MSC Stealth Login
Hide wp-login.php behind a custom login URL and stop brute-force attacks — lockouts, IP allowlist, login history, email alerts. No tracking.
Use with caution
MSC Stealth Login works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
Daily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where MSC Stealth Login stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| block wp-admin | >100 |
| Brute Force | >100 |
| custom login url | >100 |
| disable xml-rpc | >100 |
| hide login | >100 |
About MSC Stealth Login
From the official readme · v1.3.2Description
Move your WordPress login page to a secret URL of your choosing and make wp-login.php disappear.
Bots hammering wp-login.php and wp-admin are silently redirected away, while you log in at your own custom address. Enable Advanced Security and you also get brute-force lockouts with progressive delays, an IP allowlist with CIDR support, XML-RPC hardening, user-enumeration blocking, a full login history with CSV export, and email alerts — all free, with zero external services.
Stealth Login URL
Change your login page from /wp-login.php to a custom URL like /secure-login/. Attackers scanning for standard WordPress login pages are redirected away before they can even attempt a brute force attack.
wp-admin Protection
Block direct access to /wp-admin/ for users who aren’t logged in — they’re silently redirected to a URL you choose. Logged-in users and AJAX requests are unaffected.
Brute Force Protection (enable Advanced Security to arm)
After a configurable number of failed login attempts (default 3), the IP is locked out for a configurable duration (default 15 minutes). With progressive lockouts enabled, each successive lockout doubles the wait time, up to your configured maximum. This stops automated attacks while minimizing disruption to real users who mistype their password.
Email Notifications
Stay informed about security events with configurable email alerts:
- Lockout notifications when IPs are blocked
- Admin login alerts for every administrator sign-in
- New IP alerts when users log in from previously unseen locations
Login History & Export
Track login attempts with detailed logging: IP, username, result and user agent. Filter by IP address, username, result type, or date range. Export reports to CSV for security audits. Entries older than 30 days are pruned automatically.
XML-RPC & REST API Protection
Disable vulnerable XML-RPC endpoints commonly exploited for brute force attacks. Block REST API user enumeration that lets attackers harvest usernames.
IP Allowlist
Bypass protection for trusted IP addresses — exact IPv4/IPv6 or CIDR ranges (e.g. 10.0.0.0/8). Add your office, home, or server IPs to ensure uninterrupted access while maintaining maximum security for everyone else. A proxy-header trust toggle supports Cloudflare and reverse-proxy setups.
Emergency Recovery URL
Forgot your custom login URL? The Settings tab shows a secure recovery URL that always reaches wp-login.php — copy it, bookmark it, or email it to yourself from the Support tab. You can regenerate it at any time.
Private by design
No external services, no CDN assets, no tracking. Login data stays in your database, is clearable from the History tab, auto-pruned after 30 days, and fully removed on uninstall.
Privacy
MSC Stealth Login collects the following data to provide its security features:
- IP Addresses: Logged for every login attempt (successful, failed, and locked out) to enable brute force protection and login history.
- Usernames: Logged with each login attempt to help administrators identify targeted accounts.
- User Agents: Logged with each login attempt for security auditing.
- Login History: All login attempts are stored in the database and can be viewed in the History tab or exported as CSV.
Data collection only occurs when the plugin is active. All collected data is stored in your WordPress database and is not sent to any external services. Administrators can clear login history at any time from the History tab.
This plugin does not use cookies or third-party tracking.
Installation
- Upload the plugin files to
/wp-content/plugins/msc-stealth-login/directory - Activate the plugin through the ‘Plugins’ menu in WordPress
- Navigate to Settings → MSC Stealth Login
- Configure your custom login URL (e.g.,
/secure-login/) - Enable additional security features as needed (brute force protection, email alerts, etc.)
- Save your recovery URL somewhere safe — bookmark it or store it securely
Important: After activation, immediately bookmark your new login URL and save your recovery URL in a secure location.
Frequently asked questions
How do I hide my WordPress login page?
Install and activate the plugin, go to Settings → MSC Stealth Login, and set a custom login slug (e.g. my-secret-door). Save — your login page now lives at yoursite.com/my-secret-door and wp-login.php no longer works for visitors. Bookmark the new URL and the Emergency Recovery URL immediately.
What happens when someone visits wp-login.php or wp-admin?
They are silently redirected (HTTP 302) to a URL you choose — the homepage by default. There’s no error page revealing that a protection plugin is running. Logged-in users, logout/password-reset flows, and AJAX requests keep working normally.
How do I block access to /wp-admin?
Enable “Hide wp-admin” on the Settings tab. Logged-out visitors who try to open any /wp-admin URL are silently redirected to a URL you choose (your homepage by default), while logged-in users and AJAX requests are unaffected. Combined with the custom login URL, this hides both your login page and your admin area from bots and vulnerability scanners.
What happens if I forget my custom login URL?
Use the Emergency Recovery URL shown on the Settings tab — copy or bookmark it when you set up the plugin (you can also email yourself the login URL from the Support tab). The recovery URL always reaches wp-login.php. If you lose both, rename the plugin folder via FTP/SFTP or run wp plugin deactivate msc-stealth-login — deactivating instantly restores the standard login page.
How do I recover access if I’m locked out?
Wait for the lockout period to expire, or use the Emergency Recovery URL. For immediate access, disable the plugin via FTP by renaming the plugin folder. Your IP can also be added to the allowlist if you have database access.
How does brute-force protection work?
Enable Advanced Security Features on the Advanced tab (it ships disabled so nothing surprises you). Then, after the configured number of failed attempts (default 3) from one IP, that IP is locked out for the configured duration (default 15 minutes). Optional progressive lockouts double the wait after each repeat offence, capped at your configured maximum. Successful logins reset the counter.
