Linux 软件免费装
Banner图

Block wp-login

开发者 domainsupport
更新时间 2026年8月14日 01:01
捐献地址: 去捐款
PHP版本: 7.0 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security custom login url login security brute force hide login

下载

1.2.2 1.2.3 1.2.4 1.3.0 1.3.1 1.3.2 1.3.4 1.3.5 1.3.6 1.3.7 1.3.8 1.3.9 1.4.0 1.4.2 1.4.3 1.4.8 1.4.6 1.5.2 1.1.6 1.4.1 1.1.3 1.4.9 1.5 1.4.5 1.1.5 1.1.7 1.2.0 1.2.1 1.3.3 1.4.7 1.5.1 1.5.3 1.5.4 1.5.5 1.5.6 1.5.7 1.1.4 1.4.4 1.5.8

详情介绍:

Block wp-login.php and use a secret login URL Block wp-login prevents automated requests from reaching the default WordPress login endpoint. It creates a secret login URL for authorised users and adds Apache rewrite rules that return a 403 Forbidden response for direct requests to wp-login.php. Because blocked requests are rejected before WordPress loads, the plugin can reduce the server resources consumed by bots repeatedly targeting wp-login.php. Features include: Important compatibility information Block wp-login requires an Apache web server with mod_rewrite and a writable .htaccess file in the WordPress root directory. It is not compatible with Nginx or servers that do not honour .htaccess rules. Hiding the default login endpoint reduces automated login traffic, but it is not a replacement for strong passwords, two-factor authentication, updates, backups or other appropriate security controls.

安装:

Before installing, confirm that the site runs on Apache and that WordPress can write to its root directory and .htaccess file.
  1. Install Block wp-login from Plugins > Add New, or upload the plugin ZIP file.
  2. Activate the plugin.
  3. Go to Settings > Block wp-login.
  4. Enter a memorable login slug using letters and numbers, or generate a random one.
  5. Select the administrator notification option if you want the new login URL sent by email.
  6. Save the settings.
  7. Copy and bookmark the displayed login URL.
  8. Keep your current administrator session open while you test the new URL in a private or incognito browser window.
After configuration, direct requests to wp-login.php should return 403 Forbidden. Use the secret URL for login, registration and password-reset requests.

升级注意事项:

1.5.8
  • Adds a dedicated settings page and improves activation, filesystem and WordPress core-update reliability.

常见问题:

What is wp-login.php?

wp-login.php is the standard WordPress endpoint for login, registration and password-reset requests. Its predictable location is frequently targeted by automated bots.

Does this plugin stop every brute-force attack?

No. It blocks automated traffic aimed at the default wp-login.php address and can reduce the associated server load. If someone discovers the secret login URL, normal WordPress authentication still applies. Use strong unique passwords and other suitable security controls as well.

Does it work with Nginx?

No. Block wp-login relies on Apache mod_rewrite and .htaccess. Do not activate it on Nginx or another server that does not process Apache .htaccess rules.

Can users reset their passwords or register?

Yes. Password-reset emails, reset forms and registration links use the secret login URL. WordPress administration email verification is also supported.

What happens after a WordPress core update?

The plugin detects a changed WordPress version and rebuilds its secret copy of the current wp-login.php file. If the server is overloaded, it safely defers that work until a later administrator request.

What should I do if I forget the secret login URL?

First check the notification email sent when the URL was configured. If you have command-line access, deactivating the plugin with WP-CLI runs its cleanup routine and restores the default login endpoint. Otherwise, ask your hosting provider or developer to remove the section between # BEGIN BlockWPLogin and # END BlockWPLogin from the WordPress .htaccess file before deactivating the plugin. Take a backup before editing .htaccess.

How do I return to the standard WordPress login URL?

Go to Settings > Block wp-login, clear the Private login address field and save the settings, or deactivate the plugin normally. The plugin removes its rewrite rules and generated login file.

更新日志:

1.5.8 1.5.7 1.5.6 1.5.5 1.5.4 1.5.3 1.5.2 1.5.1 1.5 1.4.9 1.4.8 1.4.7 1.4.6 1.4.5 1.4.4 1.4.3 1.4.2 1.4.1 1.4.0 1.3.9 1.3.8 1.3.7 1.3.6 1.3.5 1.3.4 1.3.3 1.3.2 1.3.1 1.3.0 1.2.4 1.2.3 1.2.2 1.2.1 1.2.0 1.1.7 1.1.6 1.1.5 1.1.4 1.1.3 1.1.2 1.1.1 1.1.0 1.0.0