{"id":690,"date":"2025-12-26T08:28:30","date_gmt":"2025-12-26T07:28:30","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=690"},"modified":"2026-02-18T23:14:20","modified_gmt":"2026-02-18T22:14:20","slug":"how-to-secure-the-admin-panel-in-wordpress","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-secure-the-admin-panel-in-wordpress\/","title":{"rendered":"How to secure the admin panel in WordPress?"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<div class=\"wp-block-onethird-callout-box onethird-callout-wrap\"><div class=\"onethird-callout onethird-callout--hint\" style=\"--ot-bg:#EAFFF7;--ot-border:#C8E8D8;--ot-text:#6F7C88;--ot-title:#384048;--ot-body:#6F7C88;--ot-icon:#384048;border-radius:6px;padding:16px\"><div class=\"onethird-callout__head\"><span class=\"onethird-callout__icon\"><svg viewBox=\"0 0 24 24\" width=\"18\" height=\"18\" aria-hidden=\"true\" focusable=\"false\"><path fill=\"none\" stroke=\"#384048\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M2 10h4v12H2V10zm20 1c0-1.1-.9-2-2-2h-6.31l.95-4.57.02-.2c0-.26-.11-.5-.29-.68L13.17 2 7.59 7.59C7.22 7.95 7 8.45 7 9v11c0 1.1.9 2 2 2h8c.82 0 1.54-.5 1.84-1.22l3.02-7.05c.09-.23.14-.47.14-.73v-2z\"><\/path><\/svg><\/span><div class=\"onethird-callout__title\">Note<\/div><\/div><div class=\"onethird-callout__body\"><em><strong>&#8220;Drupal&#8221;<\/strong><\/em> and <em><strong>&#8220;PrestaShop&#8221;<\/strong><\/em> will be available at a later time, but not during the &#8220;Early Access&#8221; phase.<\/div><\/div><div class=\"onethird-callout__separator\" style=\"height:18px\" aria-hidden=\"true\"><\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In <a href=\"https:\/\/mybox.com\">mybox.com<\/a>, we offer active protection for <em><strong>the login panels to the &#8220;WordPress&#8221;<\/strong><\/em> backend. Every traffic coming to <strong>wp-login.php<\/strong> and <strong>wp-admin<\/strong> coming from a foreign IP address is additionally verified by <em><strong>&#8220;reCaptcha&#8221;.<\/strong><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Calls to <strong>xmlrpc.php<\/strong> are blocked automatically and rejected with a 403 error code.<\/p>\n\n\n\n<\/div>\n\n<div id=\"mybox-2654108022\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Thanks to this, your websites based on <em><strong>the &#8220;WordPress&#8221; <\/strong><\/em>engine are protected against Brute Force attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you have websites created by the application auto-installer (based on <em><strong>&#8220;WordPress&#8221;)<\/strong><\/em> on your account, you can manage this protection yourself.<\/p>\n\n\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"329\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2025\/12\/mybox-wpprotect-1024x329.png\" alt=\"\" class=\"wp-image-4343\" srcset=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2025\/12\/mybox-wpprotect-1024x329.png 1024w, https:\/\/mybox.com\/help\/wp-content\/uploads\/2025\/12\/mybox-wpprotect-300x96.png 300w, https:\/\/mybox.com\/help\/wp-content\/uploads\/2025\/12\/mybox-wpprotect-768x247.png 768w, https:\/\/mybox.com\/help\/wp-content\/uploads\/2025\/12\/mybox-wpprotect-1536x494.png 1536w, https:\/\/mybox.com\/help\/wp-content\/uploads\/2025\/12\/mybox-wpprotect-18x6.png 18w, https:\/\/mybox.com\/help\/wp-content\/uploads\/2025\/12\/mybox-wpprotect.png 1858w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n<div class=\"translation-block translation-block-merged\">\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-secure-the-admin-panel-in-wordpress\/#I_want_to_secure_a_WordPress_site_installed_by_myself\" >I want to secure a WordPress site installed by myself<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-secure-the-admin-panel-in-wordpress\/#Access_the_login_page_from_selected_IP_addresses\" >Access the login page from selected IP addresses<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-secure-the-admin-panel-in-wordpress\/#File_lock_wp-loginphp_if_logging_in_is_through_a_file_with_a_different_name_replace_it\" >File lock wp-login.php (if logging in is through a file with a different name, replace it).<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-secure-the-admin-panel-in-wordpress\/#Folder_Access_Lock\" >Folder Access Lock<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-secure-the-admin-panel-in-wordpress\/#Access_only_from_IP_addresses_in_a_certain_country\" >Access only from IP addresses in a certain country<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"I_want_to_secure_a_WordPress_site_installed_by_myself\"><\/span>I want to secure a WordPress site installed by myself<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, protection is active as for apps installed by the autoinstaller.