{"id":12785,"date":"2023-12-11T08:41:37","date_gmt":"2023-12-11T08:41:37","guid":{"rendered":"https:\/\/www.icdsoft.com\/blog\/?p=12785"},"modified":"2023-12-11T08:41:37","modified_gmt":"2023-12-11T08:41:37","slug":"how-to-customize-your-wordpress-login-page","status":"publish","type":"post","link":"https:\/\/www.icdsoft.com\/blog\/how-to-customize-your-wordpress-login-page\/","title":{"rendered":"How to Customize Your WordPress Login Page"},"content":{"rendered":"\n<p>With more than <a href=\"https:\/\/colorlib.com\/wp\/wordpress-statistics\/\" target=\"_blank\" rel=\"noreferrer noopener\">800 million<\/a> installations, WordPress is by far the most popular content management system out there. It is easy to use, and its repository gives you access to thousands of free and premium themes and plugins. If you own a website, it is very likely that it is built with <a href=\"https:\/\/www.icdsoft.com\/en\/hosting\/wordpress\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress<\/a>.<\/p>\n\n\n\n<p>If this is the case and the visitors on your website can sign up for an account, you may want to customize the site's login page. This way, they will not see the default simple login page that WordPress comes with. Even if there is no option for visitors to sign up, you can customize the login page as you use it to log in as an administrator. In this article, we will show you how you can use a different address (URL) and a different look on the WordPress login page. We will also mention a few useful enhancements that will increase the security of your login page.<\/p>\n\n\n\n<ul class=\"wp-block-advgb-summary advgb-toc alignnone\"><li class=\"toc-level-1\"><a href=\"#why-should-you-customize-the-page-1ac90871-ea44-44e8-aadc-e6894d616e40\">Why should you customize the page?<\/a><\/li><li class=\"toc-level-1\"><a href=\"#good-practices-49365c20-1db3-49d0-b5a1-ba6178990d32\">Good practices<\/a><\/li><li class=\"toc-level-1\"><a href=\"#customizing-the-url-23df8cae-5a8f-4b6a-b756-a9e914d6b605\">Customizing the login address (URL)<\/a><\/li><li class=\"toc-level-2\"><a href=\"#using-a-plugin-e3babce6-4500-4502-8d72-a50d3043b57c\">Using a plugin<\/a><\/li><li class=\"toc-level-2\"><a href=\"#customizing-it-manually-ac0fcef7-ff0e-4443-bb3c-74a71972a0dd\">Customizing it manually<\/a><\/li><li class=\"toc-level-1\"><a href=\"#customizing-the-look-5e6699c9-e6f1-4f26-aa74-25744d6ad919\">Customizing the look<\/a><\/li><li class=\"toc-level-2\"><a href=\"#using-a-plugin-925bd49e-8dc8-4cf5-94df-e095cb4a1ccb\">Using a plugin<\/a><\/li><li class=\"toc-level-2\"><a href=\"#customizing-it-manually-442acae1-1614-4fb2-96a0-c07bbe03e37b\">Customizing it manually<\/a><\/li><li class=\"toc-level-1\"><a href=\"#additional-customizations-6ead4845-52e5-4259-a179-d9a87962421e\">Additional customizations<\/a><\/li><li class=\"toc-level-2\"><a href=\"#add-captcha-8cae6d18-27c7-4b83-91e9-b0f87ca4f0ef\">Add CAPTCHA<\/a><\/li><li class=\"toc-level-2\"><a href=\"#limit-the-login-attempts-ac181c64-020f-412e-acce-b19cb94cd0b4\">Limit the login attempts<\/a><\/li><li class=\"toc-level-2\"><a href=\"#passwordprotect-the-login-page-8cf855bd-cba8-4218-8d5a-e462dff7ef6b\">Password-protect the login page<\/a><\/li><li class=\"toc-level-2\"><a href=\"#enforce-strong-passwords-f4e926f2-64a5-4ce6-a4ee-31851327753e\">Enforce strong passwords<\/a><\/li><li class=\"toc-level-2\"><a href=\"#add-2factor-authentication-2d0708a8-9037-44ec-887a-3ab531c941ab\">Add 2-factor authentication<\/a><\/li><li class=\"toc-level-1\"><a href=\"#wrap-up-9839487a-4ae8-4063-8dcc-850309a6b1d6\">Wrap-up<\/a><\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-should-you-customize-the-page-1ac90871-ea44-44e8-aadc-e6894d616e40\">Why should you customize the page?<\/h2>\n\n\n\n<p>Before we show you how, we will tell you why you should customize the login page. Any of the reasons below should convince you that this is the right thing to do.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"441\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login1-1024x441.png\" alt=\"WordPress login page with fields for username and password, and a blue login button under the WordPress logo.\" class=\"wp-image-12790 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login1-1024x441.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login1-300x129.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login1.png 1414w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/441;\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Security<\/strong>. This is one of the most important reasons to update the login URL for your WordPress dashboard. There are many automatic bots out there trying to brute force WordPress websites that use weak passwords. They usually attempt to log in using the default dashboard URL \u2013 example.com<strong>\/wp-admin<\/strong>. Unless you have added some kind of protection to the site, you have to rely on your hosting provider to block the intruders after a certain number of unsuccessful login attempts. Without any sort of protection, your website can get hacked sooner or later. Using a custom URL will minimize that chance significantly.