WordPress

How to Password Protect the WordPress wp-admin Directory in cPanel

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (9 sections)

Bots try WordPress logins around the clock. Putting a second password in front of the wp-admin folder means a visitor has to get past the web server before WordPress even shows its login form. This guide shows how to do it with cPanel's Directory Privacy tool, the one exception you must add so your site's front end