Yearly
Lifetime
If you purchase a yearly plan, you get access to all security updates, features, and fast replies to support requests for 1 year.
You can cancel the yearly plan anytime without affecting your website security.
After the subscription expires, you can still use the plugin without future support and compatibility updates.
You can use the free version of the plugin on any number of websites, whether or not they are owned by you.
The Ghost version can be installed on a limited number of websites, and you can transfer your license if you change your website.
This license is limited to the number of websites you use it on.
This means that you have to activate the product with a license for each website you want to use a product on.
For WordPress Multisite, the license is for the entire network.
Of course! Just deactivate the plugin from the previous domain, and activate it on the new one.
You can manage it in your account via Manage License.
We offer a full refund for the first 30 days after purchase, based on our Refund Policy.
The Hide My WP Ghost Lite version offers the basic security options for your website, while the plugin offers you a powerful security level to prevent most of the WordPress attacks made by both humans and bots. More details
You can use PayPal or any credit card to buy the plugin.
We use the Paddle gateway, which supports over 45 payment methods
You can save all the settings from the Free version and restore them after you activate the premium version.
For NGINX servers, you will need to do manual setup through SSH or SFTP to add the rewrite file into nginx.conf and reload the service.
Read the NGINX step-by-step tutorial here:
https://hidemywpghost.com/how-to-setup-hide-my-wp-on-nginx-server/
Note! Contact your host first and ask him if he can help you with it.
The plugin works on almost any WordPress server, but there are a few servers you can’t use Hide My WP Ghost with:
1. WordPress.com Business – doesn’t support a different login path and uses a shared NGINX hosting without the possibility to configure the rewrite rules.
2. Shared NGINX Hosting who doesn’t have the SSH option and refuses to add the Hide My WordPress Ghost config file and reload the NGINX settings.
Yes, you do!
Access the Knowledge Base for more answers or contact us.

6 Apr 2026
Compatible WP 7.0.x & PHP 8.5

Youtube Channel

Tutorials & FAQs
There are more and more plugins available that can hide common paths. To ensure the best results, you should consider using the fastest option available.
A slow website can put your website’s SEO and security at risk. For this reason, it is best to use Hide My WP Ghost for increased protection without compromising on speed.
= 9.0.03 (06 April 2026) = * Fix - Fixed an issue where the Dark Mode popup remained white and some settings fields were too dark * Fix - Fixed Login Page Design to work in Disable mode * Fix - Fixed Firewall whitelist IPs and paths to work in disabled mode when the Firewall is activated * Fix - Fixed minor bugs and typos = 9.0.01 (30 March 2026) = * New - Country filter in Security Threats Log and User Events Log * New - Click on a country circle in the GeoMap to open Security Threats Log filtered by that country for the last 7 days * Update - Moved Export CSV button to below the table in Security Threats Log and User Events Log to avoid accidental clicks * Update - Added proper color handling for dark mode (browser-based) * Update - Enhanced security progress indicator and introduced Security Optimization Score * Update - Add a loading process on login submit * Fix - GeoMap country circle counts now match Security Threats Log counts for the same 7-day window * Fix - Security Threats counting for the last 7 days on widget now matches the log totals (timezone-aligned day buckets) * Fix - Passkey login spinner not showing due to missing classList calls * Fix - Country codes missing from threats log rows now resolved on-the-fly from GeoIP when cron is not running * Fix - Resolved robots.txt warning when user agents are blocked = 9.0.00 (26 March 2026) = * New - Customize the login page with custom logo (with live preview), logo link URL, and color scheme (page, form, button, text, link