Search: hide theme

147 results

WP Ghost Free vs Premium - Full Feature Comparison

… Yes Change wp-content path Yes Yes Change wp-includes path Yes Yes Change uploads path Yes Yes Change author path Yes Yes Change comments path Yes Yes Change admin-ajax.php path Yes Yes Change REST API wp-json path Yes Yes Change plugin directory path Yes Yes Change theme directory path Yes Yes Hide plugin names with random names Yes Yes Hide theme names with random names Yes Yes Hide WordPress old plugins path Yes Yes Hide WordPress old themes path Yes Yes Hide WordPress common paths Yes Yes Custom theme style name Yes Yes Custom login/logout …

How to Set Up WP Ghost in Safe Mode in 3 Minutes - Quick Start Guide

… uploads, and comment paths at their defaults. Switch ON: Hide WordPress Common Paths and Hide WordPress Common Files. Add wp-comments-post.php to the Hide Common Files list. Leave Disable Directory Browsing OFF (your hosting may handle this already).

Plugins Security

Leave Custom plugins Path at default. Switch ON: Hide Plugin Names and Hide WordPress Old Plugins Path. Leave Hide All the Plugins OFF and Show Advanced Options OFF.

Themes Security

Leave Custom themes Path at default. Switch ON: Hide Theme Names and Hide WordPress Old Themes Path. Leave Advanced Options OFF.

API Security

Leave Custom wp-json Path …

How Do I Hide the WordPress Version?

… also hide IDs from META tags to remove plugin and theme identifiers from element IDs, change and hide plugin paths so directory names don’t reveal your plugin stack, and change and hide theme paths so your theme name doesn’t appear in the source. Together with version hiding, these features make your WordPress installation extremely difficult to identify.

For a comprehensive guide to removing every detection signal, see the hide from theme detectors tutorial.

Frequently Asked Questions

Does this also remove the meta generator tag?

Yes. The “Hide Version from Images, CSS, and JS” feature removes the tag …

How Do I Hide the Theme Name in WordPress?

theme includes a style.css file with a standardized header that contains the theme name, version number, author URL, and description. This is a complete fingerprint that any scanner can read with a single request. Hiding the theme name means removing all of these signals from your site.

How to Hide the Theme Name with WP Ghost

WP Ghost offers six layers of theme protection. For complete theme hiding, enable them all. Start by activating Safe Mode or Ghost Mode at WP Ghost > Change Paths > Level of Security, then configure the theme-specific options.

Change the themes path. Go to …

Can WP Ghost Hide the Plugins and Theme You're Using?

… path, hide theme names (replaces each theme directory with a random code), hide all themes (includes inactive themes whose files can still be exploited), hide the old themes path (blocks the original URL), and rename the theme style file (changes to a custom name like ).

Renaming is especially effective. Every theme detector specifically looks for this file because its header contains the theme name, version, and author in a standardized format. Rename it, and that detection method fails completely.

For the full walkthrough, see the change themes path tutorial.

Should I Also Hide WordPress Common Paths?

Yes. Hiding plugin and …

How Do I Make My WordPress Site Invisible?

… with real-time detection tools to verify you’re actually invisible. Use sites like wpthemedetector.com, whatwpthemeisthat.com, or whatcms.org. If WP Ghost is configured correctly, these tools won’t be able to identify WordPress, your theme, or your plugins.

For the complete hiding checklist covering every signal detectors look for, see the hide from theme detectors guide.

Can I Also Block AI Crawlers from Scraping My Content?

Yes. WP Ghost includes a dedicated Block AI Crawler Bots toggle in the Firewall settings. When enabled, it blocks GPTBot, ClaudeBot, PerplexityBot, CCBot, Bytespider, and over 30 other known AI …

Why Do Detectors Like IsItWP Still Show WordPress CMS?

… they can’t identify WordPress, your configuration is solid, regardless of what IsItWP or BuiltWith show from their cache.

Never test with browser extensions while logged in. Chrome extensions like Wappalyzer, WhatRuns, and BuiltWith detect WordPress through admin-only signals when you’re logged in. They may cache that result permanently and show WordPress every time, even when public visitors see a fully hidden site. Always use a separate browser profile or incognito window for testing.

For the complete hiding checklist and testing methodology, see the hide from theme detectors guide.

Can I Block Theme Detector Crawlers Entirely?

Yes. WP

How to Protect Your WordPress Website from Hackers

… to WP Ghost > Security Check > Start Scan to see your security score and fix any remaining issues with the “Fix it” buttons.

WP Ghost is designed to work alongside other security tools. You can run it together with Wordfence, Solid Security, Sucuri, or your hosting’s built-in firewall. WP Ghost handles prevention (blocking attacks at the door) while other plugins handle detection and response (scanning for malware, monitoring file changes).

