Docs / Custom Login URL Lite

    How to change the WordPress login URL and reduce bot brute-force noise

    Custom Login URL Lite moves wp-login.php to a private path you choose, blocking most automated attacks on the default login endpoint.

    Updated 2026-09-29

    Why the default login URL is noisy

    Bots hammer `/wp-login.php` and `/wp-admin` constantly. Even with strong passwords, log noise, failed-login emails, and WAF hits waste time. Changing the login path is a simple first-line filter — not a replacement for MFA or solid hosting security.

    What Custom Login URL Lite does

    You pick a custom slug. The old login paths stop working for casual bots; you (and your team) use the new URL. Reserved slug protection helps avoid colliding with common WordPress routes.

    • Custom login path instead of /wp-login.php
    • Reduces automated brute-force noise
    • Lite footprint — focused on one job
    • Settings under PluginsForStores

    Safe setup checklist

    1) Bookmark the new URL before logging out. 2) Save the slug in your password manager. 3) Test in a second browser. 4) Keep an emergency admin access path via hosting/SFTP if you ever forget the slug.

    Tell collaborators the new URL. Password reset emails and some security plugins may still mention default paths — verify after install.

    FAQ

    View Custom Login URL Lite →