Skip to content

WP Admin login and custom login addresses

How Log in to WP Admin and Visit WP login work, and how Avaloi follows a login page that a security plugin moved to a secret address.

Your site's Info tab has two ways into WordPress admin:

  • Log in to WP Admin signs you in without a password. The link works once and expires after 60 seconds.
  • Visit WP login opens the WordPress login form, where you sign in with your WordPress username and password.

The Domains tab has the same Visit WP login link under the primary domain.

Sites with a custom login address

Security plugins such as Solid Security, WPS Hide Login, Patchstack, and All-In-One Security can move the login page from /wp-login.php to a secret address, for example /my-secret-login/. Visitors who try /wp-login.php or /wp-admin then get an error page.

Avaloi follows the change:

  • The Avaloi MU plugin asks WordPress where its login page is, the same way WordPress builds the address for a visitor who is signed out.
  • Visit WP login opens that address. A Custom login address label shows next to the link, with the name of the plugin that moved it when Avaloi can tell.
  • Avaloi checks the address again when it is more than an hour old, and after a plugin is activated, deactivated, installed, updated, or deleted through Avaloi.
  • Until the site has reported its address, the link opens /wp-login.php.

The link always uses your primary domain, or the temporary domain when the site has no primary domain yet. Only the path comes from the site.

Log in to WP Admin keeps working with these plugins. It signs you in before they check the request, then opens the admin address WordPress reports.

Who can see the address

A custom login address is a secret that keeps bots away from your login form. Avaloi shows it only to people who can see the site in the dashboard, and to API keys with the sites:read scope. It is never part of the public health check.

The API route is GET /v1/environments/{id}/wp-login-url.

Quick answers

Visit WP login opens a page that does not exist. The address may have changed in the last hour outside Avaloi, for example from the plugin's settings in WP Admin. Wait a moment and reload the dashboard, or use Log in to WP Admin, which does not need the login page.

The label says a plugin on this site changed the address, with no name. Code that Avaloi does not recognize, such as a theme or a custom plugin, changed the address. The link still opens the right page.

Can I turn the custom address off? Yes, in the settings of the plugin that set it. Avaloi picks up the change within the hour.

For WordPress users and one-click login as another user, see WordPress users and one-click login.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.