Your WordPress login page is at yourdomain.com/wp-admin or yourdomain.com/wp-login.php by default. Both work the same way and always will, since WordPress core doesn't provide a setting to change this. If you want a different login URL, you need a plugin.
Where the login page actually is
Two URLs reach the same login form:
yourdomain.com/wp-admin, which redirects to the login form if you're not authenticatedyourdomain.com/wp-login.php, the direct path
Neither is a secret. Every default WordPress install uses them, and scanners know it. That's the actual reason people want to change this URL: not convenience, but to stop the constant stream of automated login attempts hitting a predictable path. If your real goal is stopping brute-force attempts rather than hiding the URL, there's a fix below that doesn't touch the login path at all.
Changing it with a plugin
WordPress core has no setting for this, so a plugin is the only route. Options like WPS Hide Login are common choices. The general steps:
- Open
wp-admin → Plugins → Add Newand search for a login URL changer. - Install and activate it.
- In its settings page, set your custom login slug, for example
yourdomain.com/secure-login. - Save. Test the new URL in a private browser window before closing your current logged-in session, so you're not locked out if something's misconfigured.
Once it's active, /wp-admin and /wp-login.php stop working entirely for logged-out visitors. Only your custom path reaches the form. Write the new URL down somewhere you'll actually find it.
Do this on staging first
A misconfigured slug can make your site unreachable. Test the change on a staging copy first, confirm the new URL works end to end, then repeat the change on production.
Getting locked out
If you activate a login-URL plugin, save a broken slug, and get locked out with no way to log in, you have two options depending on what you can access:
- File Manager access: connect via the File Manager tile in the portal or FTP, find the plugin's folder under
wp-content/plugins/, and rename it. WordPress deactivates any plugin whose folder it can't find, which reverts you to the default/wp-adminpath immediately. - No access at all: restore from a backup. Check cPanel's Backups tool (JetBackup 5) for the most recent restore point before assuming one is available for today.
A custom URL isn't the whole fix
Hiding the login path cuts down noise from generic scanners, but it isn't security by itself, and it does nothing to speed up a slow admin dashboard or a sluggish site. Login-URL plugins run on every request to check the path, which is negligible on its own, but if your site is already dragging, that's a separate problem worth chasing down. Start with My WordPress site is slow for the usual culprits: heavy plugins, unoptimized images, and theme bloat.
If WordPress's own Site Health tool is flagging login or security-adjacent warnings alongside this, check WordPress Site Health warnings and which ones matter before assuming every warning needs action.
When to contact support
If you're locked out and don't have File Manager or FTP access set up, or a backup restore isn't resolving the issue, open a ticket from Support → New ticket in the portal. It's a real person on the other end, not a bot, and they can walk through file-level access or a restore with you directly.