WPS Protect: Login URL & Security Headers
by Muhammad Junaid Tariq 1 (0 reviews)

WPS Protect: Login URL & Security Headers

Move your login URL, stop brute-force attacks, and send HTTP security headers on every response. Lightweight, cache-friendly, no bloat.

WPS Protect ranks #60,614 among WordPress.org plugins with 1+ active installations, is #1,030 of 1,590 in the Authentication category, a 1/5 rating from 0 reviews, and was last updated Aug 15, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v2.0.0 Current Version v2.0.0
Updated 1 month ago Last Update on 15 Aug, 2026
Refreshed 18 hours ago Last Refreshed on
#1,030 of 1,590 in Authentication
View on WordPress.org
Rank
#60,614
-1321 this week
Active Installs
1+
-83.3%
KW Avg Position
N/A
No change
Downloads
323
+2 today
Support Resolved
0%
No change
Rating
20%
Review 1 out of 5
1 (0 reviews)

Next Milestone 10

Total Progress 20%
0+ 10+
47,677
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 8 more installs to reach 10+

Rank Changes

50,167 55,111 60,055 64,999 69,943 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
50,167 55,111 60,055 64,999 69,943 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #60,614
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

1.0
0 reviews
Overall 20%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about WPS Protect: Login URL & Security Headers

Use the rescue URL shown when you saved the slug. If you no longer have it, add define( 'WPSP_DISABLE_LOGIN_GATE', true ); to wp-config.php, or run wp wpsp login-url over WP-CLI. Deactivating the plugin also restores wp-login.php, and your settings survive deactivation.
Login and REST requests are never cached, so brute-force protection and the login gate are unaffected. Security headers are sent by PHP, so on a page served from a full-page cache they may be served by your cache layer instead. If your host serves cached pages without invoking PHP, set the headers at the server level too.
Yes, but configure your proxy ranges under the brute-force settings first. Until you do, the plugin deliberately declines to block by IP address rather than risk locking out every visitor sharing a proxy address.
Enable "do not overwrite headers already set" if something else is already sending headers. Running two plugins that both hide the login URL is not supported — pick one.
Your settings are migrated automatically, including your login slug, HTTPS setting and any header values you saved. One thing intentionally does not carry over: 1.x applied a hard-coded Content-Security-Policy: default-src 'self' whenever you had not set one, which blocked inline scripts and styles on most sites. That fallback is gone. If you want a CSP, set one explicitly on the Security Headers tab.

Sign In / Register

You need to sign in or register to use this feature.