Get a free website with any plan

See how
WORDPRESS

Finding and changing the login URL

Last updated

IN SHORT

Default WordPress sites use /wp-admin or /wp-login.php for their login forms. WordPress core has no native setting to change these paths, so modifying your login URL on Flashcloud requires a plugin like WPS Hide Login. Once configured, standard login URLs stop working for logged-out visitors, sending authentication traffic exclusively through your custom slug.

Your WordPress login page is at yourdomain.com/wp-admin or yourdomain.com/wp-login.php by default. Both work the same way and always will, since WordPress core doesn't provide a setting to change this. If you want a different login URL, you need a plugin.

Where the login page actually is

Two URLs reach the same login form:

  • yourdomain.com/wp-admin, which redirects to the login form if you're not authenticated
  • yourdomain.com/wp-login.php, the direct path

Neither is a secret. Every default WordPress install uses them, and scanners know it. That's the actual reason people want to change this URL: not convenience, but to stop the constant stream of automated login attempts hitting a predictable path. If your real goal is stopping brute-force attempts rather than hiding the URL, there's a fix below that doesn't touch the login path at all.

Changing it with a plugin

WordPress core has no setting for this, so a plugin is the only route. Options like WPS Hide Login are common choices. The general steps:

  1. Open wp-admin → Plugins → Add New and search for a login URL changer.
  2. Install and activate it.
  3. In its settings page, set your custom login slug, for example yourdomain.com/secure-login.
  4. Save. Test the new URL in a private browser window before closing your current logged-in session, so you're not locked out if something's misconfigured.

Once it's active, /wp-admin and /wp-login.php stop working entirely for logged-out visitors. Only your custom path reaches the form. Write the new URL down somewhere you'll actually find it.

Do this on staging first

A misconfigured slug can make your site unreachable. Test the change on a staging copy first, confirm the new URL works end to end, then repeat the change on production.

Getting locked out

If you activate a login-URL plugin, save a broken slug, and get locked out with no way to log in, you have two options depending on what you can access:

  • File Manager access: connect via the File Manager tile in the portal or FTP, find the plugin's folder under wp-content/plugins/, and rename it. WordPress deactivates any plugin whose folder it can't find, which reverts you to the default /wp-admin path immediately.
  • No access at all: restore from a backup. Check cPanel's Backups tool (JetBackup 5) for the most recent restore point before assuming one is available for today.

A custom URL isn't the whole fix

Hiding the login path cuts down noise from generic scanners, but it isn't security by itself, and it does nothing to speed up a slow admin dashboard or a sluggish site. Login-URL plugins run on every request to check the path, which is negligible on its own, but if your site is already dragging, that's a separate problem worth chasing down. Start with My WordPress site is slow for the usual culprits: heavy plugins, unoptimized images, and theme bloat.

If WordPress's own Site Health tool is flagging login or security-adjacent warnings alongside this, check WordPress Site Health warnings and which ones matter before assuming every warning needs action.

When to contact support

If you're locked out and don't have File Manager or FTP access set up, or a backup restore isn't resolving the issue, open a ticket from Support → New ticket in the portal. It's a real person on the other end, not a bot, and they can walk through file-level access or a restore with you directly.

Common questions

Can I change my login URL without a plugin?

No. WordPress core does not provide a native setting to change the login path. You must install a plugin to set a custom URL.

What should I do if I get locked out?

Rename the plugin folder to restore access immediately. Connect using File Manager or FTP, locate the plugin under wp-content/plugins/, and change its name to deactivate it and return to /wp-admin. If you do not have file access, restore from a backup using JetBackup 5 in cPanel.

Why do bots target my login URL?

Scanners target the default /wp-admin and /wp-login.php paths because every standard WordPress installation uses them. Changing your URL stops generic automated login attempts from reaching that predictable location.

Will changing my login URL make my site faster?

No. A custom login URL only cuts down automated scanner traffic on that path. Site slowness is a separate issue usually caused by heavy plugins, unoptimized images, or theme bloat.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.