{"id":368707,"date":"2026-09-24T05:46:18","date_gmt":"2026-09-24T05:46:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/hide-login-url-khalaf\/"},"modified":"2026-09-24T05:46:11","modified_gmt":"2026-09-24T05:46:11","slug":"khalaf-login-access-guard","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/khalaf-login-access-guard\/","author":20519826,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"6.7.9","requires":"5.0","requires_php":"7.4","requires_plugins":null,"header_name":"KHALAF Login Access Guard","header_author":"Ahmed Khalaf","header_description":"Protect your WordPress login page by changing the login URL and blocking unauthorized access with a customizable Access Denied page and live preview.","assets_banners_color":"","last_updated":"2026-09-24 05:46:11","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/www.youtube.com\/@kalam-fe-wordpress\/","header_author_uri":"https:\/\/wa.me\/+201274915124","rating":5,"author_block_rating":0,"active_installs":0,"downloads":60,"num_ratings":2,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"khalaf22","date":"2026-09-24 05:46:11","revision":3710541}},"upgrade_notice":{"1.0.0":"<p>Initial release.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":2},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3710611,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3710611,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3710611,"resolution":"1","location":"assets","locale":"","width":1695,"height":823},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3710611,"resolution":"2","location":"assets","locale":"","width":1738,"height":830},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3710611,"resolution":"3","location":"assets","locale":"","width":1713,"height":830},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3710611,"resolution":"4","location":"assets","locale":"","width":1917,"height":1019}},"screenshots":{"1":"General configuration tab with secret slug generator and copy-to-clipboard button.","2":"Content and dual-language (Arabic\/English) blocked page editor.","3":"Appearance customizer with interactive real-time live preview.","4":"Branded 403 Access Denied page displayed to unauthorized visitors."}},"plugin_section":[],"plugin_tags":[2439,3760,25642,602,600],"plugin_category":[38,54],"plugin_contributors":[282401],"plugin_business_model":[],"class_list":["post-368707","plugin","type-plugin","status-publish","hentry","plugin_tags-brute-force","plugin_tags-custom-login-url","plugin_tags-hide-login","plugin_tags-login","plugin_tags-security","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-khalaf22","plugin_committers-khalaf22"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/khalaf-login-access-guard\/assets\/icon-128x128.png?rev=3710611","icon_2x":"https:\/\/ps.w.org\/khalaf-login-access-guard\/assets\/icon-256x256.png?rev=3710611","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/khalaf-login-access-guard\/assets\/screenshot-1.png?rev=3710611","caption":"General configuration tab with secret slug generator and copy-to-clipboard button."},{"src":"https:\/\/ps.w.org\/khalaf-login-access-guard\/assets\/screenshot-2.png?rev=3710611","caption":"Content and dual-language (Arabic\/English) blocked page editor."},{"src":"https:\/\/ps.w.org\/khalaf-login-access-guard\/assets\/screenshot-3.png?rev=3710611","caption":"Appearance customizer with interactive real-time live preview."},{"src":"https:\/\/ps.w.org\/khalaf-login-access-guard\/assets\/screenshot-4.png?rev=3710611","caption":"Branded 403 Access Denied page displayed to unauthorized visitors."}],"raw_content":"<!--section=description-->\n<p><strong>KHALAF Login Access Guard<\/strong> defends your WordPress website against automated bots, brute-force attacks, and credential stuffing by transforming the standard <code>\/wp-login.php<\/code> path into a private, customizable URL of your choice.<\/p>\n\n<p>Unlike typical hide-login plugins that simply display a generic 404 error or a blank screen, <strong>KHALAF Login Access Guard<\/strong> provides a dedicated visual customizer and a real-time live preview inside your dashboard to design a modern, branded 403 Access Denied page for blocked visitors.<\/p>\n\n<h4>Key Features<\/h4>\n\n<ul>\n<li><strong>Custom Secret Login URL<\/strong>: Move <code>\/wp-login.php<\/code> to any custom slug (e.g. <code>\/my-secret-door<\/code>).<\/li>\n<li><strong>Visual Access Denied Customizer<\/strong>: Full control over background gradients\/colors, card border radius, shadows, padding, icons, typography, and button styling.<\/li>\n<li><strong>Interactive Live Preview<\/strong>: Preview your custom 403 Forbidden page in real time directly from the admin settings before publishing.<\/li>\n<li><strong>Dual-Language &amp; RTL Ready<\/strong>: Native support for Arabic and English with seamless RTL (right-to-left) typography and layout switching.<\/li>\n<li><strong>XML-RPC Attack Defense<\/strong>: Optional toggle to block automated attacks targeting <code>xmlrpc.php<\/code>.