Changing the WordPress login address

Every WordPress in the world has its door in the same place: /wp-admin and /wp-login.php. Moving it to an address only you know means automated scanners stop knocking on it.

This is not security: it is housekeeping. Anyone who learns the new address can still try passwords, and there are ways to find it. The real gain is different and it is concrete: the site stops spending resources answering thousands of automated attempts a day. Do this after the things that genuinely count, which are in protecting the WordPress login.

How it is done

You do not change it in wp-config.php and you do not rename wp-login.php: a WordPress update would put it all back. It is done with a plugin built for it, which intercepts the request before WordPress answers it.

1 Choose the new address before installing anything. A word nobody would guess, and not login, admin or signin. Write it somewhere you will find it in six months.
2 In the dashboard, Plugins › Add New, look for a login-address plugin and install it. There are several in the official repository; pick one with many active installations and updated this year.
3 In its settings, enter the new address and choose where anyone trying the old one ends up. A 404 page is better than a message announcing that it is hidden.
4 Before saving, open a private window and leave it aside. If something goes wrong, you still have the signed-in session in the normal window to undo it.
5 Save. Test the new address in the private window. Only once you have got in there should you close the other.
The moment you save, the old address dies. It is immediate and there is no warning. Closing the window without having noted the new one leaves you locked out of your own site.

If you locked yourself out

There is a fix and you do not need to ask us for anything. The plugin is disabled through its folder:

1 In cPanel, open File Manager and go to public_html/wp-content/plugins.
2 Find the folder of the plugin that moved the address and rename it, adding -off at the end.
3 WordPress stops finding it, disables it, and /wp-login.php works again. Sign in, and only then put the folder name back.

If that is not it, the cause may be something else: cannot get into the WordPress dashboard.

What breaks, and how to fix it

What breaks What to do
Saved shortcuts Bookmarks and the password manager still point at the old address. Update them the same day, or you are guaranteed to forget.
The cached login page If you run a caching plugin, exclude the new address. A cached login page produces strange session errors: installing and tuning a page cache.
Tools that sign in by themselves Monitoring services, external backup services or multi-site managers may be using the old address. Update their settings.
Nothing in the mobile apps The WordPress app does not use the login form, so it carries on working. Which is also why hiding the door is not enough.
This does not protect xmlrpc.php. Anyone trying passwords in bulk uses that door, which never touches the login form and so is unaffected by the change. If the site still sees many attempts after this, that is almost certainly where they are: see the xmlrpc.php section in protecting the WordPress login.

What to do next

With the address moved, the two things that add most are a captcha on the form, for the attempts that remain (putting a captcha on the login), and a server-level password in front of the WordPress one, explained in the login protection article.

And if the reason for all this was a site slowed down by the attempts, confirm the gain in the consumption figures: monitoring your site performance in cPanel.

Locked yourself out and cannot reach File Manager either?

Open a request

SEE ALSO

Password generator

WordPress hosting

Support Policy

RECOMMENDED PRODUCT

WordPress hosting

One-click install, updates handled, and speed that holds up.

See plans
  • 0 Users Found This Useful
Was this answer helpful?