HTTP Auth
View on WordPress.orgScores higher than 11% of indexed plugins
About
Provides comprehensive security during development by protecting your entire site and your admin pages from brute-force attacks.
Security History
What It Does
HTTP Auth puts your entire WordPress site behind a web server-level username and password prompt, which means visitors must authenticate before any WordPress code runs. It works at the HTTP layer (Basic Auth or similar), not through WordPress's own login system, so it is particularly useful for blocking crawlers and brute-force bots from reaching the login page at all. An exemption or cookie-based bypass can be configured so you do not lock yourself out.
Who It's For
This plugin is built for developers and agencies who need to lock down staging sites, work-in-progress builds, or pre-launch client work where the public should not see anything until launch day. It is also a good fit for a small team that wants a no-friction way to password-protect the entire site during development without configuring server-level .htpasswd rules manually. Non-technical users running production sites should look elsewhere, as this is squarely a development-stage tool.
Who Should Skip It
If you run a live production site that the public needs to access, this plugin offers no value and will lock out every visitor. Anyone wanting login-specific brute-force protection on a public site should pick a dedicated login firewall such as Limit Login Attempts Reloaded instead.
The Bottom Line
HTTP Auth does one focused job, putting the whole site behind an HTTP password, and it does that job at a quality score of 65.2/100 with minimal features and no track record of community support. It is a reasonable, simple choice for staging and pre-launch protection but is the wrong tool the moment you go live or want real brute-force analytics. For most production WordPress sites one of the alternatives above will serve you better.
Related Plugins
Pick this instead when you need to protect a public-facing production site from brute-force attacks without restricting access for legitimate visitors.
Choose this when you want a more active firewall that scans for malware signatures in addition to blocking login attacks.
Pick this when you want to hide WordPress fingerprints from attackers in addition to firewalling your login and admin pages.
Choose this if you want a broader security hardening toolkit that goes beyond brute-force protection without going as heavy as a full firewall plugin.
Pick this as a complementary tool when you need visibility into who is logging in and from where, which HTTP Auth alone does not provide.