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Good reputation<\/strong>. In the unfortunate event of a client or an admin account getting hacked, your reputation will be hurt. Client data may leak, or the website may get defaced. News spreads quickly on social media these days, so such an event is not only a matter of security, but also of keeping your good reputation as a trusted partner.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Consistency<\/strong>. It is recommended that all pages on a given website have the same or similar design. This cannot happen unless you customize the login page. People with less browsing experience may find it strange that they have to log in on a page that looks completely different from the rest of your website. Having the same layout as the rest of the site will improve the overall user experience.<\/li>\n<\/ul>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login2.png\"><img decoding=\"async\" width=\"759\" height=\"745\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login2.png\" alt=\"Login page with fields for username, password, Google Authenticator code, and a Remember Me checkbox.\" class=\"wp-image-12792 lazyload\" style=\"--smush-placeholder-width: 759px; --smush-placeholder-aspect-ratio: 759\/745;width:335px;height:auto\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login2.png 759w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login2-300x294.png 300w\" data-sizes=\"(max-width: 759px) 100vw, 759px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" \/><\/a><\/figure>\n<\/div>\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Branding.<\/strong> Adding your name and\/or logo on the login page will assure people that they are logging in on the right page. If you have a membership website or an online store, for example, people will visit the page often, so you want to brand it properly. This is one more way to increase your brand exposure and awareness as well.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Additional information<\/strong>. Customizing the login page will allow you to add any additional information you see fit. This could be a phone number for people who cannot log in, or a maintenance schedule, for example. You can also add a custom message such as a reminder, holiday working hours, etc. While you will probably add such information elsewhere as well, existing customers will not miss it on the login page as there won\u2018t be any distractions there.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"good-practices-49365c20-1db3-49d0-b5a1-ba6178990d32\">Good practices<\/h2>\n\n\n\n<p>There are some good practices you can follow when you customize the login page of your WordPress website. We have listed some of the more important ones below. Of course, you can choose to do something different and not stick to conventions. After all, each website is unique in terms of ideas and user base.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Keep it simple<\/strong>. Do not add too much content on the login page. Its purpose is to allow users to access their account. It is not the place for product information, ads, additional forms, etc. You can have some useful additional information, but it should not be too much. Do not use large images or flashy animations.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Make text readable<\/strong>. Sometimes it is tempting to use new fonts while trying to create a unique page. It is important to keep the text readable in terms of font, size, and spacing. This is valid for labels and error messages, as all the information users see should be clearly visible on any device and screen resolution.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Use relevant colors and images.<\/strong> The login page is a part of your website, so its design should be similar as well. Use the same colors you use on the other pages. Add your logo and consider the best size and position. Make sure it is not blurry and it does not overlap with other elements on the page when the screen resolution is changed. The latter is valid for any other images you add on the page as well.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"customizing-the-url-23df8cae-5a8f-4b6a-b756-a9e914d6b605\">Customizing the login address (URL)<\/h2>\n\n\n\n<p>We mentioned that the main idea behind changing the login URL is to increase the security of your website, but there are other reasons as well. You may just want to have something different from the default \/wp-admin URL. Whatever the reason is, there are two ways to do that \u2013 manually or by using a plugin.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"using-a-plugin-e3babce6-4500-4502-8d72-a50d3043b57c\">Using a plugin<\/h3>\n\n\n\n<p>We will start with the easier option. You will find several plugins such as <a href=\"https:\/\/wordpress.org\/plugins\/wps-hide-login\/\" target=\"_blank\" rel=\"noreferrer noopener\">WPS Hide Login<\/a> or <a href=\"https:\/\/wordpress.org\/plugins\/wp-hide-security-enhancer\/\" target=\"_blank\" rel=\"noreferrer noopener\">WP Hide &amp; Security Enhancer<\/a>. Changing the login URL with them is straightforward \u2013 you just have to add the exact web address that you would like to use, and the plugin will do the rest. You won\u2019t have to change anything manually. One of the advantages of using such a plugin is that you can also customize the URL of the \u201c404 Not found\u201d page. Instead of a generic URL, you can use a custom one, which can be more user-friendly.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login3.png\"><img decoding=\"async\" width=\"1024\" height=\"262\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login3-1024x262.png\" alt=\"WordPress dashboard showing WPS Hide Login settings with custom login and redirection URLs for security.\" class=\"wp-image-12793 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login3-1024x262.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login3-300x77.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login3-1536x393.png 1536w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login3.png 1677w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/262;\" \/><\/a><\/figure>\n<\/div>\n\n\n<p>Some plugins offer more advanced options than others, but they may require a payment, so you have to check which one will work for you.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"customizing-it-manually-ac0fcef7-ff0e-4443-bb3c-74a71972a0dd\">Customizing it manually<\/h3>\n\n\n\n<p>This option isn\u2019t as convenient as the first one, but we mention it because there are people who prefer to use as few plugins as possible. Have in mind that editing core files manually may damage your website, or the changes may be overwritten during a future update. It is also possible that the method mentioned below may not work with all versions of WordPress.<\/p>\n\n\n\n<p>To edit the default login URL, you have to open wp-login.php in a text editor (in your account or a desktop one such as Notepad++), and replace all mentions of wp-login.php with the name you want to use \u2013 access.php, for example. After that, save the changes and rename the file to access.php. We recommend that you download a copy of the file as a backup before you make any changes.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login4.png\"><img decoding=\"async\" width=\"1024\" height=\"663\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login4-1024x663.png\" alt=\"Notepad++ showing PHP code with admin email form and Replace dialog replacing wp-login.php with access.php.\" class=\"wp-image-12795 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login4-1024x663.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login4-300x194.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login4-1536x995.png 1536w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login4.png 1584w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/663;\" \/><\/a><\/figure>\n<\/div>\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"168\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login5-1024x168.png\" alt=\"File manager interface displaying PHP files and options to edit or delete.\" class=\"wp-image-12796 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login5-1024x168.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login5-300x49.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login5.png 1197w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/168;\" \/><\/figure>\n\n\n\n<p>After that, you have to edit the functions.php file of your theme, and add the following code to make sure that the lost password and the logout options will lead to the new custom page as well:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>add_filter( 'logout_url', 'my_logout_page', 10, 2 ); \nfunction my_logout_page( $logout_url) { \n    return home_url( '\/access.php');  \n} \n \n\nadd_filter( 'lostpassword_url', 'my_lost_password_page', 10, 2 ); \nfunction my_lost_password_page( $lostpassword_url ) { \n    return home_url( '\/access.php?action=lostpassword');  \n} <\/code><\/pre>\n\n\n\n<p>You should consider using a child theme as a future theme update will likely remove your customizations. Find out how to create a child theme here: <a href=\"https:\/\/www.icdsoft.com\/en\/kb\/view\/1093_managing_wordpress_themes#child_theme\" target=\"_blank\" rel=\"noreferrer noopener\">How to use a child theme in WordPress<\/a>. If you change the theme of your site, you will have to do everything all over again.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"customizing-the-look-5e6699c9-e6f1-4f26-aa74-25744d6ad919\">Customizing the look<\/h2>\n\n\n\n<p>Here, you have two options as well. Once again, the easier one is to use a plugin, but if you prefer, you can customize the design of the page manually.