๐—ฅ๐—ฒ๐—ป๐—ฎ๐—บ๐—ถ๐—ป๐—ด ๐—ช๐—ฝ-๐—Ÿ๐—ผ๐—ด๐—ถ๐—ป ๐—œ๐˜€ ๐—ก๐—ผ๐˜ ๐—˜๐—ป๐—ผ๐˜‚๐—ด๐—ต

You want to hide your WordPress admin. Many people suggest renaming the login URL. This solves one small problem.

Rename plugins let WordPress load before they show a 404 error. This wastes your server CPU. Block the path at the server level. This stops the request before PHP runs.

Bots do not stop when they miss the login page. They look for other clues. They read your HTML source.

They see:

These clues tell bots you use WordPress. They match your versions to known bugs.

WordPress also shares clues in the REST API. It often lists your usernames.

Check your site with these tests:

Moving the login page is a start. It is not a full security plan.

Source: https://dev.to/cifi/renaming-wp-login-isnt-the-same-as-making-wp-admin-disappear-2gg8