Why protect the admin page?
The admin page is the front door to the control room of your site. Joomla and WordPress are tools for building websites. Their login pages are easy to find. Robots try thousands of passwords on them. This is called a brute force attack, like trying every key on a big ring until one fits. A few steps make it much harder.
Step 1: Use strong passwords
- Pick a long password with letters, numbers and symbols.
- Do not use the word "admin" as your username. Create a new admin user with a different name, then delete the old one.
- Do not use the same password on other sites.
Step 2: Turn on two-step login
Two-step login asks for a second code from your phone after the password. Even if someone steals the password, they cannot get in.
- WordPress: Install a two-factor plugin. A plugin is an add-on. Search for "two factor" in Plugins, then Add New.
- Joomla: Go to Users, then Manage, open your user and use the Multi-factor Authentication tab (older versions say Two Factor Authentication).
Step 3: Limit login attempts
Install a security plugin that blocks an address after a few wrong tries. For WordPress, search for "limit login attempts". For Joomla, look in the Joomla extensions directory for a security extension.
Step 4: Password protect the admin folder
You can add a second password before the login page even appears. In cPanel:
- Log in to cPanel.
- Click Directory Privacy.
- Open the folder
public_html/wp-adminfor WordPress orpublic_html/administratorfor Joomla. - Tick Password protect this directory and give it a name.
- Click Save, then add a user name and password and click Save.
On WordPress, some features use a file in wp-admin, so test your site after this step. If forms break, remove the protection.
Step 5: Keep everything updated
Update the core software, themes and extensions often. Take a backup first.
Quick recap
- Use a strong password and a new admin username.
- Turn on two-step login.
- Limit login attempts.
- Add Directory Privacy to the admin folder.
- Keep software updated and take backups.