For a complete recommended configuration, follow the WP Ghost best practice guide. For the full hiding checklist, see hide from theme detectors.

Frequently Asked Questions

Is WP Ghost …

WP Ghost Compatible Themes List - Tested WordPress Themes for 2026

… ContentsHow Theme Compatibility WorksMultipurpose ThemesWooCommerce and eCommerce ThemesDirectory and Listing ThemesCommunity and Membership ThemesTheme Compatibility TipsFrequently Asked QuestionsMy theme is not on this list. Will it work?Will WP Ghost hide my theme from theme detectors?My theme uses a page builder. Will it still work?Does WP Ghost modify theme files?Can I request compatibility testing for my theme?

WP Ghost is tested and compatible with all major WordPress themes. It does not physically modify any theme files – all path changes use server rewrite rules. This page lists every theme we have specifically tested and verified.

How Theme Compatibility …

Do I Need to Hide WordPress From Detectors or Hackers?

… label sites, hiding the WordPress identity from clients and their visitors can be important.

WP Ghost’s CMS Simulator takes detector-hiding one step further. Instead of just removing WordPress signals, it injects fake Drupal or Joomla fingerprints. Scanners don’t report “unknown.” They confidently identify the wrong CMS. For theme detector setup, see the Hide From Theme Detectors tutorial.

The Good News: Security Covers Both

When you set up WP Ghost for security (by activating Safe Mode or Ghost Mode and changing your WordPress paths), you automatically hide from theme detectors as a side effect. The path changes that …

Is There a Way to Hide My WordPress Site?

… your login path, save, and bookmark the new login URL.

For step-by-step configuration, the process is: select a security level (Safe Mode or Ghost Mode), customize your paths, enable Hide WordPress Common Paths and Hide WordPress Common Files, activate the hiding options in WP Ghost > Tweaks (version numbers, generator META, DNS prefetch, HTML comments, emojis, embed scripts), use Text Mapping to replace WordPress class names, enable sitemap and robots.txt cleanup, block theme detector crawlers, and run a Security Check to verify everything.

For the complete 9-step hiding checklist, see the hide from theme detectors tutorial …

How to Remove DNS Prefetch from WordPress for Better Security

… to hide WordPress?

No. The DNS prefetch link is just one of many WordPress fingerprints. You also need to remove the generator meta tag, version numbers, default paths, HTML comments, and style IDs. WP Ghost handles all of these from a single settings page. For the complete checklist, follow the Hide From Theme Detectors guide.

What other WordPress fingerprints should I remove?

In addition to DNS prefetch, WP Ghost can remove the WordPress generator meta tag, WordPress version numbers from CSS and JS files, RSD (Really Simple Discovery) header, WLW Manifest link, emoji scripts, HTML comments, and style/meta IDs …

How Can I Hide Plugins From WordPress Detectors?

… wp-content.

Plugin-specific class names and IDs. Some plugins add recognizable class names to the HTML (like for Contact Form 7). WP Ghost’s Text Mapping feature at WP Ghost > Mapping > Text Mapping lets you replace these class names with custom strings. This removes the final fingerprints that detectors could use to identify specific plugins.

For the complete plugin-hiding setup, see the Change Plugins Path tutorial. For the full detector-hiding guide covering themes and CMS identity as well, see the Hide From Theme Detectors tutorial.

Quick Setup

The fastest approach is to activate Ghost Mode at …

How to Change the wp-content Directory in WordPress for Better Security

… plugins that hardcode the /wp-content/ path. It is also harder to undo – you need to reverse the wp-config.php changes and rename the folder back.

You can also combine both methods. Physically rename the directory first, then use WP Ghost to change the remaining paths (plugins, themes, uploads, login, admin) and add the 8G Firewall on top. WP Ghost detects the custom WP_CONTENT_DIR constant and works with it automatically.

What Else You Should Change

Changing wp-content alone is a good start, but bots also target other default paths. For complete path security, also change …

How Do I Know If My WordPress Site Is Hidden With WP Ghost?

… should either report a different CMS (if you enabled the CMS Simulator), report “Unknown,” or fail to detect WordPress entirely. If they still identify WordPress, see the troubleshooting section below.

What to Do If WordPress Is Still Detected

If external tools still identify your site as WordPress after activating WP Ghost, one or more WordPress signals are leaking through. The most common causes and their fixes are listed here.

wp-content or wp-includes still visible in the source. Go to WP Ghost > Change Paths > WP Core Security and make sure both the Custom wp-content Path and Custom …

How to Verify Your WordPress Site Is Protected from Hackers and Theme Detectors

Moved

This tutorial has moved to the new WP Ghost Knowledge Base where each feature is presented in detail.

View on new site

Table of ContentsWhy Verifying Your Security Configuration MattersBefore You Verify – Complete the SetupStep 1 – Run the Built-in Security CheckStep 2 – Test with Third-Party Security ScannersStep 3 – Verify with WordPress Theme DetectorsDetectors to Avoid for TestingHow to Test Correctly Every TimeWhat to Do If a Detector Still Identifies WordPressVerification ChecklistFrequently Asked QuestionsHow often should I run a security check?A detector shows WordPress but the Security Check passes. What is happening?Do I need to hide …

Lesson 3 - How to Hide WordPress from Theme Detectors and Hacker Bots

MovedThis tutorial has moved to the new WP Ghost Knowledge Base where each feature is presented in detail.View on new site

Table of ContentsHide Old WordPress PathsBlock Theme DetectorsEnable Security TweaksUse Text Mapping to Replace WordPress ClassesUse URL Mapping and Cache PluginsAdditional ConfigurationVerify Your ConfigurationFrequently Asked QuestionsWill hiding all WordPress paths affect SEO?A theme detector still identifies my site. What should I check?Is it safe to replace all wp- class names?Does WP Ghost modify WordPress core files?Related Tutorials

Changing WordPress paths is the first step, but additional configuration is needed for full protection. Hide old …

How to Hide WordPress from Detectors: Erase the Fingerprints That Make You a Target

… declares by name, and your XML carries the generator version too.

Author URLs. Visiting redirects to a user’s archive, handing over a valid username for brute-force attempts.

Every detector on the internet is a script reading some subset of that list. Erase the list and the script comes back empty.

How to Hide WordPress from Detectors, Step by Step

Work through these in order. Each step removes a category of fingerprints, and Hide My WP Ghost automates every one of them from a single settings screen.

Strip the version fingerprints. Remove the generator meta tag, delete query …

How to Hide Your WordPress Footprint: Remove the Traces That Expose Your Site

… bots that hammer by default. It also removes another confirmation signal.

Remove HTML comments and oEmbed/emoji tells. Theme and plugin comments, the emoji script, and DNS-prefetch tags for all point back to WordPress. Clear them from your rendered output.

You can apply most of these through your theme’s and server rules. The catch is durability, which is the next problem.

Why Detectors Still Flag You After You Remove the Meta Tag

You delete the generator tag, reload a detector, and it still says WordPress with total confidence. That is normal. Detection is layered on purpose. A …

WP Ghost vs Wordfence vs Sucuri vs Solid Security

… – Hide plugin and theme directory names Free – – – Change REST API path Free – – – Strip WordPress version, meta, RSD headers Free – Free Free Hide common files (readme, license, wp-config) Free – – – Text, URL, and CDN mapping Free – – – Firewall 7G / 8G server-edge firewall Free – – – Application-level firewall (PHP / WordPress context) Free Free Paid – Cloud WAF (traffic filtered before reaching server) – – Paid – SQL injection protection Free Free Paid – XSS protection Free Free Paid – Security headers (HSTS, CSP, X-Frame-Options) Free – – – Block theme detector bots Free – – – Block AI crawlers (GPTBot, ClaudeBot, etc.) Premium – – – Authentication & Login Security 2FA by code (TOTP / authenticator app …

WordPress Hack Prevention: The Complete 2026 Guide

… signatures and blocking the ones that look like exploits. This matters because standard hosting firewalls miss 87.8% of WordPress-specific exploits, they were built for broad traffic filtering, not application-layer semantics.

The 7G and 8G firewall rulesets are the standard for WordPress edge filtering in 2026. They cover SQL injection payloads, XSS patterns, file inclusion probes, directory traversal attempts, and automated vulnerability scans. Combined with IP blocking for repeat offenders and security headers that force the browser to behave, the firewall layer catches what Layer 1 didn’t deter.

Layer 3: Harden the Authentication Points

Even with …

WordPress Hack Prevention - How to Stop Attacks Before They Start

… place?

They do not need to know your site exists. Bots scan IP ranges and follow links continuously. When they hit your site, they check for default WordPress paths. If those paths respond as expected, your site is logged as a WordPress installation and added to targeting lists. This takes seconds and runs at massive scale, constantly.

The Bottom Line

You do not prevent WordPress hacks by reacting faster. You prevent them by removing the conditions that make your site a target in the first place.

If your site still uses default WordPress paths, it is identifiable. Bots are …

Hide WordPress Version Numbers and Generator META with WP Ghost

Moved

This tutorial has moved to the new WP Ghost Knowledge Base where each feature is presented in detail.

View on new site

Table of ContentsHow to Hide WordPress VersionEnable Random Static NumberFrequently Asked QuestionsDoes this hide plugin and theme versions too?Should I always enable Random Static Number?Does hiding versions affect SEO?Does WP Ghost modify WordPress core files?

Remove WordPress version numbers from your source code with one toggle in WP Ghost. This hides the generator META tag, strips ?ver= parameters from all CSS and JS files, removes generator tags from WPML, Slider Revolution, and WPBakery, and …