Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To password-protect one WordPress post or page, change its visibility from Public to Password Protected in the editor, enter a shared password, then click Publish or Update. Visitors will see a password prompt before they can read the content. The built-in setting is for individual posts and pages, not the whole site.

Password-protect a post or page in the block editor

  1. Open the post or page in the WordPress block editor.
  2. In the settings sidebar, open Status & Visibility.
  3. Select the current visibility setting, which is usually Public, and choose Password Protected.
  4. Enter the shared password in the field that appears and confirm the setting.
  5. Click Publish for a new item or Update for an existing one. The change does not take effect until you save it.

WordPress’s block-editor visibility guide and password-protection guide describe this built-in process. Visitors will see the post title and a password form; after entering the correct password, they can read the protected content. It is a shared post password, not a WordPress account login.

Use the Classic Editor

  1. Open the post or page for editing.
  2. In the Publish panel, select Edit beside Visibility.
  3. Choose Password Protected, enter the password, and confirm.
  4. Click Publish or Update to save the change.

The visibility control is in a different place in the Classic Editor, as shown in WordPress’s Classic Editor visibility guide. The block editor became WordPress’s default with version 5.0 in December 2018; the block editor guide covers that editing experience.

Choose the right visibility setting

Setting Who can view the content? What the reader sees
Public Any visitor after publication The published content
Password Protected A visitor who enters the shared post password A password prompt before the content
Private Authorized WordPress users, such as Editors or Administrators Ordinary visitors cannot view the item

Use Password Protected when visitors should be able to read an individual item with a shared password. Use Private when access should be limited to authorized site users; it is not a visitor-facing password gate. WordPress notes that Editors and Administrators can view and modify protected posts in the editing interface without entering the post password. See the WordPress.org block-editor visibility and Classic Editor visibility documentation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the password setting does—and does not do

Password length and who can change it

WordPress.org’s password-protection documentation, last updated May 15, 2026, specifies a limit of 20 characters for a post password. An Administrator, Editor, or the post’s Author can change the password or visibility. Save any change with Publish or Update.

Prompts and multiple protected posts

WordPress stores the password in a browser cookie to avoid asking readers repeatedly. WordPress.org states, “WordPress will only track one password at a time.” If a reader moves between posts protected by different passwords, WordPress may ask for the relevant password again. Reusing one password across posts can reduce repeat prompts, but anyone who knows it may be able to access every post using that password.

Titles, excerpts, and custom fields

WordPress changes the public presentation of a protected post: it adds “Protected: ” to the title, replaces the excerpt with a protected-post notice, and replaces the content with a password form. However, the post-password mechanism does not automatically hide custom-field data. If a theme or custom code displays sensitive custom-field values, those outputs need separate conditional handling.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Protecting the whole site

The built-in visibility setting applies to an individual post or page. WordPress.org says restricting an entire blog or limiting it to selected users is not part of WordPress core. For that broader requirement, an access-control or membership plugin may be appropriate; check a plugin’s current maintenance, compatibility, and specific features before choosing one. A plugin is not needed to password-protect a single post or page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.