Log in and users modules
The Log in and users group protects the login page and tells you who uses the site. Switch each module on from its card in WP Plus+ > Modules, then set its options and click Save.
Change the login address
Moves the login page from /wp-login.php to an address you choose. Bots that try passwords on /wp-login.php no longer find it.
- The new address serves the whole login page: logging in, logging out, Lost your password?, the password reset link from the email, and the login window WordPress opens when a session expires.
- The old
/wp-login.php, and/wp-adminfor anyone who is not logged in, answer with a 404 or send the visitor to the home page, as you choose. Addresses such asyoursite.com/loginno longer point to the login page either. - Every link and redirect WordPress writes, including the ones in emails, uses the new address.
- The password form of password-protected pages keeps working for visitors and does not reveal the new address.
| Option | What it does |
|---|---|
| New address | Only the last part: office becomes yoursite.com/office. Use letters, numbers and dashes. The words admin, wp-admin, wp-login, wp-content, wp-includes and wp-json are not accepted. While this field is empty the module does nothing, and its card says Switched on, but it does nothing until you save a new address below. |
| Someone opens the old address | Show a 404, as if nothing was there (default) or Send them to the home page. |
Safe way to switch it on:
- Write the new address down somewhere safe.
- Type it in New address and click Save.
- Before logging out, open a private (incognito) browser window, go to
yoursite.com/your-new-addressand check that you can log in there. - Only then log out of your normal window.
While the module is running, its card shows Your login address is ... with the full address, so you can always look it up from a logged-in session.
If you forget the new address or cannot log in: connect with FTP or your hosting file manager, open wp-content/plugins/ and rename the wp-plus folder (for example to wp-plus-off). WordPress switches the plugin off and /wp-login.php works again. Log in, rename the folder back, reactivate the plugin in Plugins, and read or clear the address in the module's card.
Limit failed login attempts
After a number of wrong passwords from the same internet address (IP), that address is locked out for a while. The visitor sees Too many failed attempts. Try again in 20 minutes. (with your number of minutes). A successful login clears the counter.
| Option | Range | Default |
|---|---|---|
| Attempts allowed | 3 to 20 | 5 |
| Minutes locked out | 5 to 1440 | 20 |
The count is per IP address. In an office where everyone shares one internet connection, everyone shares the counter, so do not set it too low. If you lock yourself out, wait for the minutes to pass.
Where people land after logging in
Sends the roles you choose to a page of your own after they log in, instead of the WordPress dashboard. Useful for customers or members who have nothing to do in the admin.
| Option | What it does |
|---|---|
| Address | The full address, for example https://yoursite.com/my-account/. |
| Roles this applies to | Tick the roles. By default Subscriber and Customer. Leave all unticked and nothing changes. |
Everyone else keeps the normal behaviour. If someone clicked a link that already says where to go after login (for example a "log in to see this page" link), that link wins.
Show when each user last logged in
Records the date of every login and adds a Last login column to Users > All Users, for example 3 days ago. It has no options.
Users who have not logged in since you switched the module on show a dash: the plugin cannot know what happened before it was active.
Write to us and tell us which plugin, what you tried and what you see. We answer from Italy, usually within one working day.