Alternate WordPress login URL Revealed
-
I routinely use an alternate WordPress login URL to hide my login area from hackers and bots. It completely prevents login attacks. However, upon cloning my website with WP Staging, I opened up the new admin site and proceeded to change the default WordPress login URL to an alternate one that I use for my other sites. Immediately after doing this, a crawler came to the new staging site and visited the new “hidden” WordPress login page! I have never had this alternative login site breached before by a bot. The bot that found this secret login URL was the BomboraBot and the breach occurred within seconds of creating the new wp-login URL.
Somehow, WP Staging revealed my secret wp-login site and the BomboraBot found it! I have inspected the pages on the staging site, and the only way to find any reference to the secret wp-login URL is if someone was successfully logged into the staging site’s admin and inspected the header information, which only then shows the hidden login URL.
Please let me know if there is a security issue with the use of the WP Staging plugin to create a cloned staging site. If I can’t determine where the breach occurred, then I’ll have to uninstall the plugin and change the alternative wp-login URL for my other sites.
- The topic ‘Alternate WordPress login URL Revealed’ is closed to new replies.