WordPress WPS Hide Login Plugin

WPS Hide Login is a WordPress plugin that obfuscates the login page for a WordPress install.

It doesn’t literally rename or change files in core, nor does it add rewrite rules. It simply intercepts page requests and works on any WordPress website. The wp-admin directory and wp-login.php page become inaccessible, so you should bookmark or remember the url. Deactivating this plugin brings your site back exactly to the state it was before.

Honestly, I did this more to stop an annoyance than anything. There are tons of bots out there that try to do credential stuffing and dictionary attacks against even tiny sites like mine.

They’re unlikely to get past my strong password and 2FA, but it was getting annoying to see the constant stream of “user X has been locked out for 4 hours.”

I used the WPS Hide Login to set my login page to a random 16 character alphanumeric string that would be essentially impossible to guess.

Leave a Reply