90 Quality Score
Active Installs
28/30

With over 2,000,000 active installs, this is one of the most widely deployed login utilities in the WordPress ecosystem, indicating strong real-world trust.

Update Freshness
25/25

Last updated in January 2026 against WordPress 6.9.4 with a low minimum requirement of WordPress 4.1 and PHP 7.0, signalling consistent, careful upkeep.

User Rating
14/15

A 96 out of 100 rating from 2,110 reviewers is exceptional and reflects near-universal user satisfaction.

Support Health
8/15

Only 15 support threads exist with a 46.7% resolution rate, which is modest given the install base, though the low volume also suggests few issues arise.

WP Compatibility
15/15

Scoring full marks for compatibility, tested against the current WordPress release and requiring nothing more than PHP 7.0, which keeps it accessible on older hosting.

Scores higher than 99% of indexed plugins

About

Change wp-login.php to anything you want.

Active Installs 2M+
Rating ★★★★½ 4.8/5
Last Updated 2026-08-13 8:32am GMT
Requires WordPress 4.1+
Tested Up To 7.1
Requires PHP 7.0+

Security History

10 known vulnerabilities, all patched
1 High 8 Medium 1 Low

Most recent: June 24, 2024

View details ▸

Powered by Wordfence Intelligence

What It Does

WPS Hide Login lets you rename your default WordPress login URL (wp-login.php) to a custom slug of your choice, while also blocking access to wp-admin and wp-login.php for unauthorised users. It works without modifying core files, so it survives WordPress core updates. It is a single-purpose plugin focused entirely on login URL obfuscation, not broader security hardening.

Who It's For

This plugin is ideal for site owners who want a quick, low-overhead way to reduce automated brute force attacks by moving the login page off the well-known wp-login.php path. It fits well in agency client work where standardised, easy-to-roll-back login changes are needed across many sites. It also suits branding-conscious businesses that want a tidy custom login URL on smaller installations.

Who Should Skip It

If you already run a full security suite that includes login URL renaming, firewall rules, and brute-force protection, this plugin is redundant. Sites with complex multisite setups, custom authentication flows, or front-end-only login forms may find the redirect behaviour conflicts with their workflow.

The Bottom Line

WPS Hide Login is a focused, well-maintained utility that does one job very well, and its 2M+ installs plus 96/100 rating make it a safe, low-risk choice for most WordPress sites. It is not a complete security solution on its own, so pair it with a broader hardening strategy if threat protection is your goal. Overall Quality Score of 89.45/100 reflects a dependable plugin with a minor weakness only in public support metrics.

Tags

custom login url login rename wp login wp-login.php