Private Website – Login Required
This plugin requires users to be logged in to view the website. Activate the plugin to enforce login, and deactivate it to remove the restriction.
Use with caution
Private Website – Login Required works, but test it on a staging site before relying on it in 2026. It runs on 200+ sites, is rated 5/5 and was last updated 4 months ago, and scores 61/100 on our health check.
- Small user base (200+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Private Website stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| login | >100 |
| members | >100 |
| private | #10 |
| Restrict access | #57 |
| user authentication | #66 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 1 reviews
About Private Website – Login Required
From the official readme · v0.3.2Description
Private Website – Login Required is a simple and straightforward WordPress plugin designed to restrict access to your website. By activating this plugin, users must be logged in to view any content on your site. This is ideal for websites that host sensitive or exclusive content and want to ensure that only authenticated users can access it.
There are no complicated settings to configure. Simply activate the plugin to enforce the login requirement and deactivate it to remove the restriction.
This plugin was developed by Robin Oehler.
Privacy Policy
Private Website – Login Required uses Appsero SDK to collect some telemetry data upon user’s confirmation. This helps us to troubleshoot problems faster & make product improvements.
Appsero SDK does not gather any data by default. The SDK only starts gathering basic telemetry data when a user allows it via the admin notice. We collect the data to ensure a great user experience for all our users.
Integrating Appsero SDK DOES NOT IMMEDIATELY start gathering data, without confirmation from users in any case.
Learn more about how Appsero collects and uses this data.
Bugs & Feedback
Your feedback is important to me. If you find mistakes, have wishes, ideas, or suggestions, please send an email to mail@roehler.nrw.
Legal notice (German): https://roehler.nrw/impressum/
You are free to use it on any website across countries to protect the privacy of your users.
Note: Activating this plugin cannot guarantee that your website is completely compliant with GDPR. When using Google Analytics, Facebook pixels, or other similar tools, additional measures may need to be taken.
Installation
- Upload the plugin files to the
/wp-content/plugins/private-websitedirectory, or install the plugin through the WordPress plugins screen directly. - Activate the plugin through the ‘Plugins’ screen in WordPress.
- Once activated, the plugin will automatically restrict content to logged-in users only.
- To remove the login requirement, simply deactivate the plugin.
Frequently asked questions
What does this plugin do?
This plugin restricts access to your website content to only logged-in users. If a user is not logged in, they will be redirected to the login page.
Are there any settings I need to configure?
No, there are no settings to configure. Simply activate the plugin to enforce the login requirement and deactivate it if you no longer want to restrict access.
Can I allow access to specific pages without login?
Currently, the plugin does not provide the option to allow access to specific pages without login. It restricts access to the entire website.
How do I stop the login requirement?
To stop requiring a login to access your site, simply deactivate the plugin from the ‘Plugins’ screen in WordPress.
Changelog
Bugfix release: resolves broken images and media files for logged-in users. Recommended update for all users.
0.3.2
- Bugfix: Serve uploaded media files directly using PHP when user is logged in (prevents 404/broken images caused by .htaccess redirection).
0.3.1
- Security: Block wp-comments-post.php for non-logged-in users (bypassed template_redirect).
- Security: Block wp-admin/admin-post.php for non-logged-in users (prevents nopriv form actions).
- Security: Block wp-mail.php for non-logged-in users.
- Compatibility: Dynamic uploads path detection — supports custom content directories.
- Compatibility: AJAX whitelist is now filterable via
private_website_allowed_ajax_actions(for 2FA plugins etc.). - Compatibility: XML-RPC disable is now filterable via
private_website_xmlrpc_enabled(for Jetpack etc.). - Compatibility: Updated “Tested up to” for WordPress 7.0.
- Compatibility: Raised minimum PHP version to 7.4 (matching WordPress 7.0 requirements).
0.3.0
- Security: Protect direct access to uploaded files (images, PDFs, videos) via .htaccess in uploads directory.
- Security: Restrict REST API access to authenticated users only (prevents data leaking via /wp-json/).
- Security: Disable XML-RPC completely (prevents brute-force attacks and content leaking via xmlrpc.php).
- Security: Block RSS/Atom feeds for non-logged-in users (prevents content leaking via /feed/).
- Security: Restrict AJAX requests to a whitelist of allowed actions for non-logged-in users.
- Security: Disable XML sitemaps for non-logged-in users to prevent site structure leaking.
- Security: Make robots.txt fully restrictive (Disallow: /) to prevent search engine indexing.
- Improvement: Creates a self-contained .htaccess in wp-content/uploads/ instead of modifying the root .htaccess.
- Improvement: Show admin notice when .htaccess cannot be created or when Nginx is detected.
- Improvement: Clean up .htaccess on plugin deactivation. Supports subdirectory installs.
0.2.9
- Ask for Appsero consent again after each admin login until consent is granted (re-prompts post-login).
0.2.8
- Show tracking status badge directly in the plugin description (Plugins screen).
0.2.7
- Add opt-in/out action link directly in the Plugins screen for this plugin (enables/disables Appsero tracking).
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Private Website alternatives
All login plugins →FAQ
Private Website – Login Required: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 8, 2026
Is Private Website – Login Required free?
Yes. Private Website – Login Required is free to download and use from the official WordPress.org plugin directory.
Is Private Website – Login Required safe to use in 2026?
Private Website – Login Required works, but test it on a staging site before relying on it in 2026. It runs on 200+ sites, is rated 5/5 and was last updated 4 months ago, and scores 61/100 on our health check.
How many websites use Private Website – Login Required?
Private Website – Login Required is active on 200+ WordPress websites and has been downloaded 4,119 times since it launched in September 2024. It was downloaded 211 times in the last 30 days.
Does Private Website – Login Required work with WordPress 7.1?
Private Website – Login Required is officially tested up to WordPress 7.0.7, while the latest release is 7.1.3. It may still work, but try it on a staging site first.
What PHP version does Private Website – Login Required need?
Private Website – Login Required requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Private Website – Login Required last updated?
The latest version, 0.3.2, was released on June 16, 2026 (4 months ago).
Who makes Private Website – Login Required?
Private Website – Login Required is developed and maintained by roehler.
What are the best alternatives to Private Website – Login Required?
The most popular alternatives to Private Website – Login Required are WPS Hide Login (2M+ installs), Loginizer (1M+ installs) and Security Optimizer (1M+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card