Accurate guidance for Steel Security Free and Steel Security Pro

Hide the Default Login URL

Steel can move public login traffic away from `wp-login.php` to a custom path while preserving normal WordPress internals.

Hardening Free Updated August 9, 2026

What this means

This is the safer version of “renaming wp-admin.” WordPress core files stay where they belong, but the public login entry point moves to a private slug you choose.

What Steel Security checks

Steel validates the custom slug and rejects reserved routes, public content collisions, and important internal path conflicts.

Recommended action

Choose a unique slug that is not already used by pages, posts, or public routing structures.

Do not rely on a shared or predictable default. Steel does not suggest one for you.

What Steel Security can do

Rewrite generated login, logout, lost-password, and registration helper URLs to the configured custom path.

Return `404` for direct unauthenticated requests to `wp-login.php` and protected `wp-admin` entry points while the feature is enabled.

Rollback / Recovery

Use the hardening page to disable the custom login URL if you need to restore the default login endpoint.

If you lose track of the custom path, recovery is a troubleshooting scenario, not a reason to force a weak default.

Server or hosting considerations

This feature works at the WordPress request layer. It does not rename WordPress core directories.

Continue reading