Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Allows you to Change your WordPress WebSite Login URL Slug.
Admin Login URL Change is a WordPress plugin that allows you to change the URL of your login form page to a custom address. It intercepts page requests without altering core files, making it a lightweight solution for enhancing login security. By renaming the login URL, it aims to protect your site from automated attacks targeting the default login paths.
This plugin is suited for WordPress site owners looking to improve their site's security by obscuring the login page. It is particularly useful for those who want a straightforward way to reduce the risk of brute-force login attempts.
Best for: WordPress site owners seeking to enhance their login security.
What it does well
Where it falls short
Admin Login URL Change provides a simple and effective way to secure your login page. While it lacks advanced features found in the Pro version, it serves its purpose well for basic security needs.
Jahid Hasan's own description of Admin login URL Change, lightly tidied.
Admin login URL Change is a very lightweight, highly secure plugin that lets you easily and safely change the URL of the login form page to anything you want. It does not change any core files. It simply intercepts page requests and works on any WordPress website. This is great for your convenience, but it also closes the door to would-be brute-force attackers.
Why Use Admin Login URL Change?
WordPress websites are common targets for automated bots and hackers attempting to gain unauthorized access via brute-force login attempts. The default login URLs (wp-login.php and wp-admin) are widely known, making them easy targets. Admin Login URL Change solves this problem by letting you rename your login URL to something unique, effectively closing this security loophole.
Upgrade to the Pro Version to unlock elite-level protection mechanisms:
* IP Address Blocker: Block individual IPs or entire CIDR ranges from even accessing your custom login page, featuring auto-ban thresholds, ban durations, and email alerts.
* Searchable Country Blocker: Restrict login access to specific countries using a live, search-filtered database of 200+ global regions.
* Login Attempt Limiter: Set max retries, retry windows, lockout durations, and display warning alerts to prevent dictionary and brute-force attacks.
* Two-Factor Authentication (2FA): Add an ironclad second layer of verification via Authenticator Apps (Google Authenticator, Authy, Microsoft Authenticator) or Email OTP.
* Login Alerts: Receive instant email notifications whenever someone successfully logs in or fails to log in — with IP, username, and timestamp included.
* Full Login Audit Log: Unlimited login history (up to 500 entries) with user-agent details, replacing the free 10-entry limit.
How to use the plugin
madmin).Other plugins for securing a site.
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...