3 Total Cache, and similar plugins, add your login slug to the "never cache" or excluded URLs list.
  • Cloudflare or another CDN: Create a rule that bypasses cache for your login slug and for /wp-admin/*.
  • Server caching: If your host provides Varnish or Nginx caching, ask them to exclude the new slug, or check their documentation.

WooCommerce and Membership Sites

If you run WooCommerce, customers normally log in through the My Account page, not wp-login.php, so changing the login URL doesn't affect them. The same is true for most membership and LMS plugins that provide their own front-end login forms. Still, test a customer login and a password reset after making the change.

Password Reset Emails

Request a password reset for a test account and confirm that the link in the email uses your new login URL and actually works. If it doesn't, another plugin may be generating its own reset links, and you'll want to check its settings.

Logout and Session Expiry

Log in, open the block editor, and then log out from the admin bar. You should end up on the new login page or your redirect target. Also check that the "session expired" popup, which WordPress shows when your login cookie expires while you're editing, lets you log back in.

What to Do If You Get Locked Out

Forgetting the new login URL, or a plugin conflict that blocks every login address, is the most common problem with this technique. Fortunately, it's easy to fix.

Option 1: Deactivate the Plugin With WP-CLI

If you have SSH access and WP-CLI installed, run this from your WordPress root directory:

# Deactivate the plugin so the default wp-login.php works again
wp plugin deactivate wps-hide-login

# Or, if you just forgot the slug, look it up without deactivating anything
wp option get whl_page

WPS Hide Login stores the custom slug in the whl_page option, so the second command shows you the current value. If you use a different plugin, run wp plugin list to find its slug and deactivate that instead.

Option 2: Rename the Plugin Folder via FTP or File Manager

If you don't have SSH access:

  1. Connect to your site: Use SFTP or your hosting control panel's file manager.
  2. Open the plugins folder: Navigate to wp-content/plugins/.
  3. Rename the plugin folder: Rename wps-hide-login to something like wps-hide-login-off. WordPress will deactivate the plugin automatically because it can no longer find it.
  4. Log in normally: Visit /wp-login.php and log in.
  5. Fix the settings: Rename the folder back, reactivate the plugin from Plugins > Installed Plugins, and set a slug you'll remember.

Option 3: Check the Database

If you can't use WP-CLI or edit files but do have phpMyAdmin access through your host, you can find the slug in the database. The query below assumes the default wp_ table prefix; adjust it if your prefix is different.

SELECT option_value
FROM wp_options
WHERE option_name = 'whl_page';

Combining a Custom Login URL With Other Protections

A custom login URL works best as part of a small group of login protections. Once it's in place, consider these next steps:

  • Rate limiting: Use a plugin like Limit Login Attempts Reloaded, Wordfence, or Solid Security to block IP addresses after several failed logins.
  • Two-factor authentication: Require 2FA for administrators and anyone who can publish content.
  • XML-RPC: Bots can also attempt logins through xmlrpc.php, which a custom login URL doesn't cover. If you don't use apps or services that depend on it, consider disabling it.
  • Generic login errors: Make sure your login form doesn't reveal whether a username exists, so attackers can't confirm valid accounts.
  • Monitoring: Keep an eye on failed login logs. A sudden spike on your new URL can mean the slug has leaked.

FAQ: Changing the WordPress Login URL

No single change makes WordPress secure. A custom login URL reduces automated brute-force attempts and server load, but you still need strong passwords, two-factor authentication, rate limiting, and regular updates.

With a well-maintained plugin like WPS Hide Login, it rarely breaks anything. The most common issues are cached pages, hardcoded login links in themes or menus, and conflicts with another plugin that also changes the login URL.

You can, but it's not recommended. Renaming or editing wp-login.php breaks on updates, and a proper code solution needs to handle rewrites, password resets, logout nonces, and multisite. A small, maintained plugin is safer.

Logged-in users can still use wp-admin as normal. Logged-out visitors who try to open wp-admin are shown a 404 page or sent to your chosen redirect instead of being forwarded to the login page.

Run wp option get whl_page with WP-CLI to see the slug, or rename the plugin folder in wp-content/plugins via SFTP to deactivate it. Then log in at the default wp-login.php and set a slug you'll remember.

Usually not. WooCommerce customers log in through the My Account page, which is separate from wp-login.php. It's still worth testing customer login and password reset after the change.

Sometimes. The slug can leak through shared links, emails, or poorly coded plugins. That's why it should be combined with rate limiting and two-factor authentication rather than relied on alone.


Conclusion

Changing the default WordPress login URL is one of the quickest security wins you can make. With a plugin like WPS Hide Login or the equivalent feature in Solid Security or AIOS, you can move your login form to a custom address in minutes, and most automated bots will stop reaching it at all. The result is fewer failed logins, cleaner logs, and less load on your server.

Just remember that it's a supporting layer, not the foundation. Save the new URL in your password manager, exclude it from caching, test password resets and logouts, and know how to deactivate the plugin if you ever get locked out. Pair it with strong passwords, two-factor authentication, and login rate limiting, and your login page will be a much harder target.

Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
What is the difference between posts and pages in WordPress?

What is the difference between posts and pages in WordPress?

The main difference between posts and pages in WordPress is that posts are timely, dated entries that appear in your blog feed, archives, and RSS fee

Dive Deeper