colors) with one-click presets * New - Block AI Crawler Bots at firewall level with automatic robots.txt Disallow rules (GPTBot, ClaudeBot, PerplexityBot, Bytespider, and 30+ others) * New - GEO Map with top 5 threat countries visualization on the Overview dashboard * New - Export Security Threats Log and User Events Log to CSV * New - Security Check task to verify IP block automation is configured correctly * New - Threats count in the Overview widget now shows the full 7-day period totals * New - Notification in the Overview widget to activate 7G/8G Firewall when unblocked threats are detected * Update - Store country code in the threats log table for faster country stats * Update - Missing country codes resolved in background via cron without slowing down threat logging = 8.3.07 (16 March 2026) = * Fix - Sorting and filtering in the Events Log & Security Threats Log * Fix - Rules and Threats filters to work with WP Multisite subpaths structure * Fix - Temporary login user edit link on WP Multisite * Fix - Compatibility with Woocommerce 10.6 * Fix - Compatiibility with the Blocksy theme * Fix - Optimize the plugin speed = 8.3.06 (09 March 2026) = * Update - JS requirements for WordPress 6.9.2 * Fix - Security Log and Events Log not recording properly * Fix - Optimize user logged in verification * Fix - Don't show the 2FA and Magic Login form when the Safe URL parameter is set * Fix - Prevent logging out when the paths are changed * Fix - Sending the code too often on 2FA Email verification. The code can be resent only every 30 seconds. * Fix - Remove unused JS, CSS and fonts * Fix - Compatiibility with the Blocksy theme * Fix - Compatiibility with the new WP 6.9.4 = 8.3.04 (02 March 2026) = * Update - Remove the option to send the new paths by email as the are already on WP Ghost dDashboard * Update - Send the Brute Force, 2FA and Magic Login texts to the multilingual plugins like WPML and Polylang * Update - Add the Magic Login options to Change Paths > Login Security section * Update - Compatibility with PHP 8.5 * Fix - Small bugs and typos = 8.3.03 (25 Feb 2026) = * New - Added Automation on IP address blocking in the Firewall * Update - Added compatibility with Photo Gallery from 10Web * Update - Translations in all 14 languages * Update - Moved 2FA and Magic Login feature in WP Ghost core * Update - UI for Security Threats Log and Events Log * Update - Plugin core security acording to the latest WordPress security recommendations * Fix - Firewall rules to work with the new WordPress 6.9.2 update = 8.3.01 (10 Feb 2026) = * Update - Add the option to hide AI Bots in the Firewall > Block User Agents * Fix - Fatal error on log table creation when the plugin is activated * Fix - Safe URL parameter on login form to prevent 2FA from showing when is activated = 8.3.00 (07 Feb 2026) = * New – Security Threats Log added to track blocked attacks and malicious requests * Change – Events Log renamed to Logs, now split into User Events and Security Threats * Update – Expanded 7G / 8G Firewall rules to block advanced brute-force attempts, SQL injection, XSS payloads, file inclusion, directory traversal, and automated vulnerability scans before reaching WordPress * Update – Improved threat detection to stop malicious requests before WordPress core execution * Update – Added advanced request pattern analysis to identify and block malicious payloads * Update – Enhanced threat classification to clearly separate blocked attacks from allowed traffic in security logs * Update – Optimized firewall execution path to reduce overhead and improve performance under high attack traffic = 8.2.18 (02 Jan 2026) = * Update - Added the option to Hide Source Map References * Fix - Brute Force compatibility with Elementor Pro on form submit * Fix - Update Google reCaptcha JavaScript to work with Woocommerce Ajax = 8.2.17 (09 Dec 2025) = * Fix - Remove the wp- and admin path from prefetch paths in WP 6.9 * Fix - Small bugs and warnings = 8.2.16 (01 Dec 2025) = * Update - Compatibility with WP 6.9 * Update - 2FA to allow each user to select the 2FA method in the profile * Update - 2FA to connect through passkey and fingerprint * Update - 2FA to trust the current browser = 8.2.15 (29 Sept 2025) = * Update - Compatibility with the plugin WP Social & WP Social PRO * Update - Compatibility with LiteSpeed Quic Cloud on IPV6 * Update - Make REST API test work when permalinks are set to the default PHP parameter * Update - Minimum PHP version required is 8.0 in the Security Check section = 8.2.14 (22 Aug 2025) = * Update - Firewall rules for more compatibility * Update - Safe URL verification process * Update - Compatibility with the plugin Debloat * Update - Compatibility with WP Social login customization = 8.2.13 (08 July 2025) = * Update – Compatibility with Riode theme on Brute Force protection * Update – Compatibility with WP Engine and added support for Bulk Rewrite Rules * Fix – Plugin update check error message = 8.2.12 (19 June 2025) = * Update – 7G & 8G Firewall for more compatibility with WP Plugin * Update – Compatibility with Kadence Blocks = 8.2.11 (27 May 2025) = * Update – Compatibility with the WP 6.8 * Update – Firewall compatibility with WooCommerce * Update – Add AI support in the plugin settings * Fixed – Function _load_textdomain_just_in_time was called incorrectly * Fixed – Compatibility WooCommerce login/register with reCaptcha V3 = 8.2.10 (11 Apr 2025) = * Update – Compatibility with WordPress version 6.8 * Fix – File security when the rewrite rules are not loaded correctly * Fix – Prevent Brute Force from updating the warning text without space when switched off * Fix – Prevent PHP warning when IP address unknown in Brute Force IP check * Fix – Load i18n on the login page for password-strength-meter messages when the Clean Login option is activated * Fix – Detect if parent theme has caps when child theme is activated * Fix – Dynamic file mapping to load through index.php for better compatibility with all server types = 8.2.04 (07 Mar 2025) = * Update – Add the option to customize all active and inactive themes * Fix – Brute Force error in comments when no recaptcha option is selected * Fix – WP Multisite root directory for custom WP directory installation = 8.2.03 (04 Mar 2025) = * Update – Security update on wp-activate.php path call * Fix – Headers check on Brute Force to get the real IP behind Proxy * Fix – Admin layout issue when other plugins notification is loading in Wp Ghost settings * Fix – Remove newlines from the rewrite rules = 8.2.01 (26 Feb 2025) = * Update – Add Google reCaptcha Enterprise * Update – Increase security on Brute Force feature * Update – Compatibility with Sucuri plugin on Events Log and Brute Force * Update – Add the HMWP_CONFIG_DIR constant to define the config root path * Update – Translations files for the last text changed * Fix – Get the real IP address behind proxy * Fix – Brute Force compatibility with Advanced Pack Magic Login and small bugs * Fix – Include parent theme in the custom theme name list if the child theme is loaded = 8.1.04 (06 Feb 2025) = * Update – New WP Ghost Dashboard design * Update – Login Attempt and Blocked IPs chart in WP Ghost Dashboard * Update – Email Alerts log report in WP Ghost Dashboard * Fix – Paths changed in dynamically loaded CSS and JS files * Fix – Prevent redirecting URLs to hidden paths on config rules issue * Fix – Prevent hiding the wp-admin on config rules issue * Fix – Prevent changing the wp-admin on config rules issue = 8.1.03 (22 Jan 2025) = * Update – Knowledge Base links and responsive layout * Update – GeoIP Country database for Geo-Blocking * Fix – Config update issue when saving the whitelist from Level Of Security = 8.0.21 = * Update - Added gif and tiff to media redirect in Hide WP Common Paths * Update - Allow activating hmwp_manage_settings capability only for a user using Roles & Capabilities plugin * Fixed - Layout and improved functionality = 8.0.20 = * Update - Compatibility with WP 6.7 * Update - Compatibility with LiteSpeed Quic Cloud IP addresses automatically * Fix - Litespeed cache plugin compatibility and set /cache/ls directory by default * Fix - Whitelist website IP address on REST API disable to be able to be accessed by the installed plugins = 8.0.19 = * Fix - Compatibility with LiteSpeed when CDN is not set * Fix - Change paths when www. prefix exists on the domain = 8.0.17 = * Update - Compatibility with WP Rocket Background CSS loader * Update - Compatibility with LiteSpeed Cache CDN * Update - Map Litespeed cache directory in URL Mapping * Fix - Remove dynamic CSS and JS when Text Mapping is switched off * Fix - Prevent changing wp-content and wp-includes paths in deep URL location and avoid 404 errors = 8.0.16 = * Update - Layouts, colors * Update - Added Drupal 11 in CMS simulation * Update - Set 404 Not Found error as default option for hidden paths * Fix - Compatibility with Wordfence Scan * Fix - Changed deprecated PHP functions * Fix - Warnings when domain schema is not identified for the current website * Fix - Redirect to homepage the newadmin when user is not logged in = 8.0.15 = * Fix - Compatibility with WP 6.6.2 * Fix - Compatibility with Squirrly SEO buffer when other cache plugins are active * Fix - Compatibility with Autoptimize minify = 8.0.14 = * Update - Added the option to select all Countries in Geo Blocking * Update - Brute Force compatibility with UsersWP plugin * Update whitelist path to not check Brute force reCaptcha in case of login whitelist paths = 8.0.13 = * Update - Added the option to disable Copy & Paste separately * Fix - PHP Error on HMWP_Models_Files due to the not found class * Fix - Layout, Typos, Small Bugs = 8.0.12 = * Update - Compatibility with Wordfence = 8.0.11 = * Update - Plugin security and compatibility with WP 6.6.1 & PHP 8.3 * Update - Adding wp-admin path extensions into firewall when user is not logged in = 8.0.10 = * Fix - Google reCaptcha on frontend popup to load google header if not already loaded * Fix - Hide New Login Path to allow redirects from custom paths: lost password, signup and disconnect * Fix - WP Multisite active plugins check to ignore inactive plugins * Fix - Small bugs = 8.0.09 = * Update - Add security preset loading options in Hide My WP > Restore * Fix - Library integrity on the update process * Fix - Cookie domain on WP multisite to redirect to new login path when changing sites from the network * Fix - Brute Force shortcode to work with different login forms = 8.0.07 = * Fix - Compatibility with WP 6.6 * Fix - Security update on wp-login.php and login.php = 8.0.06 = * Update - Compatibility with WordPress 6.5.5 * Update - Added the option to immediately block a wrong username in Brute Force * Update - Sub-option layouts * Fix - File Permission check to receive the correct permissions when is set stronger than required * Fix - Hide login.php URL when hide default login path * Fix - Small bugs = 8.0.05 = * Update - Added more path in Frontend Test to make sure the settings are okay before confirmation * Fix - Compatibility with Wordfence to not remove the rules from htaccess * Fix - Filter words in 8G Firewall that might be used in article slugs * Fix - Trim error in cookie when main domain cookie is set * Fix - Login header hooks to not remove custom login themes = 8.0.03 = * Fix - isPluginActive check error when is_plugin_active is not yet declared * Fix - Disable clicks and keys to work without jQuery * Fix - Compatibility with Wordfence scan process = 8.0.02 = * Fix - Show error messages in Temporary login when a user already exists * Fix - Temporary users to work on WP Multisite > Subsites = 8.0.01 = * Fix - Login security when Elementor login form is created and Brute Force is active * Fix - Login access when member plugins are used for login process * Fix - Firewall warning on preg_match bot check in firewall.php = 8.0.00 = * Update - Added Country Blocking & Geo Security feature * Update - Added Firewall blacklist by User Agent * Update - Added Firewall blacklist by Referrer * Update - Added Firewall blacklist by Hostname * Update - Added 'Send magic link login' option in All Users user row actions on Hide My WP Advanced Pack plugin * Update - Added the option to select the level of access for an IP address in whitelist * Removed - Mysql database permission check as WordPress 6.5 handles DB permissions more secure * Moved - Firewall section was moved to the main menu as includes more subsections * Fix - 8G Firewall compatibility with all page builder plugins
Copyright © WPPlugins
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |