By default, the WordPress administration panel is accessible to anyone who knows the login URL. While WordPress already protects access with usernames and passwords, you can significantly increase security by restricting access to specific IP addresses using .htaccess rules.
This method is particularly useful if:
- You manage the website from a fixed IP address.
- Only a small number of people require access to the administration panel.
- You want to reduce the risk of brute-force login attempts.
- You want to block unauthorized access before the login page even loads.
Important
This solution works best when you have a static public IP address. If your IP address changes frequently, you will need to update the rules whenever it changes.
Table of Contents
How It Works
The protection is applied in two locations:
- The
/wp-admindirectory. - The
wp-login.phplogin page.
Users connecting from unauthorized IP addresses will be denied access before WordPress processes the request.
Step 1: Find Your Public IP Address
Before creating the rules, determine the IP address that should be allowed access.
You can check your current public IP address at:
Make a note of the displayed IP address.
Step 2: Protect the wp-admin Directory
Connect to your hosting account using FTP, SFTP, or your preferred file manager.
Navigate to:
wp-admin
Create a file named:
.htaccess
If the file already exists, edit it.
Add the following rules, replacing the example IP addresses with your own:
AuthUserFile /dev/null
AuthGroupFile /dev/null
AuthName "wp-admin security"
AuthType Basic
<LIMIT GET>
order deny,allow
deny from all
# Home IP
allow from 203.0.113.10
# Office IP
allow from 198.51.100.25
# Additional trusted IP
allow from 192.0.2.50
</LIMIT>
You can add as many trusted IP addresses as needed.
Step 3: Protect the Login Page
Open the main .htaccess file located in your website root directory.
By default, this directory is:
public_html
Add the following block at the very beginning of the file:
<Files wp-login.php>
order deny,allow
deny from all
allow from 203.0.113.10
</Files>
Replace the IP address with the address you want to authorize.
If multiple IP addresses need access, add additional allow from lines:
<Files wp-login.php>
order deny,allow
deny from all
allow from 203.0.113.10
allow from 198.51.100.25
allow from 192.0.2.50
</Files>
Result
After saving both files:
- Unauthorized visitors will not be able to access
/wp-admin. - Unauthorized visitors will not be able to load
wp-login.php. - Login attempts from unknown IP addresses will be blocked before WordPress processes them.
This greatly reduces exposure to automated attacks and brute-force login attempts.
What Happens If Your IP Changes?
If your internet provider assigns a new IP address:
- Access to the WordPress administration area will stop working.
- You must update the IP addresses listed in the
.htaccessfiles. - FTP access remains available, allowing you to modify the rules if necessary.
For this reason, IP-based protection is most suitable for users with static IP addresses.
Additional Security Recommendations
For even stronger WordPress security, consider:
- Using strong passwords.
- Enabling two-factor authentication (2FA).
- Keeping WordPress updated.
- Updating themes and plugins regularly.
- Limiting login attempts.
- Disabling file editing from the WordPress dashboard.
- Using a web application firewall (WAF).
Summary
To restrict access to the WordPress administration panel:
- Create an
.htaccessfile inside thewp-admindirectory. - Allow access only from trusted IP addresses.
- Add a second rule in the main
.htaccessfile to protectwp-login.php. - Save the changes.
With these rules in place, only users connecting from approved IP addresses will be able to access the WordPress login page and administration panel.