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"using-a-plugin-925bd49e-8dc8-4cf5-94df-e095cb4a1ccb\">Using a plugin<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login6-2.png\"><img decoding=\"async\" width=\"952\" height=\"882\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login6-2.png\" alt=\"WordPress LoginPress settings panel with options for session expiry, login order, and custom password fields.\" class=\"wp-image-12803 lazyload\" style=\"--smush-placeholder-width: 952px; --smush-placeholder-aspect-ratio: 952\/882;width:367px;height:auto\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login6-2.png 952w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login6-2-300x278.png 300w\" data-sizes=\"(max-width: 952px) 100vw, 952px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" \/><\/a><\/figure>\n<\/div>\n\n\n<p>There are lots of plugins in the WordPress repository that will allow you to change the way the login page looks. A few examples are <a href=\"https:\/\/wordpress.org\/plugins\/loginpress\/\" target=\"_blank\" rel=\"noreferrer noopener\">LoginPress<\/a>, <a href=\"https:\/\/wordpress.org\/plugins\/login-customizer\/\" target=\"_blank\" rel=\"noreferrer noopener\">Custom Login Page Customizer<\/a> and <a href=\"https:\/\/wordpress.org\/plugins\/bm-custom-login\/\" target=\"_blank\" rel=\"noreferrer noopener\">Custom Login<\/a>. While some specific options may be unique for each plugin, they all offer more or less the same basic set of functions. You can replace the logo, rename the login form boxes, customize the lost password form, edit the buttons on the page, change the error messages, and more.<\/p>\n\n\n\n<figure class=\"wp-block-gallery aligncenter has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login7.png\"><img decoding=\"async\" width=\"845\" height=\"884\" data-id=\"12799\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login7.png\" alt=\"WordPress dashboard showing theme customization options with LoginPress plugin active\" class=\"wp-image-12799 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login7.png 845w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login7-287x300.png 287w\" data-sizes=\"(max-width: 845px) 100vw, 845px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 845px; --smush-placeholder-aspect-ratio: 845\/884;\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login8.png\"><img decoding=\"async\" width=\"879\" height=\"882\" data-id=\"12801\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login8.png\" alt=\"WordPress dashboard with background image settings and various site management options visible.\" class=\"wp-image-12801 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login8.png 879w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login8-300x300.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login8-150x150.png 150w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login8-370x370.png 370w\" data-sizes=\"(max-width: 879px) 100vw, 879px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 879px; --smush-placeholder-aspect-ratio: 879\/882;\" \/><\/a><\/figure>\n<\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"customizing-it-manually-442acae1-1614-4fb2-96a0-c07bbe03e37b\">Customizing it manually<\/h3>\n\n\n\n<p>If you prefer to edit the page without plugins, you can do it manually. To update the logo, you should find the functions.php file of the active theme. You can go through the <em>WordPress dashboard -&gt; Appearance -&gt; Editor<\/em>, or you can go to the site root directory <em>\/wp-content\/themes\/active-theme<\/em>\/. There, add the following snippet below the code you will see in the file:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>function custom_login_logo() { \necho '&lt;style type=\"text\/css\"&gt; \n    h1 a { \n        background-image: url(https:\/\/example.com\/path-to-logo.png) !important; \n    } \n&lt;\/style&gt;'; \n} \nadd_action('login_head', 'custom_login_logo'); <\/code><\/pre>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login9.png\"><img decoding=\"async\" width=\"1024\" height=\"744\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login9-1024x744.png\" alt=\"Code editor displaying PHP code for WordPress theme functions in Twenty Twenty-Four template.\" class=\"wp-image-12805 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login9-1024x744.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login9-300x218.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login9.png 1207w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/744;\" \/><\/a><\/figure>\n<\/div>\n\n\n<p>You should have uploaded the new logo before that. If you want to add a background image, add the following code to functions.php:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>function login_background_image() { \n\necho '&lt;style type=\"text\/css\"&gt; \nbody.login{ \nbackground-image: url( \"https:\/\/example.com\/background.png\" )!important; \n} \n&lt;\/style&gt;'; \n} \nadd_action('login_head', 'login_background_image'); <\/code><\/pre>\n\n\n\n<p>If you want to change the design further, you will have to add custom CSS code, so it may be easier to use a plugin.