콘텐츠로 바로가기
WordPress.org

한국어

  • 테마
  • 플러그인
  • 소식
    • 문서
    • 포럼
  • About
    • WordPress 6.9
    • 워드프레스 6.8
    • 워드프레스와 40% 웹을 위한 여정
    • 워드프레스 번역 핸드북
  • 워드프레스 한국팀
  • 워드프레스 받기
워드프레스 받기
WordPress.org

Plugin Directory

Khushal Login Path Guard

  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인
  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인

Khushal Login Path Guard

작성자: Khushal Tank
다운로드
  • 세부사항
  • 평가
  • 설치
  • 개발
지원

설명

Khushal Login Path Guard is a WordPress security plugin that allows you to change your default login URL and protect your site from common attack vectors. The plugin blocks brute-force attempts, prevents user enumeration, secures sensitive files, and hides WordPress information from potential attackers. All blocked paths display 404 errors (Stealth Mode) instead of redirects, making your site invisible to attackers.

Features

Login Protection:
* Blocks 17+ common brute-force login paths
* Custom login URL (only you know the path)
* Shows 404 error instead of redirect (no hints to attackers)
* Protects /wp-admin, /login, /wp-login.php and more

Advanced Security:
* Blocks XML-RPC (prevents brute-force via API)
* Prevents user enumeration via REST API
* Blocks author page enumeration (?author=1)
* Protects wp-config.php and sensitive files
* Blocks direct access to wp-includes PHP files
* Removes WordPress version information

Security Headers:
* X-Frame-Options (prevents clickjacking)
* X-Content-Type-Options (prevents MIME sniffing)
* X-XSS-Protection (XSS attack protection)
* Referrer-Policy (privacy protection)
* Permissions-Policy (feature restriction)

User-Friendly:
* Easy settings interface
* One-click URL copy
* Normal functionality for logged-in users
* Does not block AJAX requests
* Clean admin interface

Security Benefits

  1. Brute Force Protection – 15+ login paths blocked
  2. XML-RPC Disabled – Prevents API-based attacks
  3. User Enumeration Blocked – Hides usernames from attackers
  4. Sensitive Files Protected – wp-config.php, .htaccess secured
  5. Security Headers – Industry-standard HTTP headers
  6. WordPress Hidden – Removes version and generator tags

इस्तेमाल करना बेहद आसान है

  1. Plugin activate करें
  2. Settings > Login Path Security में जाएं
  3. अपना custom login path enter करें
  4. Settings save करें
  5. नया login URL use करें

스크린샷

Settings page - Configure custom login path
Settings page – Configure custom login path
New login URL display - Your secure login URL
New login URL display – Your secure login URL
Security features overview
Security features overview

설치

  1. Upload the plugin folder to /wp-content/plugins/ directory
  2. Activate the plugin through the ‘Plugins’ menu in WordPress admin
  3. Go to Settings > Login Path Security to configure

OR

  1. Go to Plugins > Add New in WordPress admin
  2. Search for “Khushal Login Path Guard”
  3. Install and Activate

FAQ

What if I forget my login URL?

You can rename or delete the /wp-content/plugins/khushal-login-path-guard/ folder via FTP or cPanel. This will deactivate the plugin and you can login using the normal wp-login.php.

Will this plugin slow down my site?

No, this plugin is very lightweight and will not affect your site’s performance.

Will wp-admin work for logged-in users?

Yes, everything will work normally for users who are already logged in.

Does this work with multisite?

Yes, this plugin is multisite compatible.

Will AJAX requests be blocked?

No, WordPress AJAX requests will work normally.

후기

Best wp login security plugin

umang3640 2025년 12월 24일
one of the best security plugin in wp also free plugin so this is very helpful me this plugin.
모든 1 평가 읽기

기여자 & 개발자

“Khushal Login Path Guard”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자
  • Khushal Tank

자국어로 “Khushal Login Path Guard”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록을 RSS로 구독하세요.

변경이력

2.4.1

  • Fixed wp-admin redirect issue – now shows 404 when logged out
  • Added multiple layers of protection for wp-admin access
  • Improved logout functionality
  • Enhanced user experience

2.4.0

  • Changed wp-admin behavior – shows 404 instead of redirect when logged out
  • Improved security by preventing information leakage
  • Better stealth mode implementation

2.3.3

  • Fixed dashboard access after login
  • Removed wp-admin from directory blocking
  • Improved logged-in user detection

2.3.2

  • Fixed wp-admin access timing issue
  • Changed hook from ‘init’ to ‘wp’ for better authentication detection
  • Improved compatibility

2.3.1

  • Fixed logout functionality
  • Added proper logout URL filtering
  • Improved redirect handling

2.3.0

  • Added logout redirect to custom login page
  • Enhanced logout URL handling
  • Improved user experience

2.2.5

  • Fixed wp-admin directory access
  • Removed wp-admin from blocked directories list
  • Improved functionality for logged-in users

2.2.4

  • Fixed login.php blocking
  • Added admin-login.php and adminlogin.php to blocklist
  • Updated blocked paths count

2.2.3

  • Fixed undefined variable warnings
  • Initialized all required wp-login.php variables
  • Improved login page compatibility

2.2.2

  • Added comprehensive login path blocking
  • Added /login, /signin, /administrator paths to blocklist
  • Updated admin interface

2.2.1

  • Changed redirect behavior to show 404 error
  • Removed redirect URL setting
  • Enhanced security by hiding WordPress

2.2.0

  • Added XML-RPC blocking
  • Added REST API user enumeration protection
  • Added author page enumeration blocking
  • Added sensitive file protection
  • Added wp-includes PHP file protection
  • Added comprehensive security headers
  • Expanded blocked login paths

2.0.0

  • Major security update
  • Added multiple security features
  • Enhanced protection mechanisms

1.0.0

  • Initial release
  • Custom login path functionality
  • wp-login.php and wp-admin protection
  • Admin settings interface
  • Basic security features

기초

  • 버전 2.4.1
  • 최근 업데이트: 3개월 전
  • 활성화된 설치 10보다 적음
  • 워드프레스 버전 5.0 또는 그 이상
  • 다음까지 시험됨: 7.0.4
  • PHP 버전 7.0 또는 그 이상
  • 언어
    English (US)
  • 태그:
    Brute Forceloginsecurityuser enumerationxmlrpc
  • 고급 보기

평점

별 5점 만점에 5점.
  • 1/5-별점 후기 별 5개 1
  • 0/4-별점 후기 별 4개 0
  • 0/3-별점 후기 별 3개 0
  • 0/2-별점 후기 별 2개 0
  • 0/1-별점 후기 별 1개 0

Your review

모든 리뷰 보기

기여자

  • Khushal Tank

지원

할 말 있으신가요? 도움이 필요하신가요?

지원 포럼 보기

  • 소개
  • 뉴스
  • 호스팅
  • 개인정보
  • 쇼케이스
  • 테마
  • 플러그인
  • 패턴
  • 배우기
  • 지원
  • 개발자 도구
  • WordPress.tv ↗
  • 참여하기
  • 이벤트
  • 기부하기 ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

한국어

  • X(이전 트위터) 계정 방문하기
  • 블루스카이 계정 방문하기
  • 마스토돈 계정 방문하기
  • 스레드 계정 방문하기
  • 페이스북 페이지 방문하기
  • 인스타그램 계정 방문하기
  • LinkedIn 계정 방문하기
  • 틱톡 계정 방문하기
  • 유튜브 채널 방문하기
  • 텀블러 계정 방문하기
코드는 詩다
The WordPress® trademark is the intellectual property of the WordPress Foundation.