Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To restrict an entire WordPress site to approved visitors, use a maintained access-control plugin or server-level authentication: WordPress core does not provide a whole-site privacy switch. Core visibility settings can hide individual posts or pages, while the “Discourage search engines from indexing this site” option only asks crawlers not to index public content.

Choose the privacy control that matches your goal

What you want Use Who can view it
Hide an individual post or page from ordinary visitors Set its visibility to Private Authorized WordPress roles, such as Editors and Administrators; this is not access for every registered user. WordPress documentation
Share an individual post or page with people using one common password Set its visibility to Password Protected Anyone who has the shared password; it does not create individual accounts. WordPress limits post passwords to 20 characters. WordPress documentation
Restrict the whole site to logged-in or otherwise approved visitors Use an access-control plugin or server-level restriction Depends on how you configure the chosen solution; core’s per-item visibility settings do not lock the whole site. WordPress documentation
Keep a public site out of search results where crawlers honor the request Enable Search Engine Visibility in Settings → Reading Public access remains enabled. WordPress documentation

Make an individual post or page private

Use Private when the content is for authorized site roles, such as Editors or Administrators, rather than the general public. In the editor, open the post or page’s visibility controls, choose Private, then click Update or Publish to apply the change. This setting is for that item; it does not turn a whole blog into a private site. WordPress documentation

Password-protect an individual post or page

Use Password Protected when a shared secret is sufficient for a particular item. In the editor’s visibility controls, choose Password Protected, enter a password of no more than 20 characters, and click Update or Publish. Share the password only with intended readers. Because everyone uses the same password, this is not an individual login or role-based permission system. WordPress documentation

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check custom fields separately

Password protection does not automatically hide custom-field values if a theme or custom code prints them. A developer should guard custom-field output—for example, by checking post_password_required() before rendering it. WordPress documentation

Restrict the entire site

For a site-wide gate, choose a maintained access-control or force-login plugin, or configure server-level authentication. The right approach depends on whether visitors need separate accounts, different roles, membership features, or only a shared gate. WordPress documentation identifies these routes but does not compare current plugin products. WordPress documentation

Before choosing, check whether the restriction covers every route and media file, how access is granted and revoked, whether your host supports the server configuration, and who maintains the solution. Avoid protecting every page one by one as a substitute for a whole-site gate: per-item visibility is a different control.

WordPress documentation identifies .htaccess and .htpasswd as possible server-level tools, but setup varies by host. Follow your hosting provider’s current instructions rather than copying a generic configuration. After setup, test the site from a logged-out or private browser, including the home page, archives, search, feeds, direct media URLs, and any custom routes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep public content out of search without mistaking it for privacy

To ask search engines not to index an otherwise public site, go to Settings → Reading and enable Discourage search engines from indexing this site. This is an indexing request, not an access restriction: ordinary visitors can still open the site, and crawlers must honor the request. Do not rely on this setting to protect confidential content. WordPress documentation

Do not hide sensitive text with display settings

Hiding a block on mobile, desktop, or another device changes its presentation; it does not secure its contents. WordPress warns that device-based hiding leaves content in the page code and should not be used for private or sensitive information. Use an actual access-control method instead. WordPress documentation

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.