<\/p>\n\n\n\n<p>A theme update may overwrite your changes, so you should consider using a child theme before you edit the code. Do not forget to back up any files you edit before you add or delete code.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"additional-customizations-6ead4845-52e5-4259-a179-d9a87962421e\">Additional customizations<\/h2>\n\n\n\n<p>So far, we have mentioned how to edit the URL of the WordPress login page, or how to customize its design. In this section, we will mention several additional customizations you should consider. They will help you to enhance the security of your website. No matter if you have updated the login URL, or you prefer not to change it, you should think about securing the page.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"add-captcha-8cae6d18-27c7-4b83-91e9-b0f87ca4f0ef\">Add CAPTCHA<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img decoding=\"async\" width=\"430\" height=\"618\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login10.png\" alt=\"WordPress login screen with fields for username, password and reCAPTCHA verification.\" class=\"wp-image-12808 lazyload\" style=\"--smush-placeholder-width: 430px; --smush-placeholder-aspect-ratio: 430\/618;width:243px;height:auto\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login10.png 430w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login10-209x300.png 209w\" data-sizes=\"(max-width: 430px) 100vw, 430px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" \/><\/figure>\n<\/div>\n\n\n<p>You can add CAPTCHA as an additional security layer. You will find many plugins for that purpose in the WordPress repository \u2013 <a href=\"https:\/\/wordpress.org\/plugins\/really-simple-captcha\/\" target=\"_blank\" rel=\"noreferrer noopener\">Really Simple CAPTCHA<\/a>, <a href=\"https:\/\/wordpress.org\/plugins\/advanced-google-recaptcha\/\" target=\"_blank\" rel=\"noreferrer noopener\">Advanced Google reCAPTCHA<\/a>, or <a href=\"https:\/\/wordpress.org\/plugins\/hcaptcha-for-forms-and-more\/\" target=\"_blank\" rel=\"noreferrer noopener\">hCaptcha for WordPress<\/a>. If you are not familiar with the term, CAPTCHA is the challenge you have to complete on some websites to be able to access particular content. You can find out more about this option in our article: <a href=\"https:\/\/www.icdsoft.com\/blog\/what-is-captcha-and-how-to-add-one-on-your-website\/\" target=\"_blank\" rel=\"noreferrer noopener\">What Is CAPTCHA and How \u0422o Add One on Your Website?<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"limit-the-login-attempts-ac181c64-020f-412e-acce-b19cb94cd0b4\">Limit the login attempts<\/h3>\n\n\n\n<p>By adding a plugin, you can also limit the number of times a certain user can try to log in. Plugins such as <a href=\"https:\/\/wordpress.org\/plugins\/limit-login-attempts-reloaded\/\" target=\"_blank\" rel=\"noreferrer noopener\">Limit Login Attempts Reloaded<\/a> or <a href=\"https:\/\/wordpress.org\/plugins\/loginizer\/\" target=\"_blank\" rel=\"noreferrer noopener\">Loginizer<\/a> are suitable for that purpose. Once the limit is reached, users won\u2018t be allowed to make another attempt for a certain period of time. This option is very useful in preventing brute force attacks.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login11.png\"><img decoding=\"async\" width=\"1024\" height=\"564\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login11-1024x564.png\" alt=\"WordPress security dashboard showing failed login attempts and brute force settings in Loginizer plugin.\" class=\"wp-image-12809 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login11-1024x564.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login11-300x165.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login11-1536x846.png 1536w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login11.png 1598w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/564;\" \/><\/a><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\" id=\"passwordprotect-the-login-page-8cf855bd-cba8-4218-8d5a-e462dff7ef6b\">Password-protect the login page<\/h3>\n\n\n\n<p>You can also password-protect the wp-login.php file so that bots and unauthorized individuals are not able to reach it at all. For that purpose, you will need a file named .htpasswd. It will include the username and the password you want to use, separated by a colon:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>testuser:$apr1$7cv9jbr3$tZYZ7eJYv2xtSMESE.FbT0<\/code><\/pre>\n\n\n\n<p>As the password is encrypted, you should use a tool provided by your <a href=\"https:\/\/www.icdsoft.com\/en\/hosting\/shared\" target=\"_blank\" rel=\"noreferrer noopener\">web hosting<\/a> provider, or an online generator such as https:\/\/wtools.io\/generate-htpasswd-online.<\/p>\n\n\n\n<p>Then, you have to edit the .htaccess file in the site root folder (you should have one if you use WordPress, as your site won\u2019t function properly without such a file). The .htaccess file is used to \u201ctell\u201d the Apache web server how to handle certain requests. In this case, the login credentials from the .htpasswd file should be required to access wp-login.php, and the code you should add in the .htaccess file should be:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Files \"wp-login.php\"&gt; \nAuthType Basic \nAuthUserFile \"\/home\/username\/www\/www\/.htpasswd\" \nAuthName Limited! \nrequire valid-user \n&lt;\/Files&gt; <\/code><\/pre>\n\n\n\n<p>Make sure that the path is the correct one for your hosting provider\/account.<\/p>\n\n\n\n<figure class=\"wp-block-gallery aligncenter has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login12.png\"><img decoding=\"async\" width=\"550\" height=\"555\" data-id=\"12813\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login12.png\" alt=\"A text file showing a hashed password for testuser in an htpasswd format, used for web authentication.\" class=\"wp-image-12813 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login12.png 550w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login12-297x300.png 297w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login12-150x150.png 150w\" data-sizes=\"(max-width: 550px) 100vw, 550px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 550px; --smush-placeholder-aspect-ratio: 550\/555;\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login13.png\"><img decoding=\"async\" width=\"845\" height=\"719\" data-id=\"12812\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login13.png\" alt=\"Text editor displaying WordPress .htaccess file with rewrite rules and basic authentication settings for WP-login.\" class=\"wp-image-12812 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login13.png 845w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login13-300x255.png 300w\" data-sizes=\"(max-width: 845px) 100vw, 845px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 845px; --smush-placeholder-aspect-ratio: 845\/719;\" \/><\/a><\/figure>\n<\/figure>\n\n\n\n<p>If you use our web hosting services, you can easily add password protection from our feature-rich WordPress Manager, along with many other useful options such as speed optimization, content directories protection, server-side caching, and more.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login14.png\"><img decoding=\"async\" width=\"1024\" height=\"688\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login14-1024x688.png\" alt=\"WordPress tools and security settings dashboard showing PHP version, caching, optimizations, and SSL encryption status.\" class=\"wp-image-12815 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login14-1024x688.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login14-300x202.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login14-270x180.png 270w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login14.png 1210w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/688;\" \/><\/a><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\" id=\"enforce-strong-passwords-f4e926f2-64a5-4ce6-a4ee-31851327753e\">Enforce strong passwords<\/h3>\n\n\n\n<p>WordPress comes with a password strength meter, but it allows users to set even very weak passwords by simply checking a box to acknowledge they are aware of the password being weak. If you want to prevent that and make sure that users use very strong passwords, you can use plugins like <a href=\"https:\/\/wordpress.org\/plugins\/better-wp-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Solid Security<\/a> or <a href=\"https:\/\/wordpress.org\/plugins\/password-policy-manager\/\" target=\"_blank\" rel=\"noreferrer noopener\">Password Policy Manager<\/a>. They will allow you to choose the length and the complexity of the passwords that users are able to set. Some plugins check hashed passwords against public lists of leaked data to make sure that users do not use compromised passwords.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login15.png\"><img decoding=\"async\" width=\"1024\" height=\"597\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login15-1024x597.png\" alt=\"WordPress Password Policy Manager settings dashboard with options for user password security.\" class=\"wp-image-12817 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login15-1024x597.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login15-300x175.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login15.png 1411w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/597;\" \/><\/a><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\" id=\"add-2factor-authentication-2d0708a8-9037-44ec-887a-3ab531c941ab\">Add 2-factor authentication<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-large is-resized\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login16.png\"><img decoding=\"async\" width=\"1024\" height=\"765\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login16-1024x765.png\" alt=\"WordPress dashboard: Two-Factor Authentication setup with QR code, current one-time password, and advanced settings options.