Because WordPress is one of the most popular content management systems in the world, it is frequently targeted by automated attacks and vulnerability scanners. Many of these tools rely on the default WordPress directory structure when searching for installed plugins.
One way to make automated scanning more difficult is to change the location of the plugin directory. This can be useful when implementing additional security measures or when using security plugins that support custom WordPress paths.
You can define a custom plugin directory by adding a configuration directive to the wp-config.php file.
Important: Before making any changes, create a backup of your website and the
wp-config.phpfile. Incorrect configuration may cause plugins to stop loading properly.
Table of Contents
Step 1: Locate the wp-config.php File
Connect to your website via FTP.
Navigate to your WordPress installation directory, typically:
public_html Locate the file:
wp-config.php Step 2: Add a Custom Plugin Directory Definition
Open the wp-config.php file for editing and add one of the following configurations before the line:
/* That's all, stop editing! Happy publishing. */ Option 1: Local Server Path
Use this option when defining the plugin directory using the server filesystem path:
define('WP_PLUGIN_DIR', $_SERVER['DOCUMENT_ROOT'].'/path/wp-content/plugins'); Replace:
/path/wp-content/plugins with the actual path to your custom plugin directory.
Option 2: Full URL Path
Use this option when defining the plugin directory using a full URL:
define('WP_PLUGIN_URL', 'https://yourdomain.com/path/wp-content/plugins'); Replace:
https://yourdomain.com/path/wp-content/plugins with the actual URL of your custom plugin directory.
Important Notes
- Use one method only. Do not configure both options unless you fully understand the implications.
- The directory must exist and be accessible by WordPress.
- After changing the plugin location, existing plugins may need to be moved to the new directory.
- Some plugins may assume the default WordPress directory structure and may not function correctly with a custom plugin path.
When Should You Use a Custom Plugin Directory?
Changing the default plugin directory can be useful when:
- Implementing additional WordPress hardening measures
- Reducing exposure to automated vulnerability scanners
- Using custom deployment workflows
- Organizing multiple WordPress installations
However, it should not be considered a replacement for proper security practices such as:
- Keeping WordPress updated
- Updating themes and plugins regularly
- Using strong passwords
- Enabling two-factor authentication
- Using a Web Application Firewall (WAF)
Verify the Configuration
After saving the changes:
- Log in to the WordPress administration panel.
- Verify that all plugins load correctly.
- Check the website for any errors or missing functionality.
- Review the PHP error logs if problems occur.
Summary
You can change the default WordPress plugin directory by defining a custom path in the wp-config.php file using either:
define('WP_PLUGIN_DIR', $_SERVER['DOCUMENT_ROOT'].'/path/wp-content/plugins'); or
define('WP_PLUGIN_URL', 'https://yourdomain.com/path/wp-content/plugins'); Using a custom plugin directory can provide an additional layer of obscurity against automated scanning tools, but it should always be combined with standard WordPress security best practices.