Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To hide whether a failed WordPress login used an unknown username or an incorrect password, use the login_errors filter to show one neutral message for login errors. This changes the text displayed above the login form, not how WordPress checks credentials.

Replace detailed login errors with a generic message

Add this filter in a site-specific plugin or a child theme:

add_filter( 'login_errors', function ( $error ) {
    return __( 'Invalid username or password.' );
} );

The WordPress login_errors reference describes the hook as filtering “the error messages displayed above the login form.” It receives the error text prepared for display, so returning a single sentence replaces the detailed login error shown there.

A site-specific plugin keeps the behavior separate from the theme; a child theme is another option. Avoid editing WordPress core files. After adding the filter, test a failed login on your site and confirm that the same generic message appears for the cases you want to conceal.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the right login hook

Use the hook that matches what you need to change. For a blanket replacement of the displayed text, login_errors is the direct choice.

Hook What it receives or changes When to use it
login_errors Error text prepared for display above the form; introduced in WordPress 2.1.0, according to the hook reference. Replace login error text with one generic message.
wp_login_errors A WP_Error object and a redirect destination; introduced in WordPress 3.6.0, according to the hook reference. Change particular structured error entries before they are rendered.
authenticate A lower-level filter involved in validating credentials; see the WordPress hook reference. Only when changing authentication behavior is actually intended—not merely to change the displayed wording.

Check the result on your site

The WordPress login flow can be customized by themes and plugins, so a filter may not behave the same way on every installation. If the message is unchanged, check whether a plugin or theme handles login errors separately and test the filter in a controlled way. Keep a working administrator route available while troubleshooting.

WordPress Core tracked a login-message rendering issue with WordPress 6.4.3 as its milestone. That history is a reminder that edge behavior can be version-sensitive; test on the WordPress version and plugin stack your site actually runs. See the Core Trac ticket for that issue.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this changes—and what it does not

A generic error makes the login response less explicit to someone comparing failed attempts with different usernames or passwords. It does not prevent account compromise, change the authentication check, or establish a measured reduction in attacks. Treat it as one small hardening measure alongside sound authentication and broader site security practices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WordPress supports logging in with either a username or its associated email address, as described in the WordPress login guide. The filter changes the displayed error wording; it does not change those login options or the login-cookie process.

Quick Recap

SaleBestseller No. 2
Bestseller No. 3
SaleBestseller No. 4
Bestseller No. 5

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.