Hide Login Secure · v1.0.0 Submitted to WordPress.org

Stop Brute-Force Attacks
Before They Start.

The lightweight, zero-bloat WordPress login protection plugin. Hide your login page, enforce signed access tokens, and block unauthorized IP attempts instantly.

Currently under review on WordPress.org. Download the .zip directly from GitHub to install it now!

How to Install in WordPress

  1. Click the Download Plugin button above to get the latest .zip file.
  2. Go to your WordPress Dashboard → PluginsAdd New Plugin.
  3. Click Upload Plugin at the top, choose the downloaded .zip file, and click "Install Now".
  4. Activate the plugin.
  5. Configure: Go to Settings → Hide Login in your WordPress admin menu to set your secret URL and security options.
Hide Login Secure Features

Why Choose This Plugin?

Built from the ground up to solve real security problems without slowing down your site.

True URL Hiding

Completely removes `wp-login.php` from public view and HTML source code. Bots can't find what isn't there.

Signed Access Tokens

Uses HMAC-SHA256 signed, short-lived cookies. Even if someone guesses your URL, they can't access the login form without a valid token.

Cloudflare Aware

Securely detects real visitor IPs behind Cloudflare proxies. No IP spoofing vulnerabilities. Full IPv4/IPv6 & CIDR support.

Zero Bloat

No heavy JavaScript, no external API calls on the frontend. Pure, optimized PHP that won't impact your Core Web Vitals.

Passkey & 2FA Friendly

Unlike older plugins that break modern auth, our architecture ensures WordPress 6.3+ Passkeys and 2FA plugins work flawlessly.

Smart Null Routing

Returns a 403 Forbidden error to malicious scanners, wasting their resources and protecting your server load.

Live Preview

Clean & Intuitive Admin Interface

No bloated menus or confusing options. Everything you need to secure your login page is organized in one clean settings panel.

Hide Login Settings

by Hide Login Secure · Jacker Architect

Hidden Entry URL: https://example.com/my-login/

Note: If you encounter a 404 error on first use, please visit Settings > Permalinks and click "Save Changes" to refresh rewrite rules.

Login Slug

Enter a single URL slug (lowercase letters, numbers, and hyphens only). Example: my-login

Login Protection Mode
Unauthorized Request Response
Cookie Security
Whitelist IPs
IPv4 or IPv6. CIDR supported:
IPv4 (0-32), IPv6 (0-128). One per line.
Security Note: Cloudflare headers are only trusted if the request originates from an official Cloudflare IP range.

↑ Sample IPs shown for demonstration

Blacklist IPs
IPv4 or IPv6. CIDR supported:
IPv4 (0-32), IPv6 (0-128). One per line.
Note: Blacklist always takes priority over Whitelist.

↑ Sample IPs shown for demonstration

Security Options

Danger Zone

Reset all plugin settings to their default values. Your secret URL will revert to the default.


Data Retention on Plugin Deletion:

Login Events — Last 300 Entries (5 total) · sample data

ID Username Event Time User IP Actions
5 test_user 2026-09-03 08:24:15 192.0.2.1 (example)
4 demo_admin 2026-09-02 16:21:11 198.51.100.45 (example)
3 root 2026-09-01 22:45:03 203.0.113.78 (example)
2 editor 2026-08-31 12:39:23 192.0.2.52 (example)
1 subscriber 2026-08-31 10:48:29 198.51.100.52 (example)
5 items
1
Note: The data above is sample data for demonstration purposes. Your actual login events will appear here after activation.

A preview of the actual Hide Login Secure settings page inside WordPress.

The Story

Why I Built This Plugin

This plugin was born from frustration. Like many WordPress site owners, I was constantly battling brute-force attacks, suspicious login attempts, and bloated security plugins that slowed down my site to a crawl.

I needed something lightweight, effective, and modern — that respects Core Web Vitals and works seamlessly with WordPress 6.3+ Passkeys. Existing solutions were either too heavy or broke modern authentication features.

So I built it myself. No tracking, no upsells, no bloat. Just pure, lightweight security that does one thing exceptionally well: protecting your login page.

Jacker Architect

Independent Developer & Security Enthusiast

Coming Soon

Pro Version (In Development)

Based on user feedback, I'm working on advanced features for those who need enterprise-grade login protection.

Smart Auto-Ban

Automatically block IPs after X failed login attempts. Set custom thresholds and ban durations.

Forced 2FA/Passkey

Disable password login for Administrators entirely. Force biometric or TOTP authentication only.

Country Blocking

Block login attempts from specific countries using GeoIP database. Perfect for region-specific businesses.

Real-time Alerts

Email notifications for suspicious login attempts, failed authentications, and security events.

Unlimited Logs

Store unlimited login events with advanced filtering, search, and export capabilities.

Emergency Recovery

Master recovery system with one-time emergency access tokens for locked-out administrators.

Want to influence Pro development? Your feedback shapes the roadmap.

Suggest a Feature

Support Independent Development

This plugin is built, maintained, and supported by an independent developer. There are no premium upsells, no tracking, and no bloat. If this plugin has saved your website from attacks or saved you hours of debugging, consider buying me a coffee to keep the development going!

Solana

Solana (SOL)

Solana Mainnet

Address copied to clipboard!

Check out the full source code: github.com/JackerArchitect/hide-login-secure

Every contribution, no matter how small, is deeply appreciated and goes directly towards server costs and future development.