BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
HTTP Auth icon
Slowing down Tested up to 6.8.10 #1 in brute attack

HTTP Auth

Provides comprehensive security during development by protecting your entire site and your admin pages from brute-force attacks.

Active installs6K+5K+ tier
Downloads · 30d3.3K▲ +9.1% vs prev. 30d
Rating4.2/56 reviews
Health score47/100Fair
All-time downloads78.4KSince Feb 2016
Support resolved—No recent threads
RequiresWP 3.5PHP 5.6+
Downloads · 7d1K• -0.2% week over week
Our verdict

Use with caution

HTTP Auth works, but test it on a staging site before relying on it in 2026. It runs on 6K+ sites, is rated 4.2/5 and was last updated 1 year ago, and scores 47/100 on our health check.

  • No update in over a year
  • Only tested up to WordPress 6.8 (latest is 7.1)

Daily downloads

69138207Jun 28Aug 11Sep 25
Yesterday261
Daily average (1y)52
Peak day450Apr 30, 2026
Last 12 months18.9K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where HTTP Auth stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
brute attack #47 491 Best brute attack plugins →
Brute Force >100 667 Best Brute Force plugins →
http auth #4 1,057 Best http auth plugins →
prevent-crawl #5 231 Best prevent-crawl plugins →
restrict site #71 1,940 Best restrict site plugins →

Version adoption

Share of active sites per release.

  • 1.087.9%
  • 0.312.1%

Rating breakdown

★★★★★★★★★★ 4.2 from 6 reviews

  • 5★66.7%
  • 4★16.7%
  • 3★0.00%
  • 2★0.00%
  • 1★16.7%

About HTTP Auth

From the official readme · v1.0.1

Description

This plugin empowers you to set up HTTP Authentication for your website. This adds an extra layer of security by requiring a username and password to access specific areas.

Here’s how it benefits you:

  • Enhanced Admin Security: Shield your admin pages from brute-force attacks by adding a login barrier.
  • Controlled Crawling: Restrict crawlers from accessing your site during development, preventing unnecessary indexing.
  • Post-Launch Access Control: Maintain control over admin page access even after your website goes live.
  • Easy Activation/Deactivation: Conveniently enable or disable HTTP Auth without deactivating the plugin entirely.

Help Us Improve!

I am constantly working to enhance this plugin and your feedback is valuable. If you are happy with the plugin, consider leaving a review on WordPress.org. Your positive feedback motivates us to keep improving!

Link to Reviews: https://wordpress.org/support/plugin/http-auth/reviews/?rate=5#new-post

Bug Reports

We welcome bug reports for HTTP Auth on GitHub: https://github.com/samiahmedsiddiqui/http-auth. Please remember that GitHub is primarily for bug reporting, and issues not classified as genuine bugs may be closed.

From within WordPress

  1. Visit ‘Plugins > Add New’
  2. Search for HTTP Auth
  3. Activate HTTP Auth from your Plugins page.
  4. Go to “after activation” below.

Manually

  1. Upload the http-auth folder to the /wp-content/plugins/ directory
  2. Activate HTTP Auth through the ‘Plugins’ menu in WordPress
  3. Go to “after activation” below.

After activation

  1. Go to the plugin settings page and set up the plugin for your site.
  2. You’re done!

Installation

This process defines you the steps to follow either you are installing through WordPress or Manually from FTP.

Changelog

1.0.1 – Dec 23, 24

Fix minor WPCS issues and change text for better understanding.

1.0.0 – July 28, 2023

* Fix WPCS issues

Earlier versions

* For the changelog of earlier versions, please refer to the separate changelog.txt file.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

FAQ

HTTP Auth: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 26, 2026

Is HTTP Auth free?

Yes. HTTP Auth is free to download and use from the official WordPress.org plugin directory.

Is HTTP Auth safe to use in 2026?

HTTP Auth works, but test it on a staging site before relying on it in 2026. It runs on 6K+ sites, is rated 4.2/5 and was last updated 1 year ago, and scores 47/100 on our health check.

How many websites use HTTP Auth?

HTTP Auth is active on 6K+ WordPress websites and has been downloaded 78,365 times since it launched in February 2016. It was downloaded 3,324 times in the last 30 days.

Does HTTP Auth work with WordPress 7.1?

HTTP Auth is officially tested up to WordPress 6.8.10, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does HTTP Auth need?

HTTP Auth requires PHP 5.6 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was HTTP Auth last updated?

The latest version, 1.0.1, was released on July 22, 2025 (1 year ago).

Who makes HTTP Auth?

HTTP Auth is developed and maintained by Sami Ahmed Siddiqui.

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.