MSC Stealth Login
by djm56 0 (0 reviews)

MSC Stealth Login

Hide wp-login.php behind a custom login URL and stop brute-force attacks — lockouts, IP allowlist, login history, email alerts. No tracking.

MSC Stealth Login ranks #64,248 among WordPress.org plugins with 0+ active installations, is #1,333 of 1,595 in the Authentication category, and was last updated Aug 28, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1.2
v1.3.2 Current Version v1.3.2
Updated 3 weeks ago Last Update on 28 Aug, 2026
Refreshed 10 hours ago Last Refreshed on
#1,333 of 1,595 in Authentication Actively maintained
View on WordPress.org
Rank
#64,248
No change
Active Installs
0+
-100%
KW Avg Position
N/A
No change
Downloads
379
+4 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 10

Total Progress 0%
0+ 10+
44,508
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 10 more installs to reach 10+

Rank Changes

48,233 52,875 57,517 62,158 66,800 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
45,820 51,161 56,503 61,845 67,186 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #64,248
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about MSC Stealth Login

Install and activate the plugin, go to Settings → MSC Stealth Login, and set a custom login slug (e.g. my-secret-door). Save — your login page now lives at yoursite.com/my-secret-door and wp-login.php no longer works for visitors. Bookmark the new URL and the Emergency Recovery URL immediately.
They are silently redirected (HTTP 302) to a URL you choose — the homepage by default. There's no error page revealing that a protection plugin is running. Logged-in users, logout/password-reset flows, and AJAX requests keep working normally.
Enable "Hide wp-admin" on the Settings tab. Logged-out visitors who try to open any /wp-admin URL are silently redirected to a URL you choose (your homepage by default), while logged-in users and AJAX requests are unaffected. Combined with the custom login URL, this hides both your login page and your admin area from bots and vulnerability scanners.
Use the Emergency Recovery URL shown on the Settings tab — copy or bookmark it when you set up the plugin (you can also email yourself the login URL from the Support tab). The recovery URL always reaches wp-login.php. If you lose both, rename the plugin folder via FTP/SFTP or run wp plugin deactivate msc-stealth-login — deactivating instantly restores the standard login page.
Wait for the lockout period to expire, or use the Emergency Recovery URL. For immediate access, disable the plugin via FTP by renaming the plugin folder. Your IP can also be added to the allowlist if you have database access.
Enable Advanced Security Features on the Advanced tab (it ships disabled so nothing surprises you). Then, after the configured number of failed attempts (default 3) from one IP, that IP is locked out for the configured duration (default 15 minutes). Optional progressive lockouts double the wait after each repeat offence, capped at your configured maximum. Successful logins reset the counter.
Yes. Add exact IPs or CIDR ranges (IPv4 and IPv6) to the whitelist on the Advanced tab. Behind Cloudflare or a reverse proxy? Enable "Trust Proxy Headers" so the plugin sees real visitor IPs instead of the proxy's.
Yes. Activate it network-wide or per site — either way every site gets its own custom login URL, settings, login history and emergency recovery URL, and sites created later are set up automatically. Each site's administrator configures it under Settings → MSC Stealth Login on their own site. By default failed-login counters are per site; enable "Share Lockouts Across Network" on the Advanced tab if you want a lockout earned on one site to apply across the whole network. Uninstalling removes the plugin's data from every site on the network.
Yes, both are on by default once Advanced Security is enabled. XML-RPC pingback and user-listing methods are disabled, and the REST API user endpoints plus ?author=N queries are blocked. Note: disabling XML-RPC affects the WordPress mobile app and some Jetpack features — leave it off if you use those.
Yes, but ensure your login pages aren't cached — exclude your custom login URL from caching. The plugin detects six major cache/security plugins (W3 Total Cache, WP Super Cache, WP Rocket, Wordfence, iThemes Security, Sucuri) and shows a heads-up notice when one is active.

Sign In / Register

You need to sign in or register to use this feature.