\" class=\"wp-image-12818 lazyload\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/765;width:350px;height:auto\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login16-1024x765.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login16-300x224.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/login16.png 1090w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" \/><\/a><\/figure>\n<\/div>\n\n\n<p>This is one of the best options to make sure that there won\u2019t be unauthorized access to your admin account or to any of the clients\u2019 accounts. Adding a 2FA plugin will allow you to add a second level of security \u2013 email approval, SMS code, authenticator token, etc. A few examples of such plugins are <a href=\"https:\/\/wordpress.org\/plugins\/two-factor-authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">Two Factor Authentication<\/a>, <a href=\"https:\/\/wordpress.org\/plugins\/wp-2fa\/\" target=\"_blank\" rel=\"noreferrer noopener\">WP 2FA<\/a> and <a href=\"https:\/\/wordpress.org\/plugins\/two-factor\/\" target=\"_blank\" rel=\"noreferrer noopener\">Two-Factor<\/a>. You should add 2-factor authentication to your administrator account for sure. Consider the pros and cons for your customers, though. They should not experience difficulties accessing their accounts, so you should find the balance between security and good user experience.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"wrap-up-9839487a-4ae8-4063-8dcc-850309a6b1d6\">Wrap-up<\/h2>\n\n\n\n<p>With millions of WordPress websites out there, it is important for your website to stand out. One of the ways to do that is to customize the login page. You will increase the site security significantly if you change the page URL and add security measures such as CAPTCHA, 2-factor authentication or a limit for the number of login attempts. You can also improve the user experience if you customize the look of the page. Using the same design as the rest of the website, adding your brand name and logo, and displaying additional contact information or social media icons are improvements that your customers will definitely appreciate.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this article, we will show you how you can use a different URL and a different look on the login page. We will also mention a few useful enhancements that will increase its security.<\/p>\n","protected":false},"author":1,"featured_media":12787,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","footnotes":""},"categories":[1,3,11],"tags":[],"class_list":{"0":"post-12785","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-general","8":"category-how-to","9":"category-wordpress"},"author_meta":{"display_name":"ICDSoft","author_link":"https:\/\/www.icdsoft.com\/blog\/author\/icdsoft\/"},"featured_img":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/logintitle-300x169.jpg","featured_image_src":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/logintitle.jpg","featured_image_src_square":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2023\/11\/logintitle.jpg","author_info":{"display_name":"ICDSoft","author_link":"https:\/\/www.icdsoft.com\/blog\/author\/icdsoft\/"},"coauthors":[],"tax_additional":{"categories":{"linked":["<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/general\/\" class=\"advgb-post-tax-term\">General<\/a>","<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/how-to\/\" class=\"advgb-post-tax-term\">How To<\/a>","<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/wordpress\/\" class=\"advgb-post-tax-term\">WordPress<\/a>"],"unlinked":["<span class=\"advgb-post-tax-term\">General<\/span>","<span class=\"advgb-post-tax-term\">How To<\/span>","<span class=\"advgb-post-tax-term\">WordPress<\/span>"]}},"comment_count":"0","relative_dates":{"created":"Posted 3 years ago","modified":"Updated 3 years ago"},"absolute_dates":{"created":"Posted on December 11, 2023","modified":"Updated on December 11, 2023"},"absolute_dates_time":{"created":"Posted on December 11, 2023 8:41 am","modified":"Updated on December 11, 2023 8:41 am"},"featured_img_caption":"","series_order":"","_links":{"self":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/12785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/comments?post=12785"}],"version-history":[{"count":22,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/12785\/revisions"}],"predecessor-version":[{"id":12833,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/12785\/revisions\/12833"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/media\/12787"}],"wp:attachment":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/media?parent=12785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/categories?post=12785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/tags?post=12785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}