Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To restrict an entire WordPress site to approved visitors, use a maintained access-control plugin or server-level authentication: WordPress core does not provide a whole-site privacy switch. Core visibility settings can hide individual posts or pages, while the “Discourage search engines from indexing this site” option only asks crawlers not to index public content.
Choose the privacy control that matches your goal
| What you want | Use | Who can view it |
|---|---|---|
| Hide an individual post or page from ordinary visitors | Set its visibility to Private | Authorized WordPress roles, such as Editors and Administrators; this is not access for every registered user. WordPress documentation |
| Share an individual post or page with people using one common password | Set its visibility to Password Protected | Anyone who has the shared password; it does not create individual accounts. WordPress limits post passwords to 20 characters. WordPress documentation |
| Restrict the whole site to logged-in or otherwise approved visitors | Use an access-control plugin or server-level restriction | Depends on how you configure the chosen solution; core’s per-item visibility settings do not lock the whole site. WordPress documentation |
| Keep a public site out of search results where crawlers honor the request | Enable Search Engine Visibility in Settings → Reading | Public access remains enabled. WordPress documentation |
Make an individual post or page private
Use Private when the content is for authorized site roles, such as Editors or Administrators, rather than the general public. In the editor, open the post or page’s visibility controls, choose Private, then click Update or Publish to apply the change. This setting is for that item; it does not turn a whole blog into a private site. WordPress documentation
Password-protect an individual post or page
Use Password Protected when a shared secret is sufficient for a particular item. In the editor’s visibility controls, choose Password Protected, enter a password of no more than 20 characters, and click Update or Publish. Share the password only with intended readers. Because everyone uses the same password, this is not an individual login or role-based permission system. WordPress documentation
Free tools Windows power users keep installed
One-click scans. No signup required.
Check custom fields separately
Password protection does not automatically hide custom-field values if a theme or custom code prints them. A developer should guard custom-field output—for example, by checking post_password_required() before rendering it. WordPress documentation
#1 Best Overall
Restrict the entire site
For a site-wide gate, choose a maintained access-control or force-login plugin, or configure server-level authentication. The right approach depends on whether visitors need separate accounts, different roles, membership features, or only a shared gate. WordPress documentation identifies these routes but does not compare current plugin products. WordPress documentation
Before choosing, check whether the restriction covers every route and media file, how access is granted and revoked, whether your host supports the server configuration, and who maintains the solution. Avoid protecting every page one by one as a substitute for a whole-site gate: per-item visibility is a different control.
WordPress documentation identifies .htaccess and .htpasswd as possible server-level tools, but setup varies by host. Follow your hosting provider’s current instructions rather than copying a generic configuration. After setup, test the site from a logged-out or private browser, including the home page, archives, search, feeds, direct media URLs, and any custom routes.
Recommended Free Tools
Keep public content out of search without mistaking it for privacy
To ask search engines not to index an otherwise public site, go to Settings → Reading and enable Discourage search engines from indexing this site. This is an indexing request, not an access restriction: ordinary visitors can still open the site, and crawlers must honor the request. Do not rely on this setting to protect confidential content. WordPress documentation
Do not hide sensitive text with display settings
Hiding a block on mobile, desktop, or another device changes its presentation; it does not secure its contents. WordPress warns that device-based hiding leaves content in the page code and should not be used for private or sensitive information. Use an actual access-control method instead. WordPress documentation
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

