BetterShield
Login protectionHardeningSign-in

Change WordPress login URL: quieter logs, not a stronger door

BetterShield team · · 9 min read

If you have searched for how to change WordPress login URL, you have probably seen it described as a security fix. Every WordPress site signs people in at wp-login.php, and automated scripts ask for that address on site after site, so moving it sounds like changing the locks.

It does help, just not in that way. BetterShield’s own screen puts it plainly: moving the sign-in address gives you quieter logs, not a stronger door. Scripts that try wp-login.php by name stop reaching your form. Anyone who has the new address meets the same form, the same accounts and the same passwords.

Here is what the change does, what it leaves alone, and how to make it in BetterShield 1.1.0 without locking yourself out.

Quick summary

  • Moving the sign-in page makes wp-login.php answer 404, so scripts that ask for it by name never reach the form.
  • The benefit is quieter logs and fewer lockouts. It is not a substitute for attempt limits, two-factor or passkeys.
  • In BetterShield, it is Change the sign-in address, under Signing in on Protect › Login & Access. It checks your way back in first.
  • Pair it with Hide the dashboard from visitors, so /wp-admin/ does not hand out the new address.
  • Keep the address somewhere off the site. If you lose it, your recovery link brings back the standard sign-in page.

What changing the login URL does

On a standard WordPress site, the sign-in form lives at /wp-login.php, and a signed-out visit to /wp-admin/ is redirected there. Because the address is the same on every site, a script does not need to find your sign-in page. It asks for it by name.

A custom WordPress login URL, often called hiding wp-login.php, takes that address away. With Change the sign-in address applied, BetterShield:

  • Serves the sign-in page at the address you choose. Signing in, signing out and password resets all work there.
  • Answers 404 at wp-login.php, except for signing out, which keeps working from anywhere.
  • Rewrites every sign-in link WordPress builds, including the ones in its emails.
  • Stops WordPress redirecting short guesses such as /login and /admin, so they do not give the new address away.

A script that asks for wp-login.php now gets “not found” and never sees the form. That means fewer failed sign-ins in your logs and fewer lockouts to read through.

What it does not do

The door is the same door. Your accounts and passwords are unchanged, and anyone who learns the new address can try them there. An address is not a secret the way a password is: it sits in bookmarks, browser history and the emails WordPress sends.

It also leaves other ways in alone. xmlrpc.php accepts a username and password too, and application passwords let tools sign in without the second factor, by design. Each has its own fix: Disable XML-RPC (see Disable XML-RPC in WordPress) and Refuse application passwords.

What actually stops password guessing is already in BetterShield:

  • Pause sign-in after repeated failures, on Protect › Login & Access, is on by default: five wrong passwords from one connection within 15 minutes pause sign-in from it for 15 minutes. It counts wrong passwords at the password check itself, not at one address, so moving the form changes nothing about it. See Limit login attempts in WordPress.
  • Two-factor sign-in, set up on Protect › Two-Factor, asks for a six-digit code from an app after the password, so a stolen password is not enough. A passkey signs you in with your fingerprint, face or device PIN. See WordPress two-factor authentication and Two-factor and passkeys.

Set those up first. Move the address afterward, if quieter logs are worth it to you.

How to change the WordPress login URL with BetterShield

Both fixes in this guide are free, off by default, and listed under Signing in on BetterShield › Protect › Login & Access.

Check your way back in first

Before any Signing in fix applies, BetterShield checks for a working recovery link or an unused printed recovery code, and that your recovery options were checked within the last day. If that fails, Check the way back in first says why and offers Check now or Open Recovery. Go ahead anyway is there too, and is recorded in the activity log.

To pass, open Protect › Recovery, make sure you have a fresh link or printed codes, and press Check readiness now. The Locked out guide covers both.

Change the sign-in address

  1. On Protect › Login & Access, find Change the sign-in address under Signing in.
  2. Type your New sign-in address: two to forty letters, numbers and dashes. Names WordPress already uses, such as wp-admin, are refused, and so is an address where a page, post, category or tag already lives.
  3. Press Preview the change. It checks the address and names the exact sign-in address it would produce. Nothing changes yet.
  4. Turn the switch on. The card shows the new address with a Copy button, and the row reads On since and Undo never expires.
  5. Save the address somewhere off the site, such as a password manager, and tell anyone else who signs in.