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you would like to add countries to the list of allowed locations from which access would take place, please contact our Customer Service via the 24h Helpdesk.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Access_the_login_page_from_selected_IP_addresses\"><\/span>Access the login page from selected IP addresses<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you would like to restrict access to the login page to only your IP address, for example, you need to edit the file in your website directory <strong>.htaccess.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Add the following code in it, replacing XX.XX.XX.XX with your IP address.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"File_lock_wp-loginphp_if_logging_in_is_through_a_file_with_a_different_name_replace_it\"><\/span>File lock wp-login.php (if logging in is through a file with a different name, replace it).<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;files wp-login.php&gt;\nDeny from all\nAllow From XX.XX.XX.XX\n&lt;\/files&gt;<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Folder_Access_Lock\"><\/span>Folder Access Lock<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to block access to a folder (e.g. \/administrator for websites based on the &#8220;Joomla&#8221; engine) in the \/administrator directory, create a .htaccess file and add the following code to it. In the XX.XX.XX.XX space, enter your IP address.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>order deny,allow\ndeny from all\nallow from 46.242.149.10<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You can do the same in the case of a store based on <em><strong>&#8220;PrestaShop&#8221;<\/strong><\/em> \u2013 all you have to do is add the <strong>mentioned .htaccess<\/strong> file to the directory where the store management panel files are located.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Access_only_from_IP_addresses_in_a_certain_country\"><\/span>Access only from IP addresses in a certain country<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you would like anyone with a IP address from a specific country to be able to access the selected file or directory, add a list of addresses to the <strong>.htaccess<\/strong> file, which you can generate at <a href=\"https:\/\/www.countryipblocks.net\/acl.php\" target=\"_blank\" rel=\"noreferrer noopener\">this link<\/a>.<\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[25,58],"manual_kb_tag":[445,2483,2517,588,2501,2518,606,2502,2519,718,2503,2520,818,2504,2521,978,2505,2522,1014,2506,2523,1088,2507,3156,1174,2508,1262,2509,1342,2510,190,1480,2511,226,1626,2512,242,1628,2514,429,1984,2515,441,1992,2516],"class_list":["post-690","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-hosting","manualknowledgebasecat-web-applications-cms","manual_kb_tag-prestashop","manual_kb_tag-backend-protection","manual_kb_tag-wordpress-admin-panel","manual_kb_tag-website","manual_kb_tag-wordpress-admin-security","manual_kb_tag-secure-wordpress","manual_kb_tag-early-access","manual_kb_tag-admin-panel-security","manual_kb_tag-brute-force-attack-protection","manual_kb_tag-htaccess-file","manual_kb_tag-login-protection","manual_kb_tag-htaccess-access-control","manual_kb_tag-php","manual_kb_tag-recaptcha-verification","manual_kb_tag-ip-address-restriction","manual_kb_tag-helpdesk","manual_kb_tag-block-xmlrpc","manual_kb_tag-ip-allowlist","manual_kb_tag-mybox-com","manual_kb_tag-restrict-login-by-ip","manual_kb_tag-login-page-access-control","manual_kb_tag-ip-address","manual_kb_tag-file-access-restriction","manual_kb_tag-folder-access-lock","manual_kb_tag-admin-panel","manual_kb_tag-folder-access-restriction","manual_kb_tag-ip-blacklist","manual_kb_tag-country-based-access","manual_kb_tag-brute-force-attacks","manual_kb_tag-ip-whitelist","manual_kb_tag-wordpress","manual_kb_tag-ip-addresses","manual_kb_tag-auto-installer-security","manual_kb_tag-customer-service","manual_kb_tag-htaccess","manual_kb_tag-login-page-restriction","manual_kb_tag-mybox","manual_kb_tag-htaccess-rules","manual_kb_tag-website-firewall","manual_kb_tag-wordpress-security","manual_kb_tag-store-management","manual_kb_tag-secure-wordpress-admin","manual_kb_tag-brute-force-protection","manual_kb_tag-store-based","manual_kb_tag-limit-admin-access"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/690","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":3,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/690\/revisions"}],"predecessor-version":[{"id":4344,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/690\/revisions\/4344"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=690"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=690"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=690"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}