WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

Firewall & login

Change login URL

Rename wp-login.php away from the default path with Security Ninja Pro Rename Login. Slug rules, conflicts, and temporary-login plugins.

Most automated scripts look for the default login URLs /wp-admin/ and wp-login.php.

With Security Ninja Pro you can rename the login path so those scripts have a harder time finding the form.

The setting is under Security Ninja → Firewall → Settings (Rename Login / Change login URL).

Change login URL field on Firewall Settings

Slug rules

The default slug is my-login (URL looks like /my-login/). You can change it.

Allowed characters: letters, numbers, underscore, and hyphen.

  • Works: my_custom-log1n
  • Does not work: my#c%stom-løg!n

Do not reuse the slug of an existing post or page.

Rename Login does not rewrite .htaccess or add rewrite rules. To turn it off, disable the feature in Firewall Settings. If you forget the custom URL, rename the plugin folder over FTP to deactivate Security Ninja, then log in at the default WordPress login.

It does not work with plugins or themes that hardcode links to /wp-admin or wp-login.php.

Temporary login plugins

Rename Login recognizes temporary-login links from Temporary Login Without Password, One Time Login, Magic Login, and Login Links. When that plugin is active, the first wp-admin request is allowed through so the person can finish signing in. Without that, Rename Login would bounce them before the temporary-login plugin could complete the login.

Details: Temporary login plugins.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image