Linux 软件免费装
Banner图

LoginHush – Private Login URL & Access Guard

开发者 jayanta77
更新时间 2026年8月7日 21:17
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

security login custom login url wp-admin hide login

下载

1.5.1

详情介绍:

LoginHush replaces the public WordPress login address with a private path without renaming core files. Its optional security layer uses transients for active rate limits and one compact indexed table for the activity log. On Apache sites using Plain permalinks, it maintains one narrowly scoped rule inside a dedicated LoginHush section of .htaccess. The plugin starts disabled after activation. An administrator must test the candidate path successfully in the browser before protection can be enabled. This prevents the most common accidental lockout scenario. Features Security scope Changing the login URL and limiting failed attempts reduce common automated login traffic. They are defensive layers, not replacements for strong passwords, software updates, or two-factor authentication. LoginHush does not block XML-RPC authentication. When activity logging is enabled, it stores masked IP addresses, site-salted hashes, event metadata, and hashed login identities for the configured retention period. Raw IP addresses and usernames are not stored in the log. Email and webhook connections occur only when explicitly enabled.

安装:

  1. Upload the loginhush-private-login-url-access-guard folder to /wp-content/plugins/ or install the ZIP from Plugins > Add New.
  2. Activate LoginHush.
  3. Open Settings > LoginHush.
  4. Choose or generate a private path.
  5. Select "Test this path" and wait for the success message.
  6. Enable protection, save, and bookmark the private URL.
  7. If page caching is active, exclude the private path from the page cache.

常见问题:

I forgot the private URL. How do I recover access?

Use wp loginhush url with WP-CLI. To disable protection, run wp loginhush disable. Without WP-CLI, add this line above the "stop editing" line in wp-config.php: define( 'LOGIPRLO_DISABLE_PROTECTION', true ); The standard wp-login.php URL will work while that constant is true. You can also deactivate the plugin by renaming its folder.

Does LoginHush modify WordPress files or .htaccess?

It never modifies WordPress core files. On Apache sites using Plain permalinks, it adds a dedicated LoginHush marker containing only the configured private-path rule. The marker is updated when the path changes and removed on deactivation or uninstall.

Does this stop every brute-force attack?

No. It reduces traffic aimed at the standard browser login URL. Use it with strong passwords, rate limiting, and two-factor authentication where appropriate.

Does it work with caching plugins?

The private login path must not be page-cached. LoginHush displays a warning when it detects common page-caching configurations, but cache exclusions remain provider-specific.

更新日志:

1.5.1 1.5.0 1.4.0 1.3.4 1.3.3 1.3.2 1.3.1 1.3.0 1.2.2 1.2.1 1.2.0 1.1.0 1.0.2 1.0.1 1.0.0