How to change the WordPress login URL and reduce bot brute-force noise
Custom Login URL Lite moves wp-login.php to a private path you choose, blocking most automated attacks on the default login endpoint.
Updated 2026-09-29
Why the default login URL is noisy
Bots hammer `/wp-login.php` and `/wp-admin` constantly. Even with strong passwords, log noise, failed-login emails, and WAF hits waste time. Changing the login path is a simple first-line filter — not a replacement for MFA or solid hosting security.
What Custom Login URL Lite does
You pick a custom slug. The old login paths stop working for casual bots; you (and your team) use the new URL. Reserved slug protection helps avoid colliding with common WordPress routes.
- Custom login path instead of /wp-login.php
- Reduces automated brute-force noise
- Lite footprint — focused on one job
- Settings under PluginsForStores
Safe setup checklist
1) Bookmark the new URL before logging out. 2) Save the slug in your password manager. 3) Test in a second browser. 4) Keep an emergency admin access path via hosting/SFTP if you ever forget the slug.
Tell collaborators the new URL. Password reset emails and some security plugins may still mention default paths — verify after install.