Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Add a Password to the WordPress wp-admin Folder in cPanel

You can put a second lock on your WordPress admin area. This guide shows how, using cPanel's Directory Privacy tool.

Website Management2 min read14 steps5 screenshots

Why add a second password?

WordPress already asks for a username and password. But bad bots try thousands of guesses on the login page. A second password protects the whole wp-admin folder. Bots must pass this lock before they even see the WordPress login. A folder is also called a directory.

Warning: Some plugins and themes use a file inside wp-admin called admin-ajax.php for visitors. Locking the folder can break those features, such as some contact forms or live search. Test your site after you finish.

Steps

  1. Log in to cPanel. Your welcome email has the link and details.
  2. Find the Files section and click Directory Privacy.
    Screenshot: Find the Files section and click Directory Privacy .
  3. Click the public_html folder name. If WordPress lives in another folder, open that one.
  4. Click the wp-admin folder name. Click the folder's name, not the small icon, so you open the folder itself.
    Screenshot: Click the wp-admin folder name. Click the folder's name, not the small icon, so you open t
  5. Tick Password protect this directory.
  6. Type a name for the lock in the box, such as "Admin area". Visitors will see this name.
  7. Click Save.
  8. Click Go Back.
  9. Under Create User, type a username and a strong password. A strong password is long and mixes letters, numbers and symbols.
  10. Click Save.

Test it

  1. Open a private browser window.
  2. Go to yourdomain.com/wp-admin. Use your own domain.
  3. A box should pop up that asks for the new username and password.
  4. Log in with it. Then log in to WordPress as usual.

Fix the AJAX problem

If a feature on your public pages stops working, allow admin-ajax.php in the .htaccess file inside wp-admin. Take a backup of the file first. Add:

<Files admin-ajax.php>
Order allow,deny
Allow from all
Satisfy any
</Files>

This code lets that one file open without the password. If you are unsure, ask Hostvento support.

Remove the lock

Go back to Directory Privacy, open wp-admin, untick the box and click Save.

Screenshot: Go back to Directory Privacy , open wp-admin , untick the box and click Save .
Screenshot: Go back to Directory Privacy , open wp-admin , untick the box and click Save .

Quick recap

  • A second password blocks bots before WordPress loads.
    Screenshot: A second password blocks bots before WordPress loads.
  • Use Directory Privacy in cPanel.
  • Choose the wp-admin folder and add a user.
  • Test the site, especially forms and live features.
  • Allow admin-ajax.php if something breaks.