Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Secure Your Joomla or WordPress Admin Page

This guide shows you easy ways to protect the admin login page of your Joomla or WordPress website from hackers.

SSL and Security2 min read8 steps

Why protect the admin page?

The admin page is the front door to the control room of your site. Joomla and WordPress are tools for building websites. Their login pages are easy to find. Robots try thousands of passwords on them. This is called a brute force attack, like trying every key on a big ring until one fits. A few steps make it much harder.

Step 1: Use strong passwords

  1. Pick a long password with letters, numbers and symbols.
  2. Do not use the word "admin" as your username. Create a new admin user with a different name, then delete the old one.
  3. Do not use the same password on other sites.

Step 2: Turn on two-step login

Two-step login asks for a second code from your phone after the password. Even if someone steals the password, they cannot get in.

  • WordPress: Install a two-factor plugin. A plugin is an add-on. Search for "two factor" in Plugins, then Add New.
  • Joomla: Go to Users, then Manage, open your user and use the Multi-factor Authentication tab (older versions say Two Factor Authentication).

Step 3: Limit login attempts

Install a security plugin that blocks an address after a few wrong tries. For WordPress, search for "limit login attempts". For Joomla, look in the Joomla extensions directory for a security extension.

Step 4: Password protect the admin folder

You can add a second password before the login page even appears. In cPanel:

  1. Log in to cPanel.
  2. Click Directory Privacy.
  3. Open the folder public_html/wp-admin for WordPress or public_html/administrator for Joomla.
  4. Tick Password protect this directory and give it a name.
  5. Click Save, then add a user name and password and click Save.

On WordPress, some features use a file in wp-admin, so test your site after this step. If forms break, remove the protection.

Step 5: Keep everything updated

Update the core software, themes and extensions often. Take a backup first.

Tip: Only allow your own IP address to reach the admin folder if it never changes. cPanel has an IP blocker, and our guide explains it.

Quick recap

  • Use a strong password and a new admin username.
  • Turn on two-step login.
  • Limit login attempts.
  • Add Directory Privacy to the admin folder.
  • Keep software updated and take backups.