Can I allowlist my own IP so I’m never locked out?
Yes. Add exact IPs or CIDR ranges (IPv4 and IPv6) to the whitelist on the Advanced tab. Behind Cloudflare or a reverse proxy? Enable “Trust Proxy Headers” so the plugin sees real visitor IPs instead of the proxy’s.
Does it work on WordPress Multisite?
Yes. Activate it network-wide or per site — either way every site gets its own custom login URL, settings, login history and emergency recovery URL, and sites created later are set up automatically. Each site’s administrator configures it under Settings → MSC Stealth Login on their own site. By default failed-login counters are per site; enable “Share Lockouts Across Network” on the Advanced tab if you want a lockout earned on one site to apply across the whole network. Uninstalling removes the plugin’s data from every site on the network.
Does it block XML-RPC attacks and user enumeration?
Yes, both are on by default once Advanced Security is enabled. XML-RPC pingback and user-listing methods are disabled, and the REST API user endpoints plus ?author=N queries are blocked. Note: disabling XML-RPC affects the WordPress mobile app and some Jetpack features — leave it off if you use those.
Does this work with caching plugins?
Yes, but ensure your login pages aren’t cached — exclude your custom login URL from caching. The plugin detects six major cache/security plugins (W3 Total Cache, WP Super Cache, WP Rocket, Wordfence, iThemes Security, Sucuri) and shows a heads-up notice when one is active.
Can I run it alongside Wordfence or other security plugins?
Generally yes, but avoid overlapping features — if another plugin also limits login attempts or hides the login page, disable that feature in one of the two. Test on staging before production.
Does it work with WooCommerce login forms?
WooCommerce’s My Account login page is separate and keeps working. The plugin protects wp-login.php and wp-admin; test your specific checkout/membership flows on staging.
How do the email notifications work?
Navigate to Settings → MSC Stealth Login → Email tab. Enable the notifications you want and customize the subject and body using placeholders: {ip}, {attempts}, {time}, {site_name}, {site_url}. Notifications are sent immediately when events occur.
What data does it store? Is it GDPR-friendly?
Login attempts (IP, username, result, user agent, timestamp) are stored in your own database only — nothing is sent externally and there are no cookies or third-party requests. History is clearable from the History tab, auto-pruned after 30 days, and the table is removed completely on uninstall.
Is anything locked or paid?
No. Every feature is included in the plugin you download — there is nothing to unlock and no separate paid add-on.
Changelog
Translation maintenance release: adds 8 new languages (Russian, Simplified Chinese, Turkish, Polish, Indonesian, Swedish, Ukrainian, Arabic) and refreshes all 20 bundled locales to 100% string coverage. No functional changes — safe update.
1.3.2
- Updated translations: added 8 new languages (Russian, Simplified Chinese, Turkish, Polish, Indonesian, Swedish, Ukrainian, Arabic) and refreshed all 20 bundled locales to 100% string coverage. No functional changes.
1.3.1
- Tested with WordPress 7.1. No functional changes.
1.3.0
- Added: Multisite support — every site on a network now gets its own login-attempts table, settings and emergency recovery token, whether activated per site or network-wide, and new sites are set up automatically.
- Added: Optional “Share Lockouts Across Network” setting (Advanced tab, multisite only) so failed-login counters and progressive lockouts can be counted network-wide instead of per site.
- Fixed: Login History filters (IP, username, result, date) were silently ignored in the table, the entry count and the CSV export.
- Fixed: Fatal error when viewing Login History on WordPress 5.9–6.2 caused by calling a function that only exists in WordPress 6.3+.
- Fixed: The Filter and Clear Filters buttons on the History tab bounced you back to the Settings tab.
- Fixed: Export to CSV now exports the filtered view instead of everything, and no longer stops at 1,000 rows.
- Fixed: Uninstalling on a multisite network now cleans up every site, not just the current one.
1.2.0
- Changed: Support now links to the plugin’s WordPress.org support forum instead of the old contact button.
1.1.0
- Added: Automatic login-history pruning — entries older than 30 days are now cleaned up daily (filterable via
mscsl_log_retention_days). - Added: One-time, dismissible review request on the settings page (shown 7+ days after activation).
- Added: “Email Me My Login URL” form on the Support tab so you can keep the custom login URL on record.
- Fixed: Documentation incorrectly said the Emergency Recovery URL appears in the admin bar — it is shown on the Settings tab.
- Improved: WordPress.org listing rewritten — clearer title, searchable tags, expanded FAQ (incl. blocking /wp-admin), refreshed screenshot captions, and accurate description of which protections require the Advanced Security toggle.
1.0.9
- Tested with WordPress 7.0.2. No functional changes.
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
FAQ
MSC Stealth Login: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 5, 2026
Is MSC Stealth Login free?
Yes. MSC Stealth Login is free to download and use from the official WordPress.org plugin directory.
Is MSC Stealth Login safe to use in 2026?
MSC Stealth Login works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.
How many websites use MSC Stealth Login?
MSC Stealth Login is active on <10 WordPress websites and has been downloaded 401 times since it launched in May 2026. It was downloaded 70 times in the last 30 days.
Does MSC Stealth Login work with WordPress 7.1?
Yes. The developer has tested MSC Stealth Login up to WordPress 7.1.2, the latest release. It requires WordPress 5.9 or newer.
What PHP version does MSC Stealth Login need?
MSC Stealth Login requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was MSC Stealth Login last updated?
The latest version, 1.3.2, was released on August 28, 2026 (1 month ago).
Who makes MSC Stealth Login?
MSC Stealth Login is developed and maintained by djm56.
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card