W
Admin & Site Management Free WordPress.org

WPS Hide Login

4.8 (2,110 reviews)
· 2.0M+ active installs · By Remy Perona
Active Installs
2.0M+
Rating
4.8 / 5
Version
v1.9.18
Last Updated
Jan 2026
Share

Plugin Review

AI-Researched

What is WPS Hide Login?

WPS Hide Login is a lightweight security plugin that changes your WordPress login URL to any custom slug you choose. It intercepts page requests without renaming core files or adding rewrite rules. The plugin has been actively maintained for 11 years by Remy Perona, with the latest version 1.9.18 released on January 12, 2026. It currently powers over 2 million active installations and holds a 4.8 out of 5 star rating from 2,110 reviews. An impressive 94% of those ratings are 4% are one-star.

When activated, the default wp-login.php page and wp-admin directory become inaccessible. Your custom login page remains the only entry point. Deactivating the plugin restores your site to its original state without any leftover changes. The plugin requires WordPress 4.1 or higher and PHP 7.0 or newer. It has been tested up to WordPress 6.9.4.

Key Features of WPS Hide Login

  • Custom Login URL – Replace the default wp-login.php with any URL slug you choose, such as /secret-login or /admin-area.
  • No File Modifications – The plugin intercepts page requests dynamically without altering core WordPress files or adding rewrite rules to .htaccess.
  • Full Form Compatibility – Registration forms, lost password forms, login widgets, and expired session handling all continue working with your custom URL.
  • Multisite Network Support – Activate network-wide to set a default login URL for all sites, while individual sites can still customize their own slug.
  • Plugin Integration – Works with BuddyPress, bbPress, Jetpack, WPS Limit Login, and User Switching without conflicts.
  • Cache Plugin Friendly – Fully compatible with WP Rocket out of the box. Other caching plugins require adding your custom slug to the exclusion list.
  • One-Click Reversal – Deactivating the plugin immediately restores the default wp-login.php access and removes all custom URL settings.
  • Database-Based Settings – Your custom login URL is stored in the whl_page option within the WordPress options table (or sitemeta table for multisite networks).

Who Should Use WPS Hide Login?

This plugin suits WordPress users of any skill level who want to reduce automated brute force attacks. Beginners can install it in under two minutes and set a custom URL without touching code. Advanced users appreciate that it does not modify .htaccess files, avoiding conflicts with other security measures. With 2 million active installs and a 4.8 rating, it is one of the most trusted solutions for hiding login pages.

Site owners running membership platforms, ecommerce stores, or client portals benefit most from obscuring the login path. The plugin works on any WordPress site running version 1.9.18 or higher. It is also compatible with multisite networks using subdomains or subfolders. Note that plugins or themes with hardcoded wp-login.php references will not work correctly with this plugin.

Installation & Setup

Install WPS Hide Login directly from the WordPress plugin repository by searching for it in Plugins › Add New. After activation, you are redirected to the settings page where you enter your desired login URL slug. The entire process takes less than 60 seconds and requires no technical knowledge. You can change the custom URL at any time from Settings › WPS Hide Login in your WordPress admin panel.

Support & Community

Support is limited for this plugin, as stated by the developer: "This plugin is only maintained, which means we do not guarantee free support." Over the past two months, there were 14 open support threads and only 2 resolved, giving a 46% resolution rate. The rating breakdown reveals strong user satisfaction despite the limited support—94% of 2,110 ratings are five stars. The 3% one-star ratings typically involve lockout scenarios, which the FAQ addresses by advising users to check their .htaccess file or remove the plugin folder via FTP to regain access.

Pros & Cons

What's Good
  • With over 2 million active installs and a 4.8/5 rating from 2,110 reviews, it is one of the most trusted plugins for hiding the login URL.
  • It does not modify core files or add rewrite rules, making it safe to activate and deactivate without leaving permanent changes.
  • The plugin intercepts page requests to make wp-login.php and wp-admin inaccessible, reducing exposure to automated brute-force attacks.
  • It is lightweight and works on any WordPress site, requiring minimal setup to change the login URL to any custom slug.
Drawbacks
  • Only 2 of 14 total support threads are resolved, giving a 46% resolution rate, indicating limited free support for users.
  • The plugin does not provide any notification or warning if the custom login URL is forgotten, potentially locking users out of their site.
  • It offers no additional security features beyond hiding the login URL, such as two-factor authentication or login attempt limits.

Technical Details

Requires WordPress
4.1+
Requires PHP
7.0+
Tested up to WP
6.9.4
First Released
2015 (11+ years)
Support (last 2 months)
13 threads  —  46% resolved

Feature Tags

custom-login-url login rename wp-login wp-login-php

Frequently Asked Questions