With plain permalinks, the address looks like example.com/?side-door rather than example.com/side-door/. The preview shows which one you get.

Read the notes on the card. If one names a caching plugin, exclude the new address from its page cache. If one names another plugin that also moves the sign-in page, turn that version off first or leave this one off. On multisite, the address changes for that site only.

To undo, turn the switch off. The fix writes no files and adds no rewrite rules, so wp-login.php answers again straight away.

Or try it with Monitor first

Monitor first watches real requests without blocking anything. Here, it counts the requests to wp-login.php that the change would have answered with 404.

  1. Type the address, choose a New observation window (1 hour, 24 hours or 7 days), and press Start monitoring with the fields above.
  2. When the window ends, read the counts and press Enforce reviewed settings. It applies the address saved with the window and needs a working recovery link or printed codes. Undo still works.

Bots and people both show up in the count, so it shows how much traffic the move would touch, not who sent it. A match is not proof of breakage, and no matches is not proof of safety.

Add Hide the dashboard from visitors

Here is the gap that catches people out. WordPress sends a signed-out visitor who asks for /wp-admin/ to the sign-in page, and with the address moved, that redirect carries the new one. BetterShield warns about this on the card.

Hide the dashboard from visitors, in the same group, closes the gap. A signed-out visitor who asks for a dashboard page gets a 404 instead of the sign-in form, and signed-in users notice nothing. admin-ajax.php and admin-post.php keep working for front-end features, and the dashboard itself is not renamed, so signed-in users reach it exactly as before.

The same recovery check runs before it applies, and Monitor first works for it too.

Doing it from WP-CLI

The same fixes are available through wp bettershield harden. A command that changes the site needs --user=, naming an account that can manage BetterShield.

wp bettershield harden login_url --dry-run
wp bettershield harden login_url --slug=side-door --user=admin
wp bettershield harden admin_gate --user=admin

--dry-run describes what applying would do and changes nothing. After applying, the command prints a reminder to store the address off the site. If the recovery check fails, the command stops and says why; --force goes ahead anyway, and that is recorded in the activity log. --undo takes you back to wp-login.php. The full reference is WP-CLI commands.

If you forget the new address

BetterShield emailed a recovery link to the site’s administration address when you activated it. Open the newest link, or the address on your printed sheet with one code added, and press Pause protection and continue.

That turns on safe mode for one hour. Every fix pauses and no setting changes, so wp-login.php answers again. Press Go to sign-in and sign in as usual.

Once you are in, the card on Login & Access shows the address with Copy. Save it off the site, or turn the switch off to go back to wp-login.php. When the hour ends, the moved address applies again.

With no link and no codes, wp bettershield recover turns on safe mode from a terminal and needs no user account. More in Locked out of WordPress?

Common mistakes

  • Treating it as the main protection. Keep Pause sign-in after repeated failures on and set up two-factor. The address is an extra.
  • Moving the address without hiding the dashboard. /wp-admin/ then redirects signed-out visitors straight to the new address.
  • Keeping the address in one browser only. Store it off the site, alongside your recovery link and codes.
  • Running two features that move the sign-in page. They do not combine predictably. Keep one.

Frequently asked questions

Does changing the login URL stop password guessing?

It stops scripts that ask for wp-login.php by name from reaching the form. Anyone with the new address meets the same form, and XML-RPC is a separate way in. The attempt limit and two-factor are what stop guessing.

Do password reset emails still work?

Yes. Signing in, signing out and password resets all work at the new address, and the sign-in links WordPress builds, including those in its emails, point there.

Should I also hide wp-admin?

Yes. Change the sign-in address moves the form, and Hide the dashboard from visitors makes /wp-admin/ answer 404 to signed-out visitors, so it does not redirect them to the new address.

Is it in the free plugin?

Yes. Both fixes are among the 16 one-click fixes in the free BetterShield plugin on WordPress.org, and both undo with the same switch. No account or sign-up is needed.

Conclusion

Changing the WordPress login URL is worth doing for what it is: a way to take scripted noise off your sign-in form and out of your logs. It is not a lock. Attempt limits, two-factor and passkeys are the lock.

If you move it, check your way back in, apply Change the sign-in address, add Hide the dashboard from visitors, and note the address off the site. Hardening and Login & Access have the full reference, and Support is there if you get stuck.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield