Skip to contentSkip to main navigation Skip to footer

How To

Use Hide My WP Ghost with SiteGround Security

Even if both plugins are considered WordPress Security plugins, SiteGround Security and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.

Does Hide My WP Ghost work for SiteGround hosted websites?


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • SiteGround Security  prevent a number of threats such as brute-force attacks, compromised login, data leaks, and more.

HMWP Ghost will complement SiteGround Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, SiteGround Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

SiteGround Security

With the carefully selected and easy to configure functions the plugin provides everything you need to secure your website and prevent a number of threats such as brute-force attacks, compromised login, data leaks, and more.


User both plugins on your server to boost your security.

What Features to activate in Hide My WP Ghost when SiteGround Security plugin is activated.


FeaturesHMWP GhostSiteGround
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Brute Force Protection
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
Configurable lockout timings
Lockout Message
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with WP Cerber Security

Even if both plugins are considered WordPress Security plugins, WP Cerber Security and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • Wp Cerber Security defends WordPress against hacker attacks, spam, trojans, and malware.

Hide My WP Ghost will complement WP Cerber Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, WP Cerber Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

WP Cerber Security

WP Cerber Security mitigates brute-force attacks by limiting the number of login attempts through the login form, XML-RPC / REST API requests, or using auth cookies.

Tracks user and bad actors activity with flexible email, mobile and desktop notifications. tops spammers by using a specialized anti-spam engine. 


User both plugins on your server to boost your security

What Features to activate in Hide My WP Ghost when WP Cerber Security plugin is activated.


FeaturesHMWP Ghost Wp Cerber Security
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
LOGIN SECURITY
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY SCANNER
Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with BBQ Firewall

Even if both plugins are considered WordPress Security plugins, BBQ Firewall and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • BBQ Firewall protects your site against a wide range of threats.

HWMP Ghost will complement BBQ Firewall Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

BBQ Firewall

BBQ checks all incoming traffic and quietly blocks bad requests containing nasty stuff like:

 eval(base64_, and excessively long request-strings. 


User both plugins on your server to boost your security

What Features to activate in Hide My WP Ghost when BBQ Firewall plugin is activated.


FeaturesHMWP GhostBBQ Firewall
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Brute Force Protection
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
Configurable lockout timings
Lockout Message
SQL Injection Attacks Protection
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with Sucuri Security

Even if both plugins are considered WordPress Security plugins, Sucuri Security and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • Sucuri Security defend your website against hacks and DDoS attacks and more.

Hide My WP Ghost will complement Sucuri Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, Sucuri Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Sucuri Security

Sucuri safely remove any malicious code in your website file system and database.

Sucuri website firewall (WAF) blocks attacks by filtering malicious traffic. 


User both plugins on your server to boost your security

What Features to Activate in Hide My WP Ghost when Sucuri Security plugin is activated.


FeaturesHMWP GhostSucuri Security
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Brute Force Protection
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
Configurable lockout timings
Lockout Message
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with Anti-Malware Security

Even if both plugins are considered WordPress Security plugins, Anti-Malware Security and Brute-Force Firewall and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.

Hide My WP Ghost will complement Anti-Malware Security and Brute-Force Firewall Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, Anti-Malware Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Anti-Malware Security and Brute-Force Firewall

Download Definition Updates to protect against new threats. Firewall block SoakSoak and other malware from exploiting Revolution Slider and other plugins with known vulnerabilites. Upgrade vulnerable versions of timthumb scripts.


User both plugins on your server to boost your security

What Features to Activate in Hide My WP Ghost when Anti-Malware Security plugin is activated.


FeaturesHMWP GhostAM Security
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Brute Force Protection
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
Configurable lockout timings
Lockout Message
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with Limit Login Attempts Reloaded

Even if both plugins are considered WordPress Security plugins, Limit Login Attempts Reloaded and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • Limit Login Attempts Reloaded works like a shield against brute force attacks on login page.

HWMP Ghost will complement Limit Login Attempts Reloaded Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Limit Login Attempts Reloaded

Limit Login Attempts Reloaded stops brute-force attacks and optimizes your site performance by limiting the number of login attempts that are possible through the normal login as well as XMLRPC, Woocommerce and custom login pages.


User both plugins on your server to boost your security

What Features to Activate in Hide My WP Ghost when Limit Login Attempts Reloaded plugin is activated.


FeaturesHMWP GhostLoginizer
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Brute Force Protection
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
Configurable lockout timings
Lockout Message
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with Loginizer

Even if both plugins are considered WordPress Security plugins, Loginizer and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents hacker bots access to vulnerable files, plugins and themes.
  • Loginizer works like a shield against brute force attacks on login page .

HWMP Ghost will complement Loginizer Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Loginizer

It helps you fight against brute force attack by blocking login for the IP after it reaches maximum retries allowed.

