跳至主要內容
WordPress.org

Hong Kong 香港中文

  • 佈景主題
  • 外掛
  • News
  • Support
  • About
  • 重要通知
  • WordPress 常見問題
  • 團隊
  • 取得 WordPress
取得 WordPress
WordPress.org

Plugin Directory

Treder Secure Login Shield

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Treder Secure Login Shield

由Ben Treder
下載
  • 詳情
  • 評價
  • 安裝
  • 開發
支援

描述

Secure Login Shield helps you lock down your WordPress login page.
By default, WordPress exposes /wp-login.php and /wp-admin/. Bots hammer these URLs every day.

This plugin gives you a private login slug (e.g. /dragon-lair) and hides the default login endpoint:

  • Defaults to /wp-login.php until you change it.
  • Once changed, only your custom slug works.
  • Direct access to /wp-login.php shows a 404 Not Found (stealth mode).
  • Logged-out visitors hitting /wp-admin/ are redirected to the homepage.
  • Deactivate the plugin → everything reverts to normal.

Made with ❤️ by Ben Treder

Features

  • Private login slug (e.g. /dragon-lair, /control-center, /secret-gate)
  • Stealth 404 protection: Bots hitting /wp-login.php see “Not Found”
  • Homepage redirect: /wp-admin/ (logged out) → homepage
  • Easy settings page under Settings → Secure Login Shield
  • Safe activation/deactivation: no core hacks, auto-reverts when disabled

Contribute & Support

  • Website: BenTreder.com
  • Author: Ben Treder
  • Issues & Feature Requests: Please open a ticket on BenTreder.com
  • Like this plugin? ⭐ Leave a review and help spread the word!
  • ☕ Support development: Buy Me a Coffee

螢幕截圖

Settings page showing the default login slug (/wp-login.php)
Settings page showing the default login slug (/wp-login.php)
Settings page with a custom private slug (/dragon-lair)
Settings page with a custom private slug (/dragon-lair)

安裝

  1. Upload the secure-login-shield folder to the /wp-content/plugins/ directory or install via Plugins → Add New → Upload.
  2. Activate the plugin through the “Plugins” menu in WordPress.
  3. Go to Settings → Secure Login Shield.
  4. Set your private slug (example: dragon-lair).
  5. Go to Settings → Permalinks → Save Changes (refresh rewrite rules).
  6. If you use a caching plugin or CDN, clear cache to avoid stale redirects.
  7. Log in using https://yoursite.com/dragon-lair.

Important: Bookmark your new login URL! If you forget it, you’ll need to disable the plugin via FTP or database.

常見問題

Will this break my site?

No. By default it uses /wp-login.php until you change it. Deactivating the plugin instantly reverts WordPress to normal behavior.

Can I completely block /wp-login.php?

Yes. Once you set a slug, /wp-login.php (and actions) return a 404 Not Found.

What if I forget my private slug?

Deactivate the plugin via FTP (delete or rename secure-login-shield). WordPress will go back to /wp-login.php.

Does this work with caching plugins or CDNs?

Yes, but after changing your slug, you should clear cache/CDN to avoid serving stale redirects.

評價

Great plugin

urosjovanovic 2025年9月22日
Secure Login Shield is a great plugin! Easy to use and very effective at protecting your site.
閱讀全部1個評價

貢獻者及開發者

“Treder Secure Login Shield” 是一個開源的軟體。以下的人對這個外掛作出了貢獻。

貢獻者
  • Ben Treder

將 Treder Secure Login Shield 外掛本地化為台灣繁體中文版。

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄。

修改日誌

2.0.6

  • Rebranded the visible plugin name to Treder Secure Login Shield.
  • Fixed the WordPress.org contributor username to bdtreder.
  • No slug, ZIP base name, folder name, text domain, settings, or login behavior changes.

2.0.5

  • Corrected WordPress.org release versioning after the Secure Login Shield audit.
  • Confirmed WordPress 7.0 compatibility metadata.
  • Kept the free plugin focused on private login URL protection, stealth 404 behavior, and logged-out wp-admin redirect protection.

1.3.0

  • Rebrand to Secure Login Shield by Ben Treder
  • Default slug remains /wp-login.php (safe on first install)
  • Added activation notice: Save permalinks + clear cache after activation
  • Stealth 404 mode enforced when custom slug is chosen
  • Homepage redirect for logged-out visits to /wp-admin/

1.2.0

  • Added stealth 404 mode
  • Improved security enforcement

1.1.0

  • Redirected /wp-admin/ → homepage for logged-out users

1.0.0

  • Initial release with custom login slug + wp-login.php block

其它

  • Version 2.0.6
  • Last updated 2 個月之前
  • Active installations 少於10
  • WordPress version 6.0 or higher
  • Tested up to 7.0.3
  • PHP version 7.4 or higher
  • Language
    English (US)
  • Tags
    custom loginhardeningloginsecuritywp login
  • 進階顯示

評分

5 out of 5 stars.
  • 1 5-star review 5 stars 1
  • 0 4-star reviews 4 stars 0
  • 0 3-star reviews 3 stars 0
  • 0 2-star reviews 2 stars 0
  • 0 1-star reviews 1 star 0

Your review

See all reviews

貢獻者

  • Ben Treder

支援

有話想說?需要協助?

檢視支援論壇

捐贈

想要支援這個外掛的發展嗎?

贊助這個外掛

  • 關於我們
  • 最新消息
  • 寄存
  • 隱私權
  • 展示網站
  • 佈景主題
  • 外掛
  • 區塊版面配置
  • Learn
  • 技術支援
  • 開發者資源
  • WordPress.tv ↗
  • 共同參與
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Hong Kong 香港中文

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • 訪問我們的 Facebook 專頁
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
代碼就是詩歌。
The WordPress® trademark is the intellectual property of the WordPress Foundation.