| 开发者 | domainsupport |
|---|---|
| 更新时间 | 2026年8月14日 01:01 |
| 捐献地址: | 去捐款 |
| PHP版本: | 7.0 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
wp-login.php is the standard WordPress endpoint for login, registration and password-reset requests. Its predictable location is frequently targeted by automated bots.
No. It blocks automated traffic aimed at the default wp-login.php address and can reduce the associated server load. If someone discovers the secret login URL, normal WordPress authentication still applies. Use strong unique passwords and other suitable security controls as well.
No. Block wp-login relies on Apache mod_rewrite and .htaccess. Do not activate it on Nginx or another server that does not process Apache .htaccess rules.
Yes. Password-reset emails, reset forms and registration links use the secret login URL. WordPress administration email verification is also supported.
The plugin detects a changed WordPress version and rebuilds its secret copy of the current wp-login.php file. If the server is overloaded, it safely defers that work until a later administrator request.
First check the notification email sent when the URL was configured. If you have command-line access, deactivating the plugin with WP-CLI runs its cleanup routine and restores the default login endpoint. Otherwise, ask your hosting provider or developer to remove the section between # BEGIN BlockWPLogin and # END BlockWPLogin from the WordPress .htaccess file before deactivating the plugin. Take a backup before editing .htaccess.
Go to Settings > Block wp-login, clear the Private login address field and save the settings, or deactivate the plugin normally. The plugin removes its rewrite rules and generated login file.