Skip to content Skip to main navigation Skip to footer

How To

Hide wp-admin and wp-login.php from Source Code

Hiding the wp-admin and wp-login.php paths from source code it’s important especially when you use obscurity through security solution like Hide My WP Ghost.

The fastest way to change it is to use the mapping feature from Hide My WP Ghost. This way you can simply change the /wp-admin to a random name which will redirect the user to a page or to a 404 page.

(more…)

Setup Hide My WP Ghost on Ploi.io Server Management

Ploi.io service is similar with RunCloud and it helps you install your WordPress websites in minutes without being an expert. We found Ploi being a secure and accessible service.

To install Hide My WP Ghost plugin on a websites using Ploi.io, follow this tutorial.


1. Create a Server with Ubuntu + Nginx + PHP > 8



2. Create a website and add WordPress CMS

After you add WordPress on your server through Ploi, go to the website and finish the WordPress installation.


3. Install and setup Hide My WP Ghost

Now, follow the Hide My WP install & configuration like in this tutorial:

https://hidemywpghost.com/kb/hide-my-wp-ghost-tutorial/


4. Ploi.io with NGINX Server Type

When you select the Safe Mode or Ghost Mode in Hide My WP Ghost will detect the Nginx and will show you the hidemywp.conf file you need to add in Ploi.io panel in order to load the rewrite rules.

First, create the hidemywp.conf file on the website root directory through File Manager

Now, save the Safe Mode in Hide My WP Ghost and you will get the line you need to include in Ploi.io.

On Ploi.io panel, go to Manage and click on Edit NGINX configuration.

Add the include line that you copied from Hide My WP Ghost notification and add it before the ssl protocol definition.

Save the NGINX configuration and the changes will be applied automatically.

Go back to your website and test the login page. If the login is loading correctly, confirm the changes and you’re done.

WPMUDEV Server – Hide My WP Ghost Setup

Here’s how to set up the Hide My WP Ghost plugin on WPMUDEV server:

  1. Configure Hide My WP Ghost for your site the way you want it and make sure to save your settings using the Save button;
  1. Go to the website root directory using File Manager and download the hidemywp.conf file;
  1. Open a support ticket with WPMUDEV’s support team and send them the hidemywp.conf file in order to add the new paths to your website (your host will add the hidemywp.conf file in the Nginx and restart the server);

    (your host will be able to add the config line in the Nginx and restart the Nginx server);
  1. Back up the settings in HMWP Ghost from Hide My WP > Backup / Restore and deactivate the plugin until the rules are added by WPMUDEV support.

  1. Once you get the reply that the rules have been added, activate HMWP Ghost plugin and restore the settings in HMWP Ghost.

  1. Verify the login and confirm if the website loads correctly with the new paths.

You can learn more about how to use the Back Up and Restore feature here >>

Kinsta Server – Hide My WP Ghost setup

Here’s how to set up the Hide My WP Ghost plugin on Kinsta server:

  1. Configure Hide My WP Ghost for your site the way you want it and make sure to save your settings using the Save button;
This image has an empty alt attribute; its file name is image-1024x496.png
  1. Go to the website root directory using File Manager and download the hidemywp.conf file;
  1. Contact Kinsta’s support team and send them the hidemywp.conf file in order to add the new paths to your website (your host will add the hidemywp.conf file in the Nginx and restart the server);

  1. Back up the settings in HMWP Ghost from Hide My WP > Backup / Restore and deactivate the plugin until the rules are added in Nginx and the Nginx server is restarted.

  1. Once the rules are added, activate HMWP Ghost plugin and restore the settings to load the new paths.

  1. Verify the login and confirm if the website loads correctly with the new paths.

You can learn more about how to use the Back Up and Restore feature here >>

RELATED: Is Hide My WP Ghost compatible with Kinsta hosting?

Hide My WP Ghost

Ideal Hide My WP Ghost Settings – Best Practice 2022

Learn how to set up Hide My WP Ghost in Ghost Mode and activate all security features you need for a stronger and safer website in just 6 minutes.

VIDEO OUTLINE

  1. Min. 1.00 – 1.33: Select and Save GHOST MODE
  2. Min. 1.33 – 2.24: Change Paths Settings
  3. Min. 2.25 – 3.43: Tweaks Settings
  4. Min. 3.43 – 4.07: Brute Force Settings
  5. Min. 4.08 – 4.36: Events Log Settings
  6. Min. 4.36 – 5.29: Security Check
  7. Min. 5.29 – 6.28: View Changes

👉 Min. 01.00 – 1.33: Select and Save GHOST MODE


Recommended Actions:

  • Select Ghost Mode
  • A pop-up will appear showing you all the predefined paths that Hide My WP Ghost sets in Ghost Mode. READ the info.
  • Click on Continue, and then SAVE.
  • Run the Frontend Login test. 
  • SAVE your login URL (!very important that you do this)
  • SAVE your SAFE URL (!also very important, you’ll need this in case you can’t login)
  • If the test is successful, click on Yes, it’s working.

👉 Min. 1.33 – 2.24: Change Paths Settings


Admin Security

  • Custom Admin Path – Recommended action: Leave as is
  • Hide wp-admin – Recommended: ON 
  • Hide wp-admin From Non-Admin users – Recommended: ON
  • Hide the New Admin Path – Recommended: ON


Login Security

  • Custom Login Path – Recommended action: Leave as is
  • Hide wp-login.php – Recommended: ON 
  • Hide login Path – Recommended: ON
  • Custom Lost Password Path – Recommended action: Leave as is
  • Custom Register Path – Recommended action: Leave as is
  • Custom Logout Path – Recommended action: Leave as is


Ajax Security

  • Custom admin-ajax Path – Recommended action: Leave as is
  • Hide wp-admin from Ajax URL – Recommended: ON
  • Change Paths in Ajax Calls – Recommended: ON


User Security

  • Custom Author Path – Recommended action: Leave as is
  • Hide Author ID URL – Recommended: ON


WP Core Security

  • Custom wp-content Path – Recommended action: Leave as is
  • Custom wp-includes Path – Recommended action: Leave as is
  • Custom uploads Path – Recommended action: Leave as is
  • Custom comment Path – Recommended action: Leave as is
  • Hide WordPress Common Paths – Recommended: ON
  • Hide File Extensions – Recommended action: Leave as is


Plugins Security

  • Custom plugins Path – Recommended action: Leave as is
  • Hide Plugin Names – Recommended: ON
  • Hide All the Plugins – Recommended: OFF
  • Hide WordPress Old Plugins Path – Recommended: ON
  • Show Advanced Options– Recommended: OFF


Themes Security

  • Custom themes Path – Recommended action: Leave as is
  • Hide Theme Names – Recommended: ON
  • Hide WordPress Old Themes Path – Recommended: ON
  • Custom theme style name – Recommended action: Leave as is
  • Show Advanced Options – Recommended: OFF


API Security

  • Custom wp-json Path – Recommended action: Leave as is
  • Hide REST API URL link – Recommended: ON
  • Disable REST API access – Recommended: OFF
  • Disable XML-RPC access – Recommended: ON
  • Disable RSD Endpoint from XML- RPC – Recommended: ON


Firewall and Headers

  • Add Security Headers for XSS and Code Injection Attacks – Recommended: ON
  • Strict-Transport-Security – Recommended: ACTIVE, leave as is
  • Content-Security-Policy – Recommended: ACTIVE, leave as is
  • X-XSS- Protection – Recommended: ACTIVE, leave as is
  • X-Content-Type- Options – Recommended: ACTIVE, leave as is
  • Cross-Origin-Embedder- Policy – Recommended action: ADD then leave as is
  • Cross-Origin-Opener-Policy – Recommended action: ADD then leave as is
  • X-Frame-Options – Recommended action: ADD then leave as is
  • Remove Unsafe Headers – Recommended: ON
  • Block Theme Detectors Crawlers – Recommended: ON
  • Firewall Against Script Injection – Recommended: ON

👉 Min. 2.25 – 3.43: Tweaks Settings


Redirects

  • Redirect Hidden Paths – Recommended action: Leave as is (redirects hidden paths to your front page)
  • Do Login & Logout Redirects – Recommended: OFF


Feed and Sitemap

  • Hide Feed and Sitemap Link Tags – Recommended: ON
  • Change Paths in RSS feed – Recommended: ON
  • Change Paths in Sitemaps XML – Recommended: ON
  • Hide Paths in Robots.txt – Recommended: ON


Change Options

  • Change Paths for Logged Users – Recommended: ON
  • Change Relative URLs to Absolute URLs – Recommended: OFF


Hide Options

  • Hide Admin Toolbar – Recommended: ON
  • Select User Roles – Recommended action: Select the users roles for whom you DON’T want the Admin Toolbar to be visible.
  • Hide Version from Images, CSS and JS in WordPress – Recommended: ON
  • Hide IDs from META Tags – Recommended: ON
  • Hide WordPress DNS Prefetch META Tags – Recommended: ON
  • Hide WordPress Generator META Tags – Recommended: ON
  • Hide HTML Comments – Recommended: ON
  • Hide Emojicons – Recommended: ON
  • Hide Embed Scripts – Recommended: ON
  • Disable WLW Manifest scripts – Recommended: ON


Disable Options

  • Disable Right-Click – Recommended: ON
  • Disable Click Message – Recommended action: Leave as is, customization is not mandatory
  • Disable Inspect Element – Recommended: ON
  • Disable Inspect Element Message – Recommended action: Leave as is, customization is not mandatory
  • Disable View Source – Recommended: ON
  • Disable View Source Message – Recommended action: Leave as is, customization is not mandatory
  • Disable Copy/Paste – Recommended: ON
  • Disable Copy/Paste Message – Recommended action: Leave as is, customization is not mandatory
  • Disable Drag/Drop Images – Recommended: OFF
  • Disable DB Debug in Frontend – Recommended: ON

👉 Min. 3.43 – 4.07: Brute Force Settings

  • Blocked IPs report – Recommended action: Activate Brute Force Protection
  • Bruce Force Settings >> Use Brute Force Protection – Recommended: ON

!! In most cases, the Math reCAPTCHA is enough to protect your website against Brute Force login attacks.

  • Max fail attempts – Recommended action: Leave as is or customize based on preferences
  • Ban Duration – Recommended action: Leave as is or customize based on preferences
  • Lockout Message – Recommended action: Leave as is, customization is not mandatory

👉 Min. 4.08 – 4.36: Events Log Settings

  • Events Log Report – Recommended action: Activate Log Users Events
  • Events Log Settings >> Log Users Events – Recommended: ON
  • Log User Roles – Recommended: Leave as is (Hide My WP will log all user roles), or select specific user roles whose activity you want Hide My WP Ghost to log.

👉 Min. 4.36 5.29: Security Check

Recommended Actions:

  • Click on Start Scan to run a new WordPress security check. 
  • Check the list of Action Items that Hide My WP Ghost generated.
  • See if there are still issues that need to be resolved.
  • Follow the instructions to try and fix as many of them as possible.

By setting up Ghost Mode for your site, you’ve strengthened your site’s security, as shown by the graphic.


👉 Min. 5.29 – 6.28: View Changes

Recommended Actions: 

  • Click on Visit Site to see the changes you’ve enabled using Hide My Ghost take effect.
  • Log out from your account if you want to test things like: Right Click, View Source, and you’ll see that this functionality has been disabled for your site (based on your settings)
  • Take a look at your site’s source code to see the modified paths.

 

👋 Note! The settings shown in this video will work best for most sites – and present a way to quickly, safely, and effectively set up Ghost Mode for your site.

However, the ideal settings can look different from case to case, and you can always further customize these settings based on your needs and wants. 

We advise you to always read the documentation that we link to from within the plugin and ensure you clearly understand what each setting enables you to do.

Hide My WP Ghost Compatibility Themes List

Hide My WP Ghost is compatible with the most popular themes. We are continuously working on this to further extend the list of themes that Hide My WP Ghost is compatible with.

We’ve tested Hide My WP Ghost with over 1,000 plugins and themes so far, and we’ll keep at it. But if you DON’T see a theme you may be using on our list here just yet, it doesn’t mean Hide My WP Ghost won’t work with it or cause issues.

Hide My WP Ghost doesn’t physically change any path or file. Rewrites happen when a browser accesses files and paths.

Here are some of the latest themes we checked to make sure they work with Hide My WP Ghost.

This image has an empty alt attribute; its file name is list-building.jpg

Themes

Compatibility issues are unlikely, especially if you use the Safe Mode from Hide My WP Ghost.

Compatibility problems were fixed for:

  • Builders
  • Server hosting
  • Cache Plugins
  • Security Plugins

We fixed for those, because that’s where most issues were found in the past and we keep working on making it more compatible with them.

If you want us to test other WordPress plugins or themes, please contact us and send us the plugin/theme URL.

We are open to testing Hide My WP Ghost with more plugins and themes, as we are continuously looking for new ways to make Hide My WP Ghost as valuable as possible for a wide range of users.

[RELATED] Hide My WP Ghost Compatibility Plugins List

Hide My WP Ghost Exceptions

Hide My WP Ghost is compatible with all servers, hosting services, and also supports WordPress Multisite.

However, there are certain exceptions you need to take note of. We’ve documented these exceptions in this article, so make sure to keep reading.


Hide My WP Ghost with WordPress.com – Business plan

  • Automattic does NOT allow for the wp-admin and the wp-login paths to be customized. WordPress uses Jetpack for login security and doesn’t accept any changes made to wp-admin and wp-login.php.
  • you CAN, however, use Hide My WP Ghost to customize and hide other paths, such as WordPress Common Paths, in order to secure vulnerabilities related to plugins and themes. You can learn more about this here.

Hide My WP Ghost will not Work with Shared & Unmanaged NGINX Servers IF:

  • user is unable to add the hidemywp.conf file to nginx.conf (this is required in order for all rewrites to be loaded). So, in order to use Hide My WP Ghost, user needs to have access to NGINX config file and access to restart the service. Or, user needs to be able contact the host to add the path_to_file/hidemywp.conf file in NGINX and restart the service for them.
  • the host refuses to make changes in the nginx.conf file and restart NGINX.

Setup Hide My WP on RunCloud

If you run the service RunCloud, there are 2 easy options you can select on Application type who will run with Hide My WP Ghost plugin.


RunCloud – NGINX + Apache2 Hybrid

After you select to create the application WordPress on your server through RunCloud select the option NGINX + Apache2 Hybrid at the Web Application Stack. This way all the paths are loaded from .htaccess and there is no need for custom Nginx configuration.

Now, follow the Hide My WP configuration like in this tutorial:

https://hidemywpghost.com/kb/hide-my-wp-ghost-tutorial/#safeghostmode


RunCloud – Native NGINX

After you select to create the application WordPress on your server through RunCloud select the option Native NGINX at the Web Application Stack.

Hide My WP Ghost will detect the Nginx and will show you the hidemywp.conf file you need to add in RunCloud in order to load the rewrite rules.

First, create the hidemywp.conf file on the website root directory through File Manager

Now, save the Safe Mode in Hide My WP Ghost and you will get the line you need to include in RunCloud.

On RunCloud, go to NGINX Config and add the line from Hide My WP Ghost. Verify and save the settings.

For more configuration in Hide My WP Ghost, follow this tutorial:

https://hidemywpghost.com/kb/hide-my-wp-ghost-tutorial/#safeghostmode

To reload the Nginx config after you change the paths in Hide My Ghost click on Rebuild Web App Config and the plugin changes will take effect.

Hide The Old Image Paths with Hide My WP Ghost

Before hiding the images with old paths, it’s important to understand what this process entails and what are the risks involved.

Given the fact that images DON’T represent a security risk for your site, hiding them is NOT a necessity, or something we recommend doing to increase protection of your WordPress site.

From an SEO standpoint, if the images have already been indexed by Google, this is what will happen when someone lands on your site via Google Images: they will see a 404 Page Not Found error.

Even if you don’t use Hide My WP Ghost to hide images, over time, Google will index all images with the new paths without affecting SEO.

However, if you still wish to hide the images with the old paths, follow the steps below:


Hide Old Images

Add the following line to your wp-config.php:

define( 'HMW_HIDE_OLD_IMAGES', true );

Once you’ve added this, go to Hide My WP > Change Paths > WP Core Security, and you will see the option to hide Images files in the drop-down under the Hide WordPress Common Paths section (as shown in the screenshot below).

Select the IMAGE files option and Save your settings.

Once you do this, you can go ahead and check using another browser (or by going Incognito) to see if the old images can still be accessed.


Possible errors that might appear as a result of hiding old images

If your theme or other plugins load images into CSS or JS, then it’s possible for images not to load in frontend. A solution for this is using a cache plugin and activating the option to modify the paths in cache files using Hide My WP Ghost.

Use Hide My WP Ghost with SiteGround Security

Even if both plugins are considered WordPress Security plugins, SiteGround Security and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • SiteGround Security  prevent a number of threats such as brute-force attacks, compromised login, data leaks, and more.

HMWP Ghost will complement SiteGround Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, SiteGround Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

SiteGround Security

With the carefully selected and easy to configure functions the plugin provides everything you need to secure your website and prevent a number of threats such as brute-force attacks, compromised login, data leaks, and more.


User both plugins on your server to boost your security.

What Features to activate in Hide My WP Ghost when SiteGround Security plugin is activated.


FeaturesHMWP GhostSiteGround
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Brute Force Protection
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
Configurable lockout timings
Lockout Message
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with WP Cerber Security

Even if both plugins are considered WordPress Security plugins, WP Cerber Security and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • Wp Cerber Security defends WordPress against hacker attacks, spam, trojans, and malware.

Hide My WP Ghost will complement WP Cerber Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, WP Cerber Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

WP Cerber Security

WP Cerber Security mitigates brute-force attacks by limiting the number of login attempts through the login form, XML-RPC / REST API requests, or using auth cookies.

Tracks user and bad actors activity with flexible email, mobile and desktop notifications. tops spammers by using a specialized anti-spam engine. 


User both plugins on your server to boost your security

What Features to activate in Hide My WP Ghost when WP Cerber Security plugin is activated.


FeaturesHMWP Ghost Wp Cerber Security
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
LOGIN SECURITY
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY SCANNER
Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with BBQ Firewall

Even if both plugins are considered WordPress Security plugins, BBQ Firewall and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • BBQ Firewall protects your site against a wide range of threats.

HWMP Ghost will complement BBQ Firewall Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

BBQ Firewall

BBQ checks all incoming traffic and quietly blocks bad requests containing nasty stuff like:

 eval(base64_, and excessively long request-strings. 


User both plugins on your server to boost your security

What Features to activate in Hide My WP Ghost when BBQ Firewall plugin is activated.


FeaturesHMWP GhostBBQ Firewall
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Brute Force Protection
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
Configurable lockout timings
Lockout Message
SQL Injection Attacks Protection
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with Sucuri Security

Even if both plugins are considered WordPress Security plugins, Sucuri Security and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • Sucuri Security defend your website against hacks and DDoS attacks and more.

Hide My WP Ghost will complement Sucuri Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, Sucuri Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Sucuri Security

Sucuri safely remove any malicious code in your website file system and database.

Sucuri website firewall (WAF) blocks attacks by filtering malicious traffic. 


User both plugins on your server to boost your security

What Features to Activate in Hide My WP Ghost when Sucuri Security plugin is activated.


FeaturesHMWP GhostSucuri Security
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Brute Force Protection
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
Configurable lockout timings
Lockout Message
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with Anti-Malware Security

Even if both plugins are considered WordPress Security plugins, Anti-Malware Security and Brute-Force Firewall and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.

Hide My WP Ghost will complement Anti-Malware Security and Brute-Force Firewall Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, Anti-Malware Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Anti-Malware Security and Brute-Force Firewall

Download Definition Updates to protect against new threats. Firewall block SoakSoak and other malware from exploiting Revolution Slider and other plugins with known vulnerabilites. Upgrade vulnerable versions of timthumb scripts.


User both plugins on your server to boost your security

What Features to Activate in Hide My WP Ghost when Anti-Malware Security plugin is activated.


FeaturesHMWP GhostAM Security
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Brute Force Protection
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
Configurable lockout timings
Lockout Message
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with Limit Login Attempts Reloaded

Even if both plugins are considered WordPress Security plugins, Limit Login Attempts Reloaded and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • Limit Login Attempts Reloaded works like a shield against brute force attacks on login page.

HWMP Ghost will complement Limit Login Attempts Reloaded Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Limit Login Attempts Reloaded

Limit Login Attempts Reloaded stops brute-force attacks and optimizes your site performance by limiting the number of login attempts that are possible through the normal login as well as XMLRPC, Woocommerce and custom login pages.


User both plugins on your server to boost your security

What Features to Activate in Hide My WP Ghost when Limit Login Attempts Reloaded plugin is activated.


FeaturesHMWP GhostLoginizer
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Brute Force Protection
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
Configurable lockout timings
Lockout Message
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with Loginizer

Even if both plugins are considered WordPress Security plugins, Loginizer and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • Loginizer works like a shield against brute force attacks on login page .

HWMP Ghost will complement Loginizer Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Loginizer

It helps you fight against brute force attack by blocking login for the IP after it reaches maximum retries allowed.

You can blacklist or whitelist IPs for login using Loginizer. You can use various other features like Two Factor Auth, reCAPTCHA, PasswordLess Login, etc

Loginizer

Use both plugins on your server to boost your security.

What Features to Activate in Hide My WP Ghost when Loginizer plugin is activated.


FeaturesHMWP GhostLoginizer
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
LOGIN SECURITY
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with Wordfence Security

Even if both plugins are considered WordPress Security plugins, WordFence and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents access to vulnerable files, plugins and themes.
  • Wordfence works like a firewall to prevent Brute Force attacks, integrity scan, malware scan and more.

Hide My WP Ghost will complement Wordfence Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, Wordfence Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Wordfence Security

Wordfence firewall leverages user identity information in over 85% of the firewall rules, something cloud firewalls don’t have access to. And the firewall doesn’t need to break end-to-end encryption like cloud solutions.


User both plugins on your server to boost your security

What Features to Activate in Hide My WP Ghost when Wordfence plugin is activated.

FeaturesHMWP GhostWordfence
WORDPRESS FIREWALL
Change/Hide wp-admin Path
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change comments Path
Change/Hide Plugins Path
Change Themes Path
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Firewall Against Script Injection
Brute Force Attack Protection
LOGIN SECURITY
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY MONITOR
Cloud Events Log
Weekly Website Security Monitor Report
Checks User Activity on Login & Admin Dashboard
User Events Email Alerts
Notification Email Address

Hide My WP Ghost vs WP Hide & Security Enhancer PRO

HWMP Ghost will complement  WP Hide & SE PRO Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Hide My WP Ghost

Protect your site against hacker bots attacks, such as Script and SQL injection, brute-force, XSS, and more, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

WP Hide & SE PRO

Change the default WordPress login urls from wp-admin and wp-login.php to something totally arbitrary. No one will ever know where to try to guess a login and hack into your site. 


Hide My WP Ghost vs WP Hide features

FeaturesHMWP GhostWP Hide
Levels Of Security (under 5 min setup)
Change/Hide wp-admin Path
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
LOGIN SECURITY
Two-factor authentication (2FA) in progress
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address
SECURITY SUPPORT
Default WordPress Permalinks ?p=ID
ManageWP.com Integration
Cache Plugins Full Integration
Change Paths in Cache Directory
WordPress Multisite

Note! We included the features presented by WP Hide plugin on WordPress directory and the features found when we tested the plugin.


Use Hide My WP Ghost with Shield Security

Even if both plugins are considered WordPress Security plugins, Shield Security and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents access to vulnerable files, plugins and themes.
  • Shield Security works like a firewall against hackers and malicious bots, of all types and more.

HWMP Ghost will complement Shield Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, Shield Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Shield Security

It gives you a toolkit with everything you need to expertly secure your site, without being a security expert.

Instead, Shield does most of the heavy lifting for you, so you can get back to focusing on the work you love to do.

Shield Dashboard

User both plugins on your server to boost your security

What Features to Activate in Hide My WP Ghost when Shield Security plugin is activated.

FeaturesHMWP GhostShield Security
WORDPRESS FIREWALL
Change/Hide wp-admin Path
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change comments Path
Change/Hide Plugins Path
Change Themes Path
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Firewall Against Script Injection & Security Headers partially
LOGIN SECURITY
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard partially
Cloud Events Log
Weekly Website Security Monitor Report
User Events Email Alerts
Notification Email Address

Use Hide My WP Ghost with iThemes Security

Even if both plugins are considered WordPress Security plugins, iThemes Security and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents access to vulnerable files, plugins and themes.
  • iThemes works like a firewall to block bad bots, add login security , monitor site security and more.

HWMP Ghost will complement iThemes Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, iThemes Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

iThemes Security

The iThemes Security setup and onboarding experience is designed to allow anyone to secure their WordPress website in under 10 minutes, without needing a degree in cybersecurity

iThemes Security

User both plugins on your server to boost your security

See what features to activate on Hide My WP Ghost when using with iThemes Security

FeaturesHMWP GhostiThemes Security
WORDPRESS FIREWALL
Change/Hide wp-admin Path
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change comments Path
Change/Hide Plugins Path
Change Themes Path
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Firewall Against Script Injection
Brute Force Attack Protection
LOGIN SECURITY
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log
Weekly Website Security Monitor Report
User Events Email Alerts
Notification Email Address

Activate a New Website With Hide My WP Ghost

Depending on the purchased license and the limit of websites, you can connect websites to your account by installing the plugin on your websites.

To connect a new website to your account https://account.hidemywpghost.com/user/auth/connected follow these steps:

  1. Download the plugin from Orders / Licenses and copy the Activation Token
  2. Install the plugin on your WordPress site
  3. Use the Activation Token to activate the plugin and connect the website to your account

Your website will automatically appear at the Connected Website on your account https://account.hidemywpghost.com/user/auth/connected.


Delete Connected Website

Use this option if you want to remove the license from a website from your account or want to move the license to a different website.

Click to delete the connected website and the license will automatically remove from that website.

Note! The custom paths will change to WordPress defaults paths on the deleted websites. You will need to reactivate the Hide My WP Ghost plugin on the deleted website.

Now you can connect a different website using the activation steps from above.

How to change database prefix in WordPress

Almost everything that you do in WordPress is stored in databases. Your new plugins will use a database as well as the core WordPress system. Since databases contain all your information, it is important that you do everything you can to make it more secure.

Because more often than not, hackers use bots to search for security flaws in your website, it is not a good idea to have a default database name and prefix for your WP database.

If you had installed WordPress by yourself, you will remember that you had to input database information like the name of your new database, username, and a database prefix. Standard WordPress prefix for databases is wp_ and that is the one you want to change.

iThemes Security Tool

To apply a new prefix, you just need to verify that the wp-config.php is writable and that the Alter rights of the database are enable.

A single entry is need : the new database prefix. The plugin will generate a new one for you. You only have to press the button if you are ok with the generated prefix. Of course, the prefix will be added randomly.

  1. Go to the WordPress dashboard.
  2. Go to the ‘plugins’ tab and click on ‘add new.’
  3. Search iThemes Security in WordPress plugin repository.
  4. Click the Install button to install iThemes Security on your site.
  5. Click the Activate button to activate this plugin.

https://wordpress.org/plugins/better-wp-security/

Now, go to Dashboard > Security and after you do the onboarding, go to Security > Settings > Tools and Run a database prefix change and you’re done.

Use WP-Rocket with Hide My WP Ghost

Even if WP-Rocket doesn’t have a free version of the cache plugin, we tell you that it worth buying it as it’s probably the best cache plugin on the market.

  1. The WP-Rocket has all the features you need to optimize the WordPress site speed to 100%.
  2. WP-Rocket is focused on the website speed loading and not on security. It works great with the Hide My WP Ghost plugin.
  3. WP-Rocket has the option to Combine all CSS and JS files and also the inline styles.

With a bit of setup, WP Rocket + Hide My WP Ghost will help you secure your website & hide the plugins and themes from Themes Detectors.

To hide all CSS and JSS you need to follow the steps to Combine the JS and CSS files into one file. Let’s see how you can do this with the WP-Rocket plugin.

WP-Rocket > File Optimization > Combine JS Files

The plugin comes with the option to Minify & Combine the JS Files into one file. As we tested the plugin this is working really well with Change Paths in Cache Files option in Hide My WP Ghost.

Combine JS Files

The Combine JavaScript Files option will combine all of your JavaScript files into a single file.

Combine CSS and JS files will still result in a speed bump for certain types of WordPress sites, so we recommend testing your page speed with this option enabled and disabled.

Note! To hide the plugins’ JS URLs, make sure you activate the option “Combine JS-files” in WP-Rocket > File Optimization and let Hide My WP Ghost change the paths in the cached file.

WP-Rocket > File Optimization > Combine CSS Files

The plugin also comes with the option to Minify/Combine the CSS Files into one file.

Combine CSS Files

WP-Rocket “Combine CSS files” option will combine all of your CSS files into a single file.

Note! To hide all the plugins’ css files you need to activate the option “Combine CSS files” in WP-Rocket and let Hide My WP Ghost change the paths in the cached file.

Hide WP-Rocket cache path

Now that all the CSS and JS are combined, these files are present in the cache directory.

By default, the cache path is /cache/min/ but the URLs inside the cache are /cache/min/1/wp-content/ & /cache/min/1/wp-includes/ where 1 is the site ID.

Hide My WP Ghost will map and hide the WP-Rocket cache URL in Hide My WP > Mapping > URL Mapping:

Read more about URL Mapping here: https://hidemywpghost.com/kb/url-mapping-text-mapping/#url_mapping

Change Paths in Cache Files

To activate Hide My WP Ghost to change the paths in the cache file, go to Hide My WP > Tweaks > Change Paths in Cache Files and the plugin will automatically change the paths in background using WP Cron.

https://hidemywpghost.com/kb/activate-security-tweaks/#change_paths_cached_files

Note! If WordPress cron is deactivated on your website, you can manually click to change the paths once the files are cached.

Setup Hide My WP on Flywheel Server

As Flywheel stands apart from most other managed WordPress hosting companies by offering a number of features for both web designers and developers, more and more companies are moving to Flywheel server.

Flywheel is a Nginx based hosting and it will require some extra setup after you install Hide My WP Ghost plugin on your server.

Please follow this tutorial step by step to set up the Hide My WP Ghost for Flywheel server:

  1. In your WordPress dashboard, go to Hide My WP > Change Paths
  2. Select the Safe Mode or Ghost Mode,  scroll down and customize the paths as you like
  1. Click the Save button to save the changes.
  2. You will see a message to include the configuration file into nginx.conf file.

Ask the Flywheel Support to add the include /www/hidemywp.conf; in the nginx.conf (to add the line before the WordPress rules) and to restart Nginx.

Note! Do not logout until you get the confirmation from support that the config is included.

5. After the lines in added and the Nginx is reloaded, click the “Frontend Login Test” and see if the login page is loading correctly. You can also check the website with a different browser or from the incognito mode.

6. If everything loads fine in Frontend, click the button “Yes, it’s working” button. Otherwise click on “No, abort” to roll back to previous settings.

Enjoy Hide My WP Ghost and stay safe!

Use Autoptimize with Hide My WP Ghost

First, let’s see why Autoptimize is a great plugin and why you should use it with Hide My WP Ghost.

  1. The free version of Autoptimize has all the features you need to optimize the WordPress site speed.
  2. Autoptimize is strictly an optimization plugin and not a security plugin that works great with the Hide My WP Ghost plugin.
  3. Autoptimize has the option to combine all CSS and JS files and also the inline styles.
  4. Autoptimize has over 1 million active installs in the WordPress repository and is consistently updated with new features.

With a bit of setup, Autoptimize + Hide My WP Ghost will help you hide the plugins and themes from all Themes Detectors.

To hide all CSS and JSS you need to follow the steps to combine the JS and CSS files into one file. Let’s see how you can do this with the Autoptimize plugin.

Autoptimize – Combine JS Files

Autoptimize plugin comes with the option to Aggregate/Combine the JS Files into one file. As we tested the plugin this is working really well with Change Paths in Cache Files option in Hide My WP Ghost.

Aggregate JS Files

Autoptimize’s “aggregate JS files” option will combine all of your JavaScript files into a single file.

Aggregating CSS and JS files will still result in a speed bump for certain types of WordPress sites, so we recommend testing your page speed with this option enabled and disabled.

Note! To hide the plugins’ JS URLs, make sure you activate the option “Aggregate JS-files” in Autoptimize and let Hide My WP Ghost change the paths in the cached file.

Also Aggregate Inline JS

The “also aggregate inline JS” option extracts inline JS in your HTML, and combines it with Autoptimize’s optimized JS file. Since this option can cause a rapid increase in Autoptimize’s cache size, we recommend keeping this option disabled unless you have a specific reason to enable it.

Autoptimize – Combine CSS Files

Autoptimize plugin also comes with the option to Aggregate/Combine the CSS Files into one file.

Aggregate CSS Files

Autoptimize’s “aggregate CSS files” option will combine all of your CSS files into a single file.

Note! To hide all the plugins’ css files you need to activate the option “Aggregate CSS files” in Autoptimize and let Hide My WP Ghost change the paths in the cached file.

Also Aggregate Inline CSS

This option will move inline CSS to Autoptimize’s CSS file. While moving inline CSS to a browser-cacheable CSS file can reduce page size, we recommend leaving this option disabled in most cases.

Hide Autoptimize cache path

Now that all the CSS and JS are combined, these files are present in the cache directory.

By default, the cache path is /core/cache/autoptimize/ which pretty much says that you are using Autoptimize plugin.

To fix this, simply map the URL with a custom name like in the below example from Hide My WP > Mapping > URL Mapping:

Read more about URL Mapping here: https://hidemywpghost.com/kb/url-mapping-text-mapping/#url_mapping

Change Paths in Cache Files

To activate Hide My WP Ghost to change the paths in the cache file, go to Hide My WP > Tweaks > Change Paths in Cache Files and the plugin will automatically change the paths in background using the cron option.

https://hidemywpghost.com/kb/activate-security-tweaks/#change_paths_cached_files

Note! If WordPress cron is deactivated on your website, you can manually click to change the paths once the files are cached.

Setup Hide My WP on Amazon AWS Lightsail

Apache version on AWS Lightsail WordPress

Step1: Install, Setup Hide My WP Ghost Plugin and click the Save button with the new paths.

Step2: Copy the rewrite rules from Hide My WP Ghost into Bitnamy config file

AWS Lightsail (Bitnami) doesn’t enable overrides using .htaccess by default and the structure of the Apache config files is a bit different.

Bitnami uses “htaccess.conf” files by default instead of “.htaccess” files for security and performance reasons. You can find more info at https://docs.bitnami.com/general/apps/redmine/administration/use-htaccess/

(more…)

Use Hide My WP with Really Simple SSL

In this article will show you how to make Hide My WP Ghost compatible with the well known Really Simple SSL plugin.

First I want to congratulate the authors of the Really Simple SSL plugin who created such a simple and efficient plugin.

Now, Hide My WP Ghost works well with most of the Really Simple SSL options.

The only option that needs a bit of attention,if the 301 redirect with .htaccess which adds the rewrite rules in the .htaccess file after the Hide My WP Ghost rules.

To make sure the plugins are working together well after you save the options in Really Simple SSL plugin, save the settings in Hide My WP Ghost too. This way the rules are moved to the beginning or the .htaccess file.

# BEGIN rlrssslReallySimpleSSL
RewriteEngine on 
RewriteCond %{HTTPS} !=on [NC] 
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]
# END rlrssslReallySimpleSSL

Note! If the .htaccess file is not writable, make sure you manually move the Really Simple SSL rewrite rules to the beginning of the .htaccess file and save the file.

That’s all. Enjoy the plugins and stay safe!

Please contact us if you have any question.

Use Hide My WP Ghost with Manage WP

We are glad to announce that Hide My WP Ghost is now working with the Manage WP Godaddy plugin.

This is great news for developers who have many websites to manage and want to secure them with a custom wp-admin path.

How to configure Hide My WP Ghost

  1. Install the free Hide My WP Ghost plugin from https://wordpress.org/plugins/hide-my-wp/ (or the premium one)
  2. Activate the plugin and secure the WordPress paths.

How to configure Manage WP

  1. You can access your account or create a new one at https://managewp.com/
  2. Install the free Manage Worker plugin on your website https://wordpress.org/plugins/worker/
  3. Connect your website using the API key from the plugin description in the Plugins tab

Once you connected your plugin, Hide My WP Ghost will know how to handle the compatibility and you will be able to connect to your admin area directly from the Manage WP panel.

Let us know if you have any question.

Hide My WP Advanced Text Mapping

Hide My WP Ghost 5.0.12 brings new ways customize or hide the classes from your source code.

Hide Class Name

If you want to completely hide a class use the {blank} pattern to accomplish that.

Random Class Name

If you want to set a random id for a specific class, use the {rand} pattern to accomplish that.

The most common classes used by WordPress and can be detected by theme detectors are those who contain the prefix wp-. Check the website source code and see if you find classes with wp- and add them in the Text Mapping.

Check the frontent every time

Check the frontent to make sure that the class you’re mapping it’s not used by the WordPress Theme.

Demo Text Mapping in Hide My WP Ghost

Here is a list of classes we usually add in Text Mapping for our WordPress websites:

Read Also: Do I Need to Hide WordPress From Detectors or Hackers?