WordPress security

Why hiding wp-login.php does not secure WordPress

Watch on YouTube ↗

About this video

See why hiding the WordPress login page cannot stop automated attacks through XML-RPC, and learn where stronger authentication controls help.

Changing the login page URL can reduce casual visits, but it does not close other authentication paths. This video demonstrates an XML-RPC multicall attack and shows why an obscured wp-login.php address does not address that exposure.

What you’ll see

  • How automated requests can target WordPress authentication through XML-RPC.
  • Why hiding the login URL leaves that path available.
  • Ways to reduce the exposed attack surface and apply stronger authentication controls.

For more background, read Strengthening WordPress login security with AAM.