You can blacklist or whitelist IPs for login using Loginizer. You can use various other features like Two Factor Auth, reCAPTCHA, PasswordLess Login, etc

Loginizer

Use both plugins on your server to boost your security.

What Features to Activate in Hide My WP Ghost when Loginizer plugin is activated.


FeaturesHMWP GhostLoginizer
Change/Hide wp-admin Path
Hide wp-admin For non-admin Users
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
LOGIN SECURITY
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address

Use Hide My WP Ghost with Wordfence Security

Even if both plugins are considered WordPress Security plugins, WordFence and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents access to vulnerable files, plugins and themes.
  • Wordfence works like a firewall to prevent Brute Force attacks, integrity scan, malware scan and more.

Hide My WP Ghost will complement Wordfence Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, Wordfence Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Wordfence Security

Wordfence firewall leverages user identity information in over 85% of the firewall rules, something cloud firewalls don’t have access to. And the firewall doesn’t need to break end-to-end encryption like cloud solutions.


User both plugins on your server to boost your security

What Features to Activate in Hide My WP Ghost when Wordfence plugin is activated.

FeaturesHMWP GhostWordfence
WORDPRESS FIREWALL
Change/Hide wp-admin Path
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change comments Path
Change/Hide Plugins Path
Change Themes Path
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Firewall Against Script Injection
Brute Force Attack Protection
LOGIN SECURITY
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY MONITOR
Cloud Events Log
Weekly Website Security Monitor Report
Checks User Activity on Login & Admin Dashboard
User Events Email Alerts
Notification Email Address

Hide My WP Ghost vs WP Hide & Security Enhancer PRO

HWMP Ghost will complement  WP Hide & SE PRO Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Hide My WP Ghost

Protect your site against hacker bots attacks, such as Script and SQL injection, brute-force, XSS, and more, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

WP Hide & SE PRO

Change the default WordPress login urls from wp-admin and wp-login.php to something totally arbitrary. No one will ever know where to try to guess a login and hack into your site. 


Hide My WP Ghost vs WP Hide features

FeaturesHMWP GhostWP Hide
Levels Of Security (under 5 min setup)
Change/Hide wp-admin Path
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change/Hide comments Path
Change/Hide Plugins Path
Custom Plugins Name
Change Themes Path
Custom Themes Name
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Hide Admin Toolbar Based on User Role
Login & Logout Custom Redirects
Firewall Against Script Injection
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
LOGIN SECURITY
Two-factor authentication (2FA)
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY SCANNER
Weekly Website Security Monitor Report
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log Report
Security Email Alerts
Notification Email Address
SECURITY SUPPORT
Default WordPress Permalinks ?p=ID
ManageWP.com Integration
Cache Plugins Full Integration
Change Paths in Cache Directory
WordPress Multisite

Note! We included the features presented by WP Hide plugin on WordPress directory and the features found when we tested the plugin.


Use Hide My WP Ghost with Shield Security

Even if both plugins are considered WordPress Security plugins, Shield Security and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents access to vulnerable files, plugins and themes.
  • Shield Security works like a firewall against hackers and malicious bots, of all types and more.

HWMP Ghost will complement Shield Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, Shield Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Shield Security

It gives you a toolkit with everything you need to expertly secure your site, without being a security expert.

Instead, Shield does most of the heavy lifting for you, so you can get back to focusing on the work you love to do.

Shield Dashboard

User both plugins on your server to boost your security

What Features to Activate in Hide My WP Ghost when Shield Security plugin is activated.

FeaturesHMWP GhostShield Security
WORDPRESS FIREWALL
Change/Hide wp-admin Path
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change comments Path
Change/Hide Plugins Path
Change Themes Path
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Firewall Against Script Injection & Security Headers partially
LOGIN SECURITY
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard partially
Cloud Events Log
Weekly Website Security Monitor Report
User Events Email Alerts
Notification Email Address

Use Hide My WP Ghost with Solid Security

Even if both plugins are considered WordPress Security plugins, Solid Security and Hide My WP Ghost work together to add security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Advantages:

  • Both plugins have complementary features that will boost your website security.
  • Both plugins load fast and work with SEO and Cache plugins.
  • Both plugins work on all server types (Apache, Nginx, IIS, LiteSpeed, etc).
  • Hide My WP Ghost works as security through obscurity and prevents access to vulnerable files, plugins and themes.
  • Solid Security works like a firewall to block bad bots, add login security , monitor site security and more.

HWMP Ghost will complement Solid Security Plugin by offering an extra layer of protection that the other doesn’t offer:

  • With Hide My WP Ghost you prevent attacks from happening, by hiding vulnerabilities in themes, WP core and plugins.
  • Hackers and hacker bots can’t attack what they can’t find.
  • It does a bit more, as you will see on the Features list.
  • This offers an extra layer of protection that you don’t get from other plugins, because those focus on helping you while you are attacked and after you were attacked, by cleaning files, detecting malware, injections etc.
  • With Hide My WP Ghost you can avoid getting injections in the first place.

Even if both plugins are considered WordPress Security plugins, Solid Security and Hide My WP Ghost work together to add TWO DIFFERENT KINDS of security layers on your websites by stopping the hackers’ attacks and preventing data loss.


Hide My WP Ghost:

Protect your WordPress site against hacker bots and spammers.

Protect your site against common attacks, such as script and SQL injection and brute-force, by camouflaging those vulnerabilities without physically changing any file or directory.

Hide My WP Ghost

Solid Security

The Solid Security setup and onboarding experience is designed to allow anyone to secure their WordPress website in under 10 minutes, without needing a degree in cybersecurity.


User both plugins on your server to boost your security

See what features to activate on Hide My WP Ghost when using with Solid Security

FeaturesHMWP GhostSolid Security
WORDPRESS FIREWALL
Change/Hide wp-admin Path
Change/Hide wp-login Path
Change Author Path
Change Lost Password Path
Change Register Path
Change Logout Path
Change Activation Path
Change Paths in Ajax Calls
Change/Hide wp-content Path
Change/Hide wp-includes Path
Change/Hide uploads Path
Change comments Path
Change/Hide Plugins Path
Change Themes Path
Change/Hide Rest API Path
Hide RSD Endpoint
Disable Pinback & XML-RPC access
Hide WordPress Common Paths After They are Changed
Hide WordPress Common Files
Security Headers
Disable Right-Click , Copy-Paste, Inspect Element
URL Mapping
Class Name Mapping
CDN URL Mapping
Firewall Against Script Injection
Brute Force Attack Protection
LOGIN SECURITY
Google reCaptcha V2
Google reCaptcha V3
Ban IP addresses
Whitelist IP addresses
Blocked IPs Report
Limit Login Fail Attempts
WORDPRESS SECURITY MONITOR
Checks User Activity on Login & Admin Dashboard
Cloud Events Log
Weekly Website Security Monitor Report
User Events Email Alerts
Notification Email Address

Activate a New Website With Hide My WP Ghost

Depending on the purchased license and the limit of websites, you can connect websites to your account by installing the plugin on your websites.

To connect a new website to your account https://account.hidemywpghost.com/user/auth/connected follow these steps:

  1. Download the plugin from Orders / Licenses and copy the Activation Token
  2. Install the plugin on your WordPress site
  3. Use the Activation Token to activate the plugin and connect the website to your account

Your website will automatically appear at the Connected Website on your account https://account.hidemywpghost.com/user/auth/connected.


Delete Connected Website

Use this option if you want to remove the license from a website from your account or want to move the license to a different website.

Click to delete the connected website and the license will automatically remove from that website.

Note! The custom paths will change to WordPress defaults paths on the deleted websites. You will need to reactivate the Hide My WP Ghost plugin on the deleted website.

Now you can connect a different website using the activation steps from above.

How to change database prefix in WordPress

Almost everything that you do in WordPress is stored in databases. Your new plugins will use a database as well as the core WordPress system. Since databases contain all your information, you must do everything you can to make it more secure.

Because more often than not, hackers use bots to search for security flaws in your website, it is not a good idea to have a default database name and prefix for your WP database.

If you had installed WordPress by yourself, you will remember that you had to input database information like the name of your new database, username, and a database prefix. The Standard WordPress prefix for databases is wp_ and that is the one you want to change.

Solid Security Tool (previous iThemes Security)

To apply a new prefix, you just need to verify that the wp-config.php is writable and that the Alter rights of the database are enable.

A single entry is needed: the new database prefix. The plugin will generate a new one for you. You only have to press the button if you are okay with the generated prefix. Of course, the prefix will be added randomly.

  1. Go to the WordPress dashboard.
  2. Go to the ‘plugins’ tab and click on ‘add new.’
  3. Search Solid Security in WordPress plugin repository.
  4. Click the Install button to install Solid Security on your site.
  5. Click the Activate button to activate this plugin.

https://wordpress.org/plugins/better-wp-security/

Now, go to Dashboard > Security and after you do the onboarding, go to Security > Tools and Run a database prefix change and you’re done.

More Details: Solid Security Change Database Prefix – Solid Help Center

Use Hide My WP Ghost with WP-Rocket

Even if WP-Rocket doesn’t have a free version of the cache plugin, we tell you that it worth buying it as it’s probably the best cache plugin on the market.

  1. The WP-Rocket has all the features you need to optimize the WordPress site speed to 100%.
  2. WP-Rocket is focused on the website speed loading and not on security. It works great with the Hide My WP Ghost plugin.
  3. WP-Rocket has the option to Combine all CSS and JS files and also the inline styles.

With a bit of setup, WP Rocket + Hide My WP Ghost will help you secure your website & hide the plugins and themes from Themes Detectors.

To hide all CSS and JSS you need to follow the steps to Combine the JS and CSS files into one file. Let’s see how you can do this with the WP-Rocket plugin.

WP-Rocket > File Optimization > Combine JS Files

The plugin comes with the option to Minify & Combine the JS Files into one file. As we tested the plugin this is working really well with Change Paths in Cache Files option in Hide My WP Ghost.

Combine JS Files

The Combine JavaScript Files option will combine all of your JavaScript files into a single file.

Combine CSS and JS files will still result in a speed bump for certain types of WordPress sites, so we recommend testing your page speed with this option enabled and disabled.

Note! To hide the plugins’ JS URLs, make sure you activate the option “Combine JS-files” in WP-Rocket > File Optimization and let Hide My WP Ghost change the paths in the cached file.

WP-Rocket > File Optimization > Combine CSS Files

The plugin also comes with the option to Minify/Combine the CSS Files into one file.

Combine CSS Files

WP-Rocket “Combine CSS files” option will combine all of your CSS files into a single file.

Note! To hide all the plugins’ css files you need to activate the option “Combine CSS files” in WP-Rocket and let Hide My WP Ghost change the paths in the cached file.

Hide WP-Rocket cache path

Now that all the CSS and JS are combined, these files are present in the cache directory.

By default, the cache path is /cache/min/ but the URLs inside the cache are /cache/min/1/wp-content/ & /cache/min/1/wp-includes/ where 1 is the site ID.

Hide My WP Ghost will map and hide the WP-Rocket cache URL in Hide My WP > Mapping > URL Mapping:

Read more about URL Mapping here: https://hidemywpghost.com/kb/url-mapping-text-mapping/#url_mapping

Change Paths in Cache Files

To activate Hide My WP Ghost to change the paths in the cache file, go to Hide My WP > Tweaks > Change Paths in Cache Files and the plugin will automatically change the paths in background using WP Cron.

https://hidemywpghost.com/kb/activate-security-tweaks/#change_paths_cached_files

Note! If WordPress cron is deactivated on your website, you can manually click to change the paths once the files are cached.

Setup Hide My WP on Flywheel Server

As Flywheel stands apart from most other managed WordPress hosting companies by offering a number of features for both web designers and developers, more and more companies are moving to Flywheel server.

Flywheel is a Nginx based hosting and it will require some extra setup after you install Hide My WP Ghost plugin on your server.

Please follow this tutorial step by step to set up the Hide My WP Ghost for Flywheel server:

  1. In your WordPress dashboard, go to Hide My WP > Change Paths
  2. Select the Safe Mode or Ghost Mode,  scroll down and customize the paths as you like
  1. Click the Save button to save the changes.
  2. You will see a message to include the redirects in the Flywheel Redirect tool.

Note! Do not logout until you set all the redirects and they were activated by the Flywheel server.

5. Clear the Flywheel Cache to load the new paths from your website. If you have other cache plugins installed on your website, you need to clear the cache on those plugins too.

6. After the redirects are added in the Flywheel Redirect tool, click the “Frontend Login Test” and see if the login page is loading correctly. You can also check the website with a different browser or from incognito mode.

7. If everything loads fine in Frontend, click the button “Yes, it’s working” button. Otherwise click on “No, abort” to roll back to previous settings.

Enjoy Hide My WP Ghost and stay safe!

Use Autoptimize with Hide My WP Ghost

If you’re looking to improve the speed and security of your WordPress website, you may have considered using the Hide My WP Ghost and Autoptimize cache plugin. And the good news is that these two plugins are not only compatible but using them together can significantly improve your website’s performance.

Autoptimize is an optimization plugin that can help you reduce the size of your website’s CSS, JS, and HTML files. By aggregating and minifying these files, Autoptimize can speed up your website’s load times, making it a popular choice for WordPress users.

But what about security? While Autoptimize is an excellent optimization plugin, it doesn’t offer any security features. That’s where Hide My WP Ghost comes in. This powerful plugin allows you to hide your WordPress themes and plugins from Theme Detectors, making it harder for hackers to identify vulnerabilities on your website.

By using Hide My WP Ghost and Autoptimize together, you can significantly improve your website’s speed and security.

Let’s take a closer look at how these two plugins work together to optimize your website.


Combining CSS and JS files

One of the key features of Autoptimize is the ability to combine CSS and JS files into a single file. This can significantly reduce the number of HTTP requests your website needs to make, which can improve load times.

To enable this feature in Autoptimize, go to the “Optimize” tab and check the “Optimize CSS Code” and “Optimize JavaScript Code” options. Then, check the “Aggregate inline CSS” and “Aggregate inline JavaScript” options to combine inline code with the rest of your website’s files.

Note that enabling these options may increase the size of your Autoptimize cache, so it’s best to test your website’s performance with and without these features enabled.


Hiding your WordPress plugins and themes

By default, WordPress websites reveal information about the plugins and themes they use. This can make it easier for hackers to identify vulnerabilities and attack your website. Hide My WP Ghost can help you hide this information, making it harder for hackers to target your site.

To enable this feature in Hide My WP Ghost, go to the “Settings” tab and check the “Hide WordPress” option. This will change the paths of your WordPress files, making it harder for hackers to identify the plugins and themes you’re using.

Changing the cache path

By default, Autoptimize stores cached files in the /core/cache/autoptimize/ directory. This can reveal that you’re using the plugin, which could make your website a target for attacks.

To change the cache path, you can use the “Cache Path” option in the Autoptimize settings. Simply enter a custom directory name to hide the fact that you’re using the plugin.

Using Hide My WP Ghost, you can also change the paths of cached files. This can help to further hide the fact that you’re using Autoptimize.

To enable this feature in Hide My WP Ghost, go to the “Tweaks” tab and check the “Change Paths in Cache Files” option. This will automatically change the paths of cached files, making it harder for hackers to identify the files you’re using.

Conclusion

Using Hide My WP Ghost and Autoptimize together can significantly improve the speed and security of your WordPress website. By combining CSS and JS files, you can reduce load times and improve performance. And by hiding information about your WordPress plugins and themes, you can make it harder for hackers to identify vulnerabilities on your site.

By changing the cache path of Autoptimize and using Hide My WP Ghost to change the paths of cached files, you can further improve the security

Note! If WordPress cron is deactivated on your website, you can manually click to change the paths once the files are cached.

Setup Hide My WP on Amazon AWS Lightsail

Apache version on AWS Lightsail WordPress

Step1: Install, Setup Hide My WP Ghost Plugin and click the Save button with the new paths.

Step2: Copy the rewrite rules from Hide My WP Ghost into Bitnamy config file

AWS Lightsail (Bitnami) doesn’t enable overrides using .htaccess by default and the structure of the Apache config files is a bit different.

Bitnami uses “htaccess.conf” files by default instead of “.htaccess” files for security and performance reasons. You can find more info at https://docs.bitnami.com/general/apps/redmine/administration/use-htaccess/

(more…)

Use Hide My WP with Really Simple SSL

In this article will show you how to make Hide My WP Ghost compatible with the well known Really Simple SSL plugin.

First I want to congratulate the authors of the Really Simple SSL plugin who created such a simple and efficient plugin.

Now, Hide My WP Ghost works well with most of the Really Simple SSL options.

The only option that needs a bit of attention,if the 301 redirect with .htaccess which adds the rewrite rules in the .htaccess file after the Hide My WP Ghost rules.

To make sure the plugins are working together well after you save the options in Really Simple SSL plugin, save the settings in Hide My WP Ghost too. This way the rules are moved to the beginning or the .htaccess file.

# BEGIN rlrssslReallySimpleSSL
RewriteEngine on 
RewriteCond %{HTTPS} !=on [NC] 
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]
# END rlrssslReallySimpleSSL

Note! If the .htaccess file is not writable, make sure you manually move the Really Simple SSL rewrite rules to the beginning of the .htaccess file and save the file.

That’s all. Enjoy the plugins and stay safe!

Please contact us if you have any question.

Use Hide My WP Ghost with Manage WP

We are glad to announce that Hide My WP Ghost is now working with the Manage WP Godaddy plugin.

This is great news for developers who have many websites to manage and want to secure them with a custom wp-admin path.

How to configure Hide My WP Ghost

  1. Install the free Hide My WP Ghost plugin from https://wordpress.org/plugins/hide-my-wp/ (or the premium one)
  2. Activate the plugin and secure the WordPress paths.

How to configure Manage WP

  1. You can access your account or create a new one at https://managewp.com/
  2. Install the free Manage Worker plugin on your website https://wordpress.org/plugins/worker/
  3. Connect your website using the API key from the plugin description in the Plugins tab

Once you connected your plugin, Hide My WP Ghost will know how to handle the compatibility and you will be able to connect to your admin area directly from the Manage WP panel.

Let us know if you have any question.

Hide My WP Advanced Text Mapping

Hide My WP Ghost 5.0.12 brings new ways customize or hide the classes from your source code.

Hide Class Name

If you want to completely hide a class use the {blank} pattern to accomplish that.

Random Class Name

If you want to set a random id for a specific class, use the {rand} pattern to accomplish that.

The most common classes used by WordPress and can be detected by theme detectors are those who contain the prefix wp-. Check the website source code and see if you find classes with wp- and add them in the Text Mapping.

Check the frontent every time

Check the frontent to make sure that the class you’re mapping it’s not used by the WordPress Theme.

Demo Text Mapping in Hide My WP Ghost

Here is a list of classes we usually add in Text Mapping for our WordPress websites:

Read Also: Do I Need to Hide WordPress From Detectors or Hackers?

Use Hide My WP in Dashboard

Once you installed Hide My WP Ghost plugin on your website, the plugin will add by default a widget in the WordPress Dashboard with the security status for every single day.

Hide My WP Ghost Widget in Dashboard

In this widget, the plugin verifies the critical tasks from Security Check like Brute Force on login path, Script Insertion, SQL Insertion, XML-RPC Vulnerability, SSL security, HTML Headers and more.

You will get a level of security based on how many vulnerabilities were found and you can check the full report with a simple click.

Activate/Deactivate Hide My WP in Dashboard

To activate/deactivate the widget, simply go to Screen Options and check/uncheck the Hide My WP box.

Activate Hide My WP Ghost in Dashboard

Hide My WP widget on WP Multisite

To see the Hide My WP widget on WP Multisite, go to one of the sub-sites’ Dashboard. The widget will not load while connected on the network dashboard.

Setup Hide My WP on Windows IIS server

Please follow this tutorial step by step to set up the Hide My WP Ghost for IIS server:

  1. In your WordPress dashboard, go to Hide My WP > Change Paths
  2. Select the Safe Mode or Ghost Mode,  scroll down and customize the paths as you like
  1. Click the Save button to save the changes.
  2. You will see a message to include the rewrite rules into web.config file located in the root directory of your website.

This is how the web.config file should look like before you add the rules:

This is how the web.config file should look like after you add the rules:

5. After you add the lines in your config file, save it and go back to your Hide My Wp Ghost settings and press the “Okay, I set it up” button.

6. Note: You need to reload the IIS server to apply the changes.

7. Check the Frontend Login page and make sure the paths are correct. If everything loads fine, click “Yes, it’s working” button. Otherwise click on “No, abort” to roll back to previous settings.

Theme Not Loading Correctly & Website Loads Slower

After you install Hide My WP Ghost plugin and select Safe Mode or Ghost Mode, make sure you follow the instruction based on your server type after you save the settings.

Now, if you followed all the notifications from Hide My WP settings, there are some situations when the website loads slower in frontend or the theme is now showing correctly:

Attention! Please check the rewrite rules in the config file. Some URLs passed through the config file rules and are loaded through WordPress which may slow down your website or not load correctly.


On Apache & Litespeed servers

1. All the rewrite rules are loaded through .htaccess file which works instantly for Apache and Litespeed servers. If the rewrites are not loaded through .htaccess, they are handled by WordPress redirects and as they use more resources, they will load slower.

To make sure the rules are loaded through .htaccess you need to first check the .htaccess file and you should see the rules starting with #BEGIN HMWP_RULES and ending with #END HMWP_RULES like in this example:

# BEGIN HMWP_RULES
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^([_0-9a-zA-Z-]+/)?ajax$ /wp-admin/admin-ajax.php [QSA,L]
RewriteRule ^([_0-9a-zA-Z-]+/)?custom-admin/(.*) /wp-admin/$2 [QSA,L]
..........
</IfModule>
# END HMWP_RULES

Also, make sure to activate AllowOverride All for your directory. See how to do this:

For Cyberpanel with LiteSpeed you need to specify the .htaccess path where you have the rewrites:


If Hide My WP Ghost detects the rewrites are handled by WordPress and not by the config file you will get a notification in the Hide My WP settings after you check your website as a visitor:

Solution: After the settings are saved, change the .htaccess to read-only or to 0440 if you have Linux. This way the rules will not be removed by other plugins.

2. If you activate the Text Mapping in CSS and JS option, all the CSS and JS URLs will load dynamically as this is the only option to change the text in these files. Even with a cache plugin, you may experience a slower website as the CSS and JS are not cached on the first call.

https://hidemywpghost.com/kb/url-mapping-text-mapping/#text_mapping

If you want to use this option, use a cache plugin like Autoptimize or WP Rocket and Combine all the CSS and JS files into one. Set the cache to be deleted once a week or even once a month.

We encourage you to switch off the option Text Mapping in CSS and JS files including caches as it’s not improving the security but only hides classes and ids from theme detectors.


On Nginx servers

1. All the rewrite rules are loaded through nginx.conf file which works instantly for Nginx servers. If the rewrites are not loaded through nginx.conf file, they are handled by WordPress redirects and as they use more resources, they will load slower.

Make sure the rules are loaded through nginx.conf and you restarted Nginx server after you changed the paths.

Check if you have the line include path_to_file/hidemywp.conf in nginx.conf file as detailed in these examples:

If Hide My WP Ghost detects the rewrites are handled by WordPress and not by the config file you will get a notification in the Hide My WP settings after you check your website as a visitor:


On Windows IIS servers

1. All the rewrite rules are loaded through web.config file which works instantly for IIS servers with URL Rewrites 2 tool installed. If the rewrites are not loaded through web.config file, they are handled by WordPress redirects and as they use more resources, they will load slower.

Make sure you added the rules in web.config and restarted IIS server after you changed the paths.

https://hidemywpghost.com/kb/setup-hide-my-wp-on-windows-iis-server/

If Hide My WP Ghost detects the rewrites are handled by WordPress and not by the config file you will get a notification in the Hide My WP settings after you check your website as a visitor:


Other servers

For servers like Amazon Bitnami, Inmotion, WPEngine, Godaddy, Google Cloud, Flyweel, Kinsta, WPMUDEV, RunCloud, etc. please make sure you followed the instruction from Hide My WP Ghost after you saved the settings:

Amazon Bitnami Server: https://hidemywpghost.com/how-to-set-hide-my-wp-for-bitnami-servers/

WP Engine Server: https://hidemywpghost.com/hide-my-wp-pro-compatible-with-wp-engine/

Inmotion Server: https://hidemywpghost.com/hide-my-wp-pro-compatible-with-inmotion-wordpress-hosting/

Google Cloud: https://hidemywpghost.com/how-to-enable-allowoverwrite-on-google-cloud-platform/

Godaddy Server: https://hidemywpghost.com/how-to-use-hide-my-wp-with-godaddy/

AWS Lightsail Server: https://hidemywpghost.com/how-to-setup-hide-my-wp-on-amazon-aws-lightsail/

Flyweel Server: https://hidemywpghost.com/how-to-setup-hide-my-wp-on-flywheel-server/

Kinsta Server: https://hidemywpghost.com/kinsta-server-hide-my-wp-ghost-setup/

WPMUDEV Server: https://hidemywpghost.com/wpmudev-server-hide-my-wp-ghost-setup/

RunCloud Server: https://hidemywpghost.com/setup-hide-my-wp-on-runcloud/

Ploi Server: https://hidemywpghost.com/setup-hide-my-wp-on-ploi-io/

Set AllowOverride all on Apache Servers

Ubuntu Server

In case you are on Ubuntu, edit the file /etc/apache2/apache2.conf (here we have an example of /var/www):

<Directory /var/www/>
        Options Indexes FollowSymLinks
        AllowOverride None
        Require all granted
</Directory>

and change it to;

<Directory /var/www/>
        Options Indexes FollowSymLinks
        AllowOverride All
        Require all granted
</Directory>

then,

sudo service apache2 restart

You may need to also do sudo a2enmod rewrite to enable module rewrite.

Centos 7,8 Server

If you have Centos server, edit the file /etc/httpd/conf/httpd.conf

And depending on what directory level you want to relax access to, you have to change the directive

AllowOverride None

to

AllowOverride All

So, assuming you want to allow access to files on the /var/www/html directory, you should change the following lines from:

<Directory "/var/www/html">
 AllowOverride None
</Directory>

to

<Directory "/var/www/html">
 AllowOverride All
</Directory>

You may need to also do sudo httpd rewrite to restart the Apache.

How to check if .htaccess is loading:
Make sure .htaccess is working with Allowoverride All – Hide My WP Ghost

You can find more situations here: https://stackoverflow.com/questions/18740419/how-to-set-allowoverride-all

Use Hide My WP with WP Hide & Security Enhancer

Over 90,000 hacking attacks per minute strike WordPress sites and WordPress hosting around the world, hitting not only large corporate websites packed with sensitive data but also sites belonging to small businesses, independent entrepreneurs, and individuals running personal blogs.

In such an environment, ensuring the security of your WordPress site is crucial.

However, it is not necessary to install all the security plugins available online. Instead, selecting the right combination of plugins can provide comprehensive protection without redundancy.

Two notable plugins in the WordPress security landscape are Hide My WP Ghost and WP Hide & Security Enhancer.


WP Hide & Security Enhancer

WP Hide & Security Enhancer is designed to hide your WordPress core files, login page, theme, and plugin paths from being visible on the front end. This plugin offers a significant improvement in site security by making it difficult for attackers to identify that your site is running on WordPress.

Key features of WP Hide & Security Enhancer

  • Hiding WordPress Core Files: This feature conceals the core WordPress files, making it harder for attackers to target known vulnerabilities.
  • Hiding Login Page: By changing the login URL, this plugin prevents attackers from accessing the standard WordPress login page, reducing the risk of brute-force attacks.
  • Hiding Theme and Plugin Paths: Concealing theme and plugin paths helps prevent attackers from exploiting known vulnerabilities in specific themes and plugins.
  • HTML Cleanup: WP Hide & Security Enhancer can remove WordPress fingerprints from the HTML code, further obscuring the fact that the site is powered by WordPress.

While WP Hide & Security Enhancer provides robust security through obscurity, Hide My WP Ghost takes this approach to the next level with additional features and functionalities that enhance the overall security of your WordPress site.


Hide My WP Ghost

Hide My WP Ghost is more than just a security through obscurity solution; it is a comprehensive security plugin designed to protect your WordPress site from a wide range of threats.

In addition to hiding WordPress common paths, themes, and plugin names, Hide My WP Ghost offers several advanced features that make it a superior choice for WordPress security.

Key Features of Hide My WP Ghost

  • Security Through Obscurity: Hide My WP Ghost hides all WordPress common paths, making it difficult for attackers to identify and exploit vulnerabilities. However, Hide My WP Ghost does not physically change the paths to avoid compatibility issues and massive problems.
  • Two-Factor Authentication (2FA): This feature adds an extra layer of security by requiring users to verify their identity using a second form of authentication, such as a code sent to their mobile device. This significantly reduces the risk of unauthorized access.
  • Temporary Login: Hide My WP Ghost allows you to create temporary login URLs that can be used to grant access to specific users for a limited time. This is particularly useful for granting temporary access to developers or support staff without compromising your primary login credentials.
  • 8G Firewall: The 8G Firewall is a powerful firewall solution that blocks malicious requests and prevents common hacking attempts, such as SQL injections and cross-site scripting (XSS) attacks.
  • Country Blocking: With this feature, you can block traffic from specific countries, reducing the risk of attacks from regions known for high levels of cybercrime. This is particularly useful for sites that do not serve an international audience.
  • Header Security: Hide My WP Ghost enhances your site’s security by adding HTTP security headers, which help protect against a variety of attacks, including clickjacking, MIME-type sniffing, and cross-site scripting.
  • Compatibility with Other Security Plugins: Hide My WP Ghost is designed to work seamlessly with other popular security plugins, such as iThemes Security, Sucuri, and Wordfence. This allows you to use Hide My WP Ghost as a complementary solution to enhance your site’s security without conflicts.

Using Hide My WP Ghost and WP Hide Together

While Hide My WP Ghost and WP Hide & Security Enhancer have some common features, they can be used together to provide an even stronger security solution for your WordPress site.

By combining the strengths of both plugins, you can achieve a higher level of security through obscurity and benefit from the advanced features offered by Hide My WP Ghost.


How to Use Both Plugins Together

  1. Install and Configure WP Hide & Security Enhancer: Start by installing and configuring WP Hide & Security Enhancer to hide your WordPress core files, login page, and theme/plugin paths. This will provide a strong foundation of security through obscurity.
  2. Install and Configure Hide My WP Ghost: Next, install Hide My WP Ghost and configure its advanced security features, such as 2FA, temporary login, the 8G firewall, country blocking, and header security. Ensure that the settings do not conflict with WP Hide & Security Enhancer to avoid compatibility issues.
  3. Test Your Site: After configuring both plugins, thoroughly test your site to ensure that everything is working correctly. Check for any conflicts or issues and adjust the settings as needed to ensure optimal performance and security.
  4. Monitor and Maintain: Regularly monitor your site for security issues and keep both plugins up to date. Staying vigilant and proactive is key to maintaining a secure WordPress site.

Testing our demo website:

https://demo.wpplugins.tips/
https://demo.wpplugins.tips/wp-admin
https://demo.wpplugins.tips/wp-login
https://demo.wpplugins.tips/wp-content
https://demo.wpplugins.tips/wp-content/plugins
https://demo.wpplugins.tips/wp-content/themes

Use Hide My WP Ghost with Zapier

Update! Since Hide My WP Ghost 5 we added the IP filter in XML-RPC to let apps like Zapier and Aliexpress to access the website xml-rpx.php and block the hackers.

Everybody knows that Zapier is a great tool when you need to create automated tasks on your WordPress site or to trigger an action when you create new posts or pages

We recently tested Zapier to create new posts in WordPress while Hide My WP Ghost plugin is activated.

We noticed that Zapier needs the xml-rpc.php file access to work properly and we switched off the option Hide My WP > Change Paths > API Security > Disable XML-RPC access. With this option off we were able to create and promote our posts on Social Media.

Having this option OFF it’s not safe for your website. Many brute force attacks are made through this URL. Sometimes you need to make compromises in order to prevent functionality issues.

Setup Hide My WP Ghost with Advanced Access Manager

The Advanced Access Manager is a great plugin which lets you customize the users rights when it comes to access the backend of your website.

It’s also a good security plugin which protects your personal information when you want to limit the access to developers who sometimes have to work on your live website.

We tested Hide My WP Ghost together with AAM plugin and we noticed that with small adjustments, the two plugins are working beautifully together.

(more…)