What this means
This is the safer version of “renaming wp-admin.” WordPress core files stay where they belong, but the public login entry point moves to a private slug you choose.
What Steel Security checks
Steel validates the custom slug and rejects reserved routes, public content collisions, and important internal path conflicts.
Recommended action
Choose a unique slug that is not already used by pages, posts, or public routing structures.
Do not rely on a shared or predictable default. Steel does not suggest one for you.
What Steel Security can do
Rewrite generated login, logout, lost-password, and registration helper URLs to the configured custom path.
Return `404` for direct unauthenticated requests to `wp-login.php` and protected `wp-admin` entry points while the feature is enabled.
Rollback / Recovery
Use the hardening page to disable the custom login URL if you need to restore the default login endpoint.
If you lose track of the custom path, recovery is a troubleshooting scenario, not a reason to force a weak default.
Server or hosting considerations
This feature works at the WordPress request layer. It does not rename WordPress core directories.