Hiding wp-login.php behind a custom URL is one of the most common WordPress security tips, and it’s worth doing โ€” but it’s genuinely a small piece of a security setup, not the whole thing. Here’s what the URL swap actually buys you, and what it doesn’t.

What moving the login URL actually stops

The overwhelming majority of brute-force login attempts against WordPress sites come from automated bots blindly requesting /wp-login.php on every domain they can find, with no idea whether WordPress is even running there. Moving the login page to a custom URL (this site runs on one) means that traffic hits a 404 instead of a login form, which quietly removes almost all of that automated noise without you doing anything else. It’s a genuinely good, low-effort change.

What it doesn’t stop

  • A targeted attacker. If someone is specifically trying to get into your site rather than opportunistically scanning thousands of domains, they can usually find the real login URL through other means. This is obscurity, not a lock.
  • A compromised plugin or theme. Moving the login page does nothing if the actual entry point is a vulnerable plugin with direct file access, unrelated to the login form entirely.
  • Weak passwords on the accounts that do exist. If the login form itself is still accepting “password123,” hiding its URL hasn’t fixed the actual weakness.

What an actually solid setup looks like

  • Two-factor authentication on every account with publish or admin access โ€” this stops a leaked or guessed password from being enough on its own.
  • Unique, generated passwords stored in a password manager, not reused from anywhere else.
  • Limited login attempts, so even a correctly-guessed username can’t be brute-forced at speed.
  • Plugins and WordPress core kept current. The large majority of real WordPress compromises trace back to a known, already-patched vulnerability in outdated software, not a clever attack.
  • Least-privilege user roles. A contributor account doesn’t need publish rights, and a client who only edits text doesn’t need admin access to plugins and themes.

The honest summary

Hide the login URL โ€” it’s quick, free, and it genuinely cuts out most of the automated noise. Just don’t let it be the only security measure on the site. It’s one layer in a setup that needs several.