<\/li>\n<li><strong>Zero Disruption to Core Actions<\/strong>: Password recovery links with secure reset tokens, logout, privacy confirmations, and protected post actions continue working seamlessly.<\/li>\n<li><strong>Safe Redirect Option<\/strong>: Option to redirect unauthorized attempts to any custom URL on your domain instead of rendering the denied page.<\/li>\n<li><strong>One-Click Toggle<\/strong>: Activate or deactivate protection anytime without losing your customized design or settings.<\/li>\n<li><strong>Cryptographic Slug Generator<\/strong>: Generate secure, randomized login slugs using browser cryptographic randomness with one click.<\/li>\n<li><strong>Non-Intrusive Admin Notices<\/strong>: Dismissible dashboard reminders compliant with WordPress Guidelines.<\/li>\n<\/ul>\n\n<h4>Security Notes<\/h4>\n\n<ul>\n<li>The plugin does <strong>not<\/strong> alter the WordPress admin dashboard (<code>\/wp-admin<\/code>). Once logged in, administrators and authors work normally.<\/li>\n<li>Hiding your login URL provides a strong layer of defense against automated scanning bots, but should be combined with strong passwords and 2FA.<\/li>\n<li>The redirect option restricts destination targets to the same site domain to eliminate open-redirect vulnerabilities.<\/li>\n<li>Reserved system slugs (<code>wp-admin<\/code>, <code>admin<\/code>, <code>login<\/code>, <code>xmlrpc<\/code>, <code>wp-json<\/code>, etc.) are blocked from being set as the login slug.<\/li>\n<li>All settings and requests are sanitized, validated, and escaped following WordPress coding standards.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>khalaf-login-access-guard<\/code> folder to your <code>\/wp-content\/plugins\/<\/code> directory.<\/li>\n<li>Activate the plugin via <strong>Plugins \u2192 Installed Plugins<\/strong>.<\/li>\n<li>Navigate to <strong>Login Access Guard<\/strong> in the WordPress admin menu.<\/li>\n<li>Set your desired custom slug or click <strong>Generate<\/strong> for a secure random slug.<\/li>\n<li>(Optional) Customize your Access Denied page and preview it in real time under the <strong>Style &amp; Live Preview<\/strong> tab.<\/li>\n<li>Toggle <strong>Enable Protection<\/strong> and save your settings.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"i%20forgot%20my%20custom%20login%20url.%20how%20do%20i%20regain%20access%3F\"><h3>I forgot my custom login URL. How do I regain access?<\/h3><\/dt>\n<dd><p>You can regain access at any time via FTP or your hosting File Manager: temporarily rename the <code>khalaf-login-access-guard<\/code> directory inside <code>\/wp-content\/plugins\/<\/code> or delete the <code>klguard_settings<\/code> entry in <code>wp_options<\/code>. WordPress will immediately revert to the default <code>\/wp-login.php<\/code>.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20work%20with%20woocommerce%20and%20membership%20plugins%3F\"><h3>Does this plugin work with WooCommerce and membership plugins?<\/h3><\/dt>\n<dd><p>Yes. The plugin only intercepts direct visits to <code>\/wp-login.php<\/code> and protects the admin area against unauthenticated access. It does not alter frontend account pages or WooCommerce endpoints.<\/p><\/dd>\n<dt id=\"will%20this%20break%20password%20reset%20emails%20or%20logout%3F\"><h3>Will this break password reset emails or logout?<\/h3><\/dt>\n<dd><p>No. Legitimate password reset links containing verification tokens, logout requests, and GDPR privacy actions are whitelisted and execute normally.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20caching%20plugins%3F\"><h3>Does it work with caching plugins?<\/h3><\/dt>\n<dd><p>Yes. Ensure your caching plugin (WP Rocket, LiteSpeed, W3 Total Cache, etc.) is configured to exclude your custom secret login slug from page caching.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release of KHALAF Login Access Guard.<\/li>\n<li>Fully customizable 403 Access Denied page with real-time live preview.<\/li>\n<li>Native dual-language (Arabic &amp; English) with RTL support.<\/li>\n<li>Cryptographic slug generator using window.crypto.<\/li>\n<li>XML-RPC brute force protection toggle.<\/li>\n<li>Full WordPress.org plugin directory compliance.<\/li>\n<\/ul>","raw_excerpt":"Protect your WordPress login page by moving \/wp-login.php to a secret URL, with a fully customizable Access Denied page and live preview.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/368707","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=368707"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/khalaf22"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=368707"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=368707"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=368707"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=368707"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=368707"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=368707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}