{"id":611,"date":"2026-06-29T11:28:58","date_gmt":"2026-06-29T11:28:58","guid":{"rendered":"https:\/\/brutefort.com\/blog\/how-to-change-wordpress-login-url\/"},"modified":"2026-07-15T13:47:42","modified_gmt":"2026-07-15T13:47:42","slug":"how-to-change-wordpress-login-url","status":"publish","type":"post","link":"https:\/\/brutefort.com\/blog\/how-to-change-wordpress-login-url\/","title":{"rendered":"How to Change Your WordPress Login URL (And Why It Matters)"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1125\" height=\"750\" src=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/06\/pexels-photo-326501.jpeg\" alt=\"URL bar in browser showing custom WordPress login URL slug\" class=\"wp-image-610\" srcset=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/06\/pexels-photo-326501.jpeg 1125w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/06\/pexels-photo-326501-300x200.jpeg 300w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/06\/pexels-photo-326501-1024x683.jpeg 1024w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/06\/pexels-photo-326501-768x512.jpeg 768w\" sizes=\"auto, (max-width: 1125px) 100vw, 1125px\" \/><figcaption>Photo by Pixabay from Pexels<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Every WordPress site uses the same default login address: <code>\/wp-login.php<\/code>. Bots that run brute force attacks don&#8217;t have to search for it. They already know exactly where it lives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s not a flaw specific to your site. It&#8217;s true of every WordPress install by default, which is exactly why automated login-page scanning is so widespread across the web.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Changing your login URL to something unpredictable closes that gap in under a minute. This guide walks through doing it with BruteFort&#8217;s Custom Login URL feature, picking a slug that&#8217;s actually secure, and pairing it with rate limiting for full coverage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Quick Answer:<\/strong> In BruteFort, go to <strong>Settings \u2192 Custom Login URL<\/strong>, toggle it on, enter a slug that isn&#8217;t &#8220;login,&#8221; &#8220;admin,&#8221; or your brand name, and click <strong>Save<\/strong>. Test the new URL in a private window before closing your current admin session \u2014 the default <code>\/wp-login.php<\/code> will return a 404 afterward.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why the Default Login URL Is a Security Problem<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Automated bots scan IP ranges and domain lists looking for known WordPress paths. Finding <code>\/wp-login.php<\/code> confirms a WordPress installation and marks the site for credential testing. This scanning happens around the clock, and it targets sites of all sizes \u2014 a personal blog with ten visitors a day gets the same automated probing as a high-traffic WooCommerce store.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hiding your login page doesn&#8217;t replace rate limiting \u2014 you should have both \u2014 but it stops the attack before it even starts. A bot that can&#8217;t find your login form can&#8217;t submit credentials to it. It&#8217;s the difference between locking your door and making the door invisible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Change Your WordPress Login URL with BruteFort<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">BruteFort&#8217;s Custom Login URL feature is built specifically for this. Here&#8217;s how to set it up:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Go to <strong>BruteFort \u2192 Settings<\/strong> in your WordPress admin.<\/li><li>Click the <strong>Custom Login URL<\/strong> tab.<\/li><li>Toggle <strong>Enable Custom Login URL<\/strong> on.<\/li><li>Enter your chosen slug in the <strong>Login Slug<\/strong> field. This becomes the new path: <code>https:\/\/yoursite.com\/your-slug<\/code>. Pick something unpredictable \u2014 not &#8220;login,&#8221; &#8220;admin,&#8221; or &#8220;wp,&#8221; as these are commonly scanned too.<\/li><li>Click <strong>Save<\/strong>.<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"589\" src=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-custom-login-url.webp\" alt=\"BruteFort Custom Login URL panel with enable toggle and login slug field\" class=\"wp-image-671\" srcset=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-custom-login-url.webp 1024w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-custom-login-url-300x173.webp 300w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-custom-login-url-768x442.webp 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<div class=\"wp-block-callout\"><p><strong>Important:<\/strong> Write down your custom slug before saving. Once the change is active, the default <code>\/wp-login.php<\/code> URL will return a 404. If you forget the slug, you may be locked out of your own site.<\/p><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">After saving, test the new URL in a private browsing window before closing your current admin session. Confirm <code>\/wp-login.php<\/code> now returns a 404, and your new URL loads the login form correctly.<\/p>\n\n\n\n<div class=\"wp-block-stackable-button-group stk-block-button-group stk-block stk-1d8b53f\" data-block-id=\"1d8b53f\"><div class=\"stk-row stk-inner-blocks stk-block-content stk-button-group\">\n<div class=\"wp-block-stackable-button stk-block-button stk-block stk-6e2a0c7\" data-block-id=\"6e2a0c7\"><style>.stk-6e2a0c7 .stk-button{background:#f13434 !important;border-top-left-radius:var(--stk--preset--border-radius--small, 4px) !important;border-top-right-radius:var(--stk--preset--border-radius--small, 4px) !important;border-bottom-right-radius:var(--stk--preset--border-radius--small, 4px) !important;border-bottom-left-radius:var(--stk--preset--border-radius--small, 4px) !important;}.stk-6e2a0c7 .stk-button:before{border-color:#0f0e17 !important;}<\/style><a class=\"stk-link stk-button stk--hover-effect-darken\" href=\"https:\/\/brutefort.com\/blog\/best-security-plugins-wordpress\/\"><span class=\"stk-button__inner-text\">Get BruteFort Now!<\/span><\/a><\/div>\n<\/div><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Choosing a Good Login Slug<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A good custom login slug is unpredictable but easy for you to remember. Avoid:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Common words like <code>login<\/code>, <code>admin<\/code>, <code>dashboard<\/code>, <code>signin<\/code>, <code>access<\/code> \u2014 these are included in scanner wordlists<\/li><li>Your domain name or brand name, which is guessable<\/li><li>Very short slugs that are easily brute-forced by URL scanners<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Something like <code>my-panel-2024<\/code> or a short phrase meaningful to you but not publicly associated with your site works well. The goal is unpredictability, not complexity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Using Both a Custom Login URL and Rate Limiting Together<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A custom login URL is a strong first layer \u2014 it eliminates the bulk of automated bot traffic that targets the default <code>\/wp-login.php<\/code> path. But it isn&#8217;t the only layer you need. An attacker who discovers your custom URL through other means \u2014 a leaked link, a sitemap, or an exposed admin menu \u2014 can still attempt logins against it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">BruteFort&#8217;s rate limiting applies to your custom login URL as well as the default path. With both enabled, your login page is both hidden from automated scanners and rate-limited against anyone who does find it.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"589\" src=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-rate-limiting-settings.webp\" alt=\"BruteFort Rate Limit Settings tab showing rate limits and lockout settings together\" class=\"wp-image-672\" srcset=\"https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-rate-limiting-settings.webp 1024w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-rate-limiting-settings-300x173.webp 300w, https:\/\/brutefort.com\/blog\/wp-content\/uploads\/2026\/07\/brutefort-rate-limiting-settings-768x442.webp 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">That combination covers the vast majority of WordPress login attack scenarios without any ongoing maintenance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions About Changing the WordPress Login URL<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Will changing the login URL break anything on my site?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. Changing the login URL with BruteFort doesn&#8217;t touch your theme, content, or WordPress database structure. It simply redirects login requests to the new path and returns a 404 for the old one. Plugins that link directly to <code>\/wp-login.php<\/code> in their admin interfaces may need their settings updated, but this is uncommon for well-maintained plugins.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What if I forget my custom login slug?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you forget the slug and can&#8217;t access your admin, you can recover it via FTP or your hosting file manager. Connect to your site, open the WordPress database via phpMyAdmin, and look in the <code>wp_options<\/code> table for the BruteFort login slug option. Alternatively, deactivating the BruteFort plugin via FTP (by renaming its plugin folder) will restore the default login URL temporarily.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does this work with WooCommerce and membership plugins?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes. WooCommerce, most membership plugins, and other tools that use WordPress&#8217;s authentication system will use your new login URL automatically. The WordPress authentication system itself hasn&#8217;t changed \u2014 only the URL that reaches it. Custom login page plugins that create entirely separate login interfaces may need separate configuration.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is hiding the login URL enough to stop all attacks?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It stops the automated bots that target the default path \u2014 which is the source of most WordPress login attack volume. It doesn&#8217;t stop a targeted attacker who already knows your custom URL. That&#8217;s why combining it with BruteFort&#8217;s rate limiting is the recommended approach: the custom URL stops mass scanning, and rate limiting stops anyone who finds the URL from attempting more than a handful of credentials.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">Changing your WordPress login URL is a 60-second setup that eliminates a huge proportion of automated attack traffic. <a href=\"https:\/\/wordpress.org\/plugins\/brutefort\/\" target=\"_blank\" rel=\"noopener\">BruteFort<\/a> handles it from the Custom Login URL tab \u2014 no code required, no server configuration needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You might also like:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/brutefort.com\/blog\/how-to-limit-login-attempts-wordpress\/\">How to Limit Login Attempts in WordPress (Step by Step)<\/a><\/li><li><a href=\"https:\/\/brutefort.com\/blog\/how-bots-attack-wordpress\/\">How Bots Attack WordPress Sites (And How to Stop Them)<\/a><\/li><li><a href=\"https:\/\/brutefort.com\/blog\/wordpress-login-security\/\">WordPress Login Security: How to Protect Your Site from Unauthorized Access<\/a><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Every WordPress site has the same login URL by default \u2014 and bots exploit that. Here&#8217;s how to change it in 60 seconds with BruteFort and why it matters.<\/p>\n","protected":false},"author":1,"featured_media":610,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[35],"tags":[],"class_list":["post-611","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-access-control"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts\/611","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/comments?post=611"}],"version-history":[{"count":1,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts\/611\/revisions"}],"predecessor-version":[{"id":700,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/posts\/611\/revisions\/700"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/media\/610"}],"wp:attachment":[{"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/media?parent=611"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/categories?post=611"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/brutefort.com\/blog\/wp-json\/wp\/v2\/tags?post=611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}