Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The simplest way to change your WordPress login address is the maintained WPS Hide Login plugin. In WordPress, open Plugins → Add New, search for “WPS Hide Login,” install and activate it, then choose a custom login slug in its settings. Bookmark the new address and verify every authentication flow before logging out of your administrator session.

What changing the login URL actually does

WPS Hide Login intercepts requests instead of renaming WordPress core files or adding rewrite rules. After activation, logged-out visitors can no longer use the standard /wp-login.php or /wp-admin/ endpoints to reach the login form; they must use the slug you select.

This is an exposure-reduction measure, not a complete security system. It can reduce automated traffic aimed at the familiar endpoint, but there is no authoritative quantitative study establishing a particular percentage reduction in attacks. Continue using strong, unique passwords, two-factor authentication, login-attempt limiting, and current WordPress and plugin versions.

Recommended method: WPS Hide Login

Before you change anything

  • Create a current site backup.
  • Confirm you have an administrator account and a hosting-panel, FTP, or database recovery route.
  • Record any membership, forum, mobile-app, API, XML-RPC, or two-factor-authentication integrations that may generate login links.

Install and configure the plugin

  1. Sign in to WordPress and go to Plugins → Add New.
  2. Search for WPS Hide Login, install the plugin from the WordPress.org directory, and activate it.
  3. Follow the activation link to the plugin settings page.
  4. Enter a memorable but non-obvious slug, such as account-access, and save the change. Avoid publishing the slug publicly.
  5. Bookmark the resulting URL in a password manager and in your private administrator documentation.

Test before ending your session

  • Open the new URL in a private browser window and sign in.
  • Log out, then sign in again.
  • Use Lost your password? and complete a password-reset request.
  • Check registration and any login widget, membership, forum, or community page.
  • Test two-factor authentication, expired-session handling, and any connected mobile app or external integration.
  • As a logged-out user, confirm that direct visits to /wp-login.php and /wp-admin/ no longer expose the normal login form.

If a page-cache or CDN sits in front of the site, exclude the custom login path from caching when your cache provider requires it. The plugin documentation specifically calls out cache configuration and reports compatibility with WP Rocket.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Plugin compatibility and common breakage

The plugin states that ordinary registration, lost-password, login-widget, and expired-session flows continue to work. Its listing also identifies compatibility with BuddyPress, bbPress, Jetpack, WPS Limit Login, and User Switching. Compatibility is not universal: a theme or plugin that hardcodes wp-login.php can still fail or send users to the old address.

When an integration breaks, look for a setting that accepts a login URL, update templates or documentation containing the old path, and retest redirects and authentication callbacks. Do not assume that changing the visible link also updates a third-party service’s callback or API configuration.

What happens if you forget the new slug?

Keep a recovery route before making the change. The plugin’s official FAQ says you can find the slug in the whl_page value in the WordPress options table; on multisite, inspect the corresponding value in sitemeta. If database access is unavailable, remove the WPS Hide Login plugin folder through your hosting panel or FTP, sign in through /wp-login.php, then reinstall or reactivate the plugin and set the slug again.

Removing the plugin is a recovery action, not a routine disable-and-reenable test. Take care on multisite installations and make sure you are working on the correct site or network tables.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Using PHP instead: change generated links only

WordPress core’s wp_login_url( $redirect = '', $force_reauth = false ) creates a URL for wp-login.php and applies the login_url filter. A small filter can replace links emitted by a theme or plugin:

add_filter( 'login_url', function ( $login_url, $redirect, $force_reauth ) {
    $custom = home_url( '/my-login/' );
    return $redirect ? add_query_arg( 'redirect_to', $redirect, $custom ) : $custom;
}, 10, 3 );

The $redirect value must be preserved, as in this example, so users return to the page they originally requested. Test password reset, registration, two-factor authentication, XML-RPC or API connections, mobile apps, and every plugin that emits a login link before deploying the filter.

This hook does not block a visitor who types /wp-login.php directly into a browser. It changes URLs returned by wp_login_url(); it is therefore a link-customization technique, not a complete endpoint-hiding solution.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which approach fits your site?

Approach Direct /wp-login.php access Integration and maintenance considerations Recovery
WPS Hide Login Logged-out requests to the standard login and admin endpoints are intercepted. Maintained plugin; ordinary flows and several named plugins are reported compatible, but hardcoded paths can break. Cache exclusions may be needed. Find whl_page in options (or sitemeta on multisite), or remove the plugin folder and use the standard endpoint temporarily.
login_url PHP filter Not blocked; a direct browser request still reaches the core endpoint. Low runtime overhead, but the site owner maintains the code and must preserve redirects and audit every generated link. Remove or disable the filter through the theme or code-management system.

Choose the plugin when you need the standard endpoint intercepted without editing core. Choose the filter only when your requirement is to alter links generated by your own theme or plugins and you have separately addressed direct endpoint access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Security checklist after the change

  • Use a long, unique administrator password and enable two-factor authentication.
  • Enable login-attempt limiting and monitor authentication failures.
  • Keep WordPress, themes, plugins, and server software patched.
  • Check cache and CDN rules so the login form is not served from a public cache.
  • Search custom code and integrations for hardcoded /wp-login.php references.
  • Store the custom URL and recovery instructions securely, not in public site content.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.