New: professional WordPress services from the team behind your theme

Tutorial Security Level: Beginner 10 Minutes

How to Change the WordPress Login URL (Step by Step)

Learn how to change your WordPress login URL safely with a free plugin, why you should avoid editing core files, and how to get back in if you forget your new login address or get locked out.

How to change your WordPress login URL safely, replacing wp-login.php and wp-admin with a custom login address

Every WordPress site uses the same login address by default: /wp-admin or /wp-login.php added to the end of the domain. That makes the login page easy for you to remember, but it’s just as easy for bots and attackers to find. Automated scripts try thousands of username and password combinations on these pages every day, slowing sites down and putting weak accounts at risk.

Changing your WordPress login URL is a quick way to hide the login page from most of these attacks. In this tutorial, we’ll show you how to change the WordPress login URL safely with a free plugin, explain the other options and why you shouldn’t edit core files, and show you how to get back in if you ever forget your new login address or get locked out.

Why change the WordPress login URL?

The default WordPress login page sits at the same place on every site. Anyone can visit example.com/wp-login.php and start guessing passwords. Changing that address has real benefits:

  • Fewer brute force attacks. Most bots only try the default login URLs. If the page isn’t there, they give up and move on.
  • Less server load. Thousands of failed login attempts use server resources. Blocking them can make your site faster, especially on shared hosting.
  • Cleaner security logs. With fewer junk login attempts, real threats are easier to spot.
  • A more branded experience. A login address like example.com/members looks more professional to your team, clients or members.

Changing the WordPress login URL is not a complete security solution on its own. Think of it as one extra lock on the door, used together with strong passwords, two-factor authentication and regular updates.

Why change the WordPress login URL: default addresses like wp-admin and wp-login.php are targeted by bots, so a custom login URL means fewer brute force attacks, less server load, cleaner logs and a branded login page

How to find your current WordPress login URL

On a standard WordPress site, you can reach the login page by adding one of these to the end of your domain:

  • example.com/wp-admin
  • example.com/wp-login.php
  • example.com/login or example.com/admin (WordPress redirects these to the login page on most sites)

If none of these work, your login URL has probably already been changed by a plugin, your host or a previous developer.

Before you start

Changing the WordPress login URL is safe, but a few minutes of preparation will save you a headache later:

  1. Back up your site. Make a full backup of your files and database, so you can restore it if anything goes wrong. For a recovery plan, see our tutorial on what to do when a WordPress update breaks your site.
  2. Make sure you can reach your files. Check that you can log in to your hosting control panel and open the File Manager, or connect with FTP. You’ll need this if you’re ever locked out.
  3. Choose your new login address. Pick something easy for you to remember but hard to guess. Avoid obvious words like login, admin or signin. Something like team-access or studio-entry works well.

WPS Hide Login is a free, lightweight plugin with more than 2 million active installs. It lets you choose a new login address and hides the default wp-login.php and /wp-admin pages from visitors who aren’t logged in. It doesn’t change any core files or add rewrite rules, so it’s safe and easy to undo.

How to change the WordPress login URL with WPS Hide Login: install the plugin, open its settings, enter a new login URL, choose a redirect for the old URL, save, and bookmark the new address

Step 1: Install and activate the plugin

  1. Go to Plugins » Add New Plugin in your dashboard.
  2. Search for WPS Hide Login.
  3. Click Install Now, then Activate.

Step 2: Set your new login URL

  1. Go to Settings » WPS Hide Login. On some versions, the settings appear at the bottom of Settings » General.
  2. In the Login url field, type your new login slug, for example team-access. Your new login address will be example.com/team-access.
  3. In the Redirection url field, choose where people go if they try the old login pages. By default this is a 404 page, which is a good choice. You can also enter a page of your own.
  4. Click Save Changes.

Step 3: Bookmark and test the new address

  1. Copy your new login URL and save it somewhere safe, such as your browser bookmarks and your password manager.
  2. Log out, then visit your new login URL and log in to check it works.
  3. Visit example.com/wp-login.php and example.com/wp-admin in a private browser window. You should see your 404 page or the redirect page you chose, not the login form.

That’s it. Bots that try the default login pages will now hit a dead end.

Using a caching plugin?

If you use a page caching plugin, add your new login slug to its list of pages that should never be cached. Otherwise, some visitors may see a cached version of the login page. WP Rocket handles this automatically, but other caching plugins may need it set by hand.

How to choose a good WordPress login URL

Your new WordPress login URL only helps if it’s hard to guess. Bots don’t just try wp-login.php. Many also try common alternatives, so a predictable slug gives you very little protection.

AvoidBetter choiceWhy
/login/team-access/login is one of the first addresses bots try
/admin/studio-entry/admin is already a well-known WordPress shortcut
/dashboard/north-gate-24Anything that sounds like WordPress is easy to guess
/yourname/blue-lanternYour name or brand is public information

A few simple rules help:

  • Use two or three unrelated words, such as quiet-harbor or maple-door.
  • Add a number if you like, but don’t use your birth year or founding year.
  • Keep it lowercase with hyphens, so it’s easy to type on any device.
  • Don’t share it publicly. Give it only to people who need to log in.

What to update after you change your WordPress login URL

Once your new WordPress login URL is live, take a minute to update the places that still point to the old one:

  • Bookmarks and password managers for everyone on your team.
  • Login links in menus or footers. If your theme or a widget shows a “Log in” link, check that it uses the new address or remove it.
  • Documentation and client handovers that mention /wp-admin.
  • Uptime and security monitoring tools that check your login page.
  • Your caching plugin’s exclusion list, so the new login page is never cached.

Method 2: Use your security plugin’s built-in option

If you already use a security plugin, you may not need a separate one. Many security plugins include a WordPress login URL feature. For example, All-In-One Security (AIOS) includes a Rename Login Page option, and Solid Security includes a Hide Backend feature.

The steps are similar in each one: open the security plugin’s settings, find the login or brute force section, turn on the feature, choose your new slug and save. Don’t run two plugins that change the login URL at the same time, because they can conflict and lock you out.

Method 3: Create a custom front-end login page

Membership, community and online course sites often want a branded login page that matches the rest of the site. Plugins such as User Registration & Membership, and the account pages built into WooCommerce, let you create a login page with a block or shortcode. Many of them can also redirect the default WordPress login page to your new one.

This is a great option for sites where customers or members log in. For sites where only your team logs in, Method 1 is simpler.

Why you shouldn’t rename wp-login.php by hand

Some older guides suggest renaming the wp-login.php file in your site’s root folder and editing the code inside it. We don’t recommend this:

  • WordPress updates undo it. Every core update replaces wp-login.php, so your changes disappear and the old login page comes back.
  • It can break features. Password resets, logouts and some plugins expect the original file and can stop working.
  • It’s easy to lock yourself out. One mistake in the file can make it impossible to log in at all.

A plugin does the same job safely, survives updates and can be undone in seconds.

What to do if you forget your login URL or get locked out

It happens to everyone. Here’s how to get back into your dashboard.

What to do if you're locked out after changing the WordPress login URL: check your saved bookmarks, look up the slug in the database, or rename the plugin folder to restore the default wp-login.php page

Option 1: Check your bookmarks and password manager

Before anything else, check your browser bookmarks, browser history and password manager. The address is often saved there.

Option 2: Look up the slug in your database

If you can open phpMyAdmin from your hosting control panel:

  1. Open your WordPress database and the wp_options table (your prefix may be different from wp_).
  2. Search for the option named whl_page.
  3. Its value is your login slug. Add it to the end of your domain to log in.

Option 3: Turn the plugin off from your files

If you can’t find the slug, deactivating the plugin brings back the default login page:

  1. Open your host’s File Manager or connect with FTP.
  2. Go to wp-content/plugins.
  3. Rename the wps-hide-login folder, for example to wps-hide-login-off.
  4. Visit example.com/wp-login.php and log in as normal.
  5. Rename the folder back, reactivate the plugin under Plugins, and set a login URL you’ll remember.

The same approach works for security plugins: rename that plugin’s folder to turn it off temporarily.

If you still can’t log in and see a server error instead, follow our guide on how to fix the 500 internal server error in WordPress.

Other ways to protect your WordPress login page

Changing the WordPress login URL works best alongside other security habits. Here are the most effective ones:

  • Use strong, unique passwords for every account, and store them in a password manager.
  • Turn on two-factor authentication (2FA) so a stolen password isn’t enough to log in.
  • Limit login attempts to block anyone who keeps guessing passwords. Many security plugins include this.
  • Add a CAPTCHA to your login form to stop automated bots.
  • Don’t use “admin” as a username. It’s the first name every bot tries.
  • Remove old user accounts that no one uses anymore, and give each person only the role they need.
  • Keep WordPress, plugins and your theme updated, because most hacks use known, already-fixed vulnerabilities.
  • Use HTTPS so login details are always encrypted.
WordPress login security checklist: custom login URL, strong unique passwords, two-factor authentication, limited login attempts, CAPTCHA, no admin username, regular updates and HTTPS

The WordPress project’s own guide to hardening WordPress is a good next read if you want to go further.

Let our team secure your WordPress site

If you’d rather leave security to experts, the WPInterface team can help:

You can also see all our professional WordPress services.

Frequently asked questions

Does changing the login URL make WordPress secure?

It makes your site a much harder target for automated attacks, but it isn’t enough on its own. Some bots can still find a hidden login page. Use it together with strong passwords, two-factor authentication, limited login attempts and regular updates.

Will changing the login URL break my website?

No. With a plugin like WPS Hide Login, only the login address changes. Your pages, posts and front-end visitors aren’t affected. Password resets, registration and logouts keep working.

What happens to wp-admin after I change the login URL?

Visitors who aren’t logged in are sent to a 404 page or the redirect page you chose. Once you’re logged in, /wp-admin works as normal.

Can I change the login URL without a plugin?

You can rename wp-login.php by hand, but we don’t recommend it. Every WordPress update restores the original file, and a small mistake can lock you out. A plugin is safer and survives updates.

How do I find my login URL if I forgot it?

Check your bookmarks and password manager first. If you use WPS Hide Login, look up the whl_page option in your database, or rename the plugin’s folder in wp-content/plugins to bring back the default wp-login.php page.

Does changing the login URL affect WooCommerce customers?

No. WooCommerce customers log in through the My Account page, which is a normal page on your site and isn’t affected by the plugin.

Will my new login URL work with multisite?

Yes. WPS Hide Login supports multisite networks with subdomains or subfolders. You can set a network-wide default, and individual sites can choose their own.

Conclusion

Changing your WordPress login URL takes less than five minutes and stops most automated login attacks before they start. Install WPS Hide Login, choose a new login slug, save it somewhere safe and test it in a private window. Avoid editing core files by hand, and keep a recovery plan ready in case you’re ever locked out.

For complete peace of mind, combine a custom login URL with strong passwords, two-factor authentication and our WordPress Care Plans.

Reactions

How did this make you feel?

Be the first to react

One reaction per visitor. Tap again to change or remove it.

Keep reading

Browse all resources

Discussion

Leave a reply

Your email address stays private. Required fields are marked *