Results 1 to 14 of 14
  1. #1
    edgarf76's Avatar
    edgarf76 is offline Private Member
    Join Date
    March 2013
    Location
    Montreal
    Posts
    2,196
    Thanks
    804
    Thanked 582 Times in 429 Posts

    Default Question About Wordpress Plugin

    hHope all is well and you are having a great weekend. I am trying to find a reputable wordpress plugin that re-names the wp-admin login. Any help would be great. Thank you.

  2. The Following 2 Users Say Thank You to edgarf76 For This Useful Post:

    ARZ (3 November 2015), BestBonusBets (18 April 2018)

  3. #2
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,988
    Thanks
    4,540
    Thanked 9,297 Times in 5,981 Posts

    Default

    AllInOne WP Security does a GREAT job of renaming the admin login.

    There are additional features as well, but that one I feel is the most important.

    Just install it, and look in the left navigation, it is located in the BruteForce section.

    Have a word picked out you want to use and it will move the login to domain.com/?wordchosen

    Rick
    Universal4

  4. The Following 4 Users Say Thank You to universal4 For This Useful Post:

    ARZ (3 November 2015), BestBonusBets (18 April 2018), edgarf76 (1 November 2015), Moonlight Cat (2 November 2015)

  5. #3
    MrBinaryAff's Avatar
    MrBinaryAff is offline Public Member
    Join Date
    August 2014
    Location
    Leeds, UK
    Posts
    743
    Thanks
    200
    Thanked 231 Times in 188 Posts

    Default

    We use Better WP Security, it has this option of changing wp-admin login as well.
    My website: http://mrbinary.co.uk/

    Follow me on Twitter: https://twitter.com/MrBinaryAff
    Like my pictures on Instagram: https://instagram.com/mrbinary

  6. The Following 2 Users Say Thank You to MrBinaryAff For This Useful Post:

    BestBonusBets (18 April 2018), edgarf76 (1 November 2015)

  7. #4
    FruityJelena's Avatar
    FruityJelena is offline Former AM
    Join Date
    September 2015
    Location
    Belgrade, Serbia
    Posts
    563
    Blog Entries
    1
    Thanks
    590
    Thanked 339 Times in 230 Posts

    Default

    Hi there

    Maybe this link could be useful to you
    http://vc.wpbakery.com/

  8. #5
    ARZ's Avatar
    ARZ
    ARZ is offline Private Member
    Join Date
    April 2015
    Posts
    256
    Thanks
    66
    Thanked 74 Times in 62 Posts

    Default

    Thanks Edgar for starting this thread

    I am just taking a multiple brute force attacks on my website, renaming thi wp-admin seems like a great option!

    Thanks once more
    Nejlepší Výherní hrací automaty online zdarma! - zahrajte si z pohodlí domova
    Vyhraj.cz - nejlepší portál o casino bonusech v ČR
    Vyhraj.sk - nejlepší portál o casino bonusech na Slovensku
    Check the best casino bonuses and free spins every day!
    Confira as melhores ofertas de bônus de rodadas grátis no Brasil.

  9. The Following 3 Users Say Thank You to ARZ For This Useful Post:

    -Shay- (3 November 2015), BestBonusBets (18 April 2018), edgarf76 (23 November 2015)

  10. #6
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,988
    Thanks
    4,540
    Thanked 9,297 Times in 5,981 Posts

    Default

    Brute Force attacks on wordpress logins start almost immediately after wp is installed.

    When I set up new wordpress installs I often do so on an ip address first if there is a live html site, and then change it when its ready. I have to even be careful to remember to move the login because if I don't within days, sometimes even the next day, the attacks start.

    As a normal course of the day for scammers, they scan the net looking for wp-login as well as a few other named login pages.

    Rick
    Universal4

  11. The Following 2 Users Say Thank You to universal4 For This Useful Post:

    BestBonusBets (18 April 2018), Cash Bonus (17 April 2018)

  12. #7
    vmguide is offline Private Member
    Join Date
    April 2018
    Posts
    5
    Thanks
    0
    Thanked 1 Time in 1 Post

    Default

    It is, what I would consider a myth, that changing the wp-admin would protect your site from brute force attacks. Here are two reasons why:
    1. Any hacker or bot that have the tools to actually hack your site will also be able to find your login-page no matter what name it is given.
    2. A lot of plugins and theme functions depend on the wp-admin location on the server. Moving or renaming it may cause crashes.

    My advice:
    1. Make sure you don't have any users with the default username "admin". If so delete it.
    2. Set strong passwords that are canged on a regular basis.
    3. Get a good security plugin that blocks brute force attacks, and maybe even use a firewall. Here are some examples:

    https://ithemes.com/security/
    https://sucuri.net/
    https://www.wordfence.com/

  13. The Following User Says Thank You to vmguide For This Useful Post:

    BestBonusBets (18 April 2018)

  14. #8
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,988
    Thanks
    4,540
    Thanked 9,297 Times in 5,981 Posts

    Default

    I use to recommend All In One security, but now I use WP Cerber for securing fresh installs of Word Press.

    It allows for easy use of moving the admin login.
    If something goes wrong with the login move, you can ftp a file up and run it, and it will move the login back to the default location. (nice feature for emergencies, and those who might be less comfortable with word press)
    It has a lot of other features you may or may not want to enable, such as turning off rpc stuff, auto blocking of failed logins, logging all logins and their IP, ip blocking and many more things.

    The important thing is to use SOMETHING for extra security, and to do so right away.

    Rick
    Universal4

  15. The Following 2 Users Say Thank You to universal4 For This Useful Post:

    BestBonusBets (18 April 2018), Cash Bonus (17 April 2018)

  16. #9
    wonderpunter's Avatar
    wonderpunter is offline Private Member
    Join Date
    August 2013
    Posts
    3,411
    Blog Entries
    5
    Thanks
    427
    Thanked 2,003 Times in 1,255 Posts

    Default

    I used wordfence but have found cerber much less resource hungry, I actually mad e the switch when i came into php problems with WF, since then not looked back


  17. #10
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,988
    Thanks
    4,540
    Thanked 9,297 Times in 5,981 Posts

    Default

    Thanks for confirming that wonderpunter, I actually never tried wordfence on my own sites, but have had a few clients over the years who had it on sites.

    I also found wpcerber to be very smooth and less resource hungry...

    Rick
    Universal4

  18. #11
    schegolev100's Avatar
    schegolev100 is offline Private Member
    Join Date
    April 2018
    Location
    Vietnam
    Posts
    33
    Thanks
    5
    Thanked 4 Times in 4 Posts

    Default

    I don't use a plugin for this. You can rename the file yourself.

    Use instruction:

    1. Find the file " wp-login.php " in the root directory of the site, rename the file, for example in new.php.
    2. Open the file in a text editor and replace all references to "wp-login.php " to " new.php", save the file.

    Now WP will give 404 error to /wp-admin/ and wp-login.php.

    P.S. instead of new.php use your random name.

  19. #12
    citizen42's Avatar
    citizen42 is offline Public Member
    Join Date
    September 2017
    Posts
    116
    Thanks
    21
    Thanked 72 Times in 43 Posts

    Default

    if you use a security plugin and you're happy with that and only need a plugin for wp-login.php, you can use "WPS Hide Login"- it does just that.

  20. #13
    Online Poker America is offline Private Member
    Join Date
    June 2018
    Posts
    18
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    Hey!

    Definitely try using an all in one wp security, can't go wrong with that.

    Good luck

  21. #14
    Join Date
    November 2005
    Posts
    4,507
    Blog Entries
    1
    Thanks
    1,920
    Thanked 2,216 Times in 1,278 Posts

    Default

    Simple solution...

    If you have a static IP for your internet (aka your ISP), all you need to do is add a attaccess to your wp-admin folder, and ONLY allow access to that area, with your static IP.

    Doesn't matter how many times a script kiddy or hacker attempts a brute force or any other action, if they are not using your ALLOWED IP, they wont get in. Of course, you also need to harden your WP install in other areas, all can be done without using plugins. Hence, site speed is maintained.

    NB - If it's on the net, then no matter what you do it's not 100% safe.

    However the object here, is to make it a PITA to hack. In which case, the abuser's will move to a softer target

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •