Перейти до вмісту
WordPress.org

Україна

  • Теми
  • Плагіни
  • Новини
  • Підтримка
  • Про
  • Документація
  • Спільнота
  • Завантажити WordPress
Завантажити WordPress
WordPress.org

Plugin Directory

Treder Secure Login Shield

  • Надіслати плагін
  • My favorites
  • Увійти
  • Надіслати плагін
  • My favorites
  • Увійти

Treder Secure Login Shield

Від автора Ben Treder
Завантажити
  • Деталі
  • Відгуки
  • Встановлення
  • Розробка
Підтримка

Опис

Secure Login Shield helps you lock down your WordPress login page.
By default, WordPress exposes /wp-login.php and /wp-admin/. Bots hammer these URLs every day.

This plugin gives you a private login slug (e.g. /dragon-lair) and hides the default login endpoint:

  • Defaults to /wp-login.php until you change it.
  • Once changed, only your custom slug works.
  • Direct access to /wp-login.php shows a 404 Not Found (stealth mode).
  • Logged-out visitors hitting /wp-admin/ are redirected to the homepage.
  • Deactivate the plugin → everything reverts to normal.

Made with ❤️ by Ben Treder

Features

  • Private login slug (e.g. /dragon-lair, /control-center, /secret-gate)
  • Stealth 404 protection: Bots hitting /wp-login.php see “Not Found”
  • Homepage redirect: /wp-admin/ (logged out) → homepage
  • Easy settings page under Settings → Secure Login Shield
  • Safe activation/deactivation: no core hacks, auto-reverts when disabled

Contribute & Support

  • Website: BenTreder.com
  • Author: Ben Treder
  • Issues & Feature Requests: Please open a ticket on BenTreder.com
  • Like this plugin? ⭐ Leave a review and help spread the word!
  • ☕ Support development: Buy Me a Coffee

Скріншоти

Settings page showing the default login slug (/wp-login.php)
Settings page showing the default login slug (/wp-login.php)
Settings page with a custom private slug (/dragon-lair)
Settings page with a custom private slug (/dragon-lair)

Встановлення

  1. Upload the secure-login-shield folder to the /wp-content/plugins/ directory or install via Plugins → Add New → Upload.
  2. Activate the plugin through the “Plugins” menu in WordPress.
  3. Go to Settings → Secure Login Shield.
  4. Set your private slug (example: dragon-lair).
  5. Go to Settings → Permalinks → Save Changes (refresh rewrite rules).
  6. If you use a caching plugin or CDN, clear cache to avoid stale redirects.
  7. Log in using https://yoursite.com/dragon-lair.

Important: Bookmark your new login URL! If you forget it, you’ll need to disable the plugin via FTP or database.

Часті питання

Will this break my site?

No. By default it uses /wp-login.php until you change it. Deactivating the plugin instantly reverts WordPress to normal behavior.

Can I completely block /wp-login.php?

Yes. Once you set a slug, /wp-login.php (and actions) return a 404 Not Found.

What if I forget my private slug?

Deactivate the plugin via FTP (delete or rename secure-login-shield). WordPress will go back to /wp-login.php.

Does this work with caching plugins or CDNs?

Yes, but after changing your slug, you should clear cache/CDN to avoid serving stale redirects.

Відгуки

Great plugin

urosjovanovic 22.09.2025
Secure Login Shield is a great plugin! Easy to use and very effective at protecting your site.
Прочитати всі 1 відгук

Учасники та розробники

“Treder Secure Login Shield” — проект з відкритим вихідним кодом. В розвиток плагіну внесли свій вклад наступні учасники:

Учасники
  • Ben Treder

Перекладіть “Treder Secure Login Shield” на вашу мову.

Цікавитесь розробкою?

Перегляньте код, перегляньте сховище SVN або підпишіться на журнал розробки за допомогою RSS.

Журнал змін

2.0.6

  • Rebranded the visible plugin name to Treder Secure Login Shield.
  • Fixed the WordPress.org contributor username to bdtreder.
  • No slug, ZIP base name, folder name, text domain, settings, or login behavior changes.

2.0.5

  • Corrected WordPress.org release versioning after the Secure Login Shield audit.
  • Confirmed WordPress 7.0 compatibility metadata.
  • Kept the free plugin focused on private login URL protection, stealth 404 behavior, and logged-out wp-admin redirect protection.

1.3.0

  • Rebrand to Secure Login Shield by Ben Treder
  • Default slug remains /wp-login.php (safe on first install)
  • Added activation notice: Save permalinks + clear cache after activation
  • Stealth 404 mode enforced when custom slug is chosen
  • Homepage redirect for logged-out visits to /wp-admin/

1.2.0

  • Added stealth 404 mode
  • Improved security enforcement

1.1.0

  • Redirected /wp-admin/ → homepage for logged-out users

1.0.0

  • Initial release with custom login slug + wp-login.php block

Мета

  • Версія 2.0.6
  • Останнє оновлення 3 місяці тому
  • Активних встановлень Менше 10
  • Версія WordPress 6.0 або вище
  • Tested up to 7.0.4
  • Версія PHP 7.4 або вище
  • Мова
    English (US)
  • Позначки
    custom loginhardeningloginsecuritywp login
  • Розширений перегляд

Оцінки

5 out of 5 stars.
  • 1 5-star review 5 stars 1
  • 0 4-star reviews 4 stars 0
  • 0 3-star reviews 3 stars 0
  • 0 2-star reviews 2 stars 0
  • 0 1-star reviews 1 star 0

Your review

See all reviews

Учасники

  • Ben Treder

Підтримка

Є що сказати? Потрібна допомога?

Перейти в форум підтримки

Пожертвування

Ви хотіли б підтримати розвиток цього плагіна?

Пожертвувати на розвиток плагіна

  • Про нас
  • Новини
  • Хостинг
  • Приватність
  • Вітрина
  • Теми
  • Плагіни
  • Паттерни
  • Навчання
  • Підтримка
  • Розробники
  • WordPress.tv ↗
  • Приєднатися
  • Події
  • Підтримати ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Україна

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Завітайте до нашої стрічки в Mastodon
  • Visit our Threads account
  • Завітайте на нашу сторінку в Facebook
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Код – це поезія.
The WordPress® trademark is the intellectual property of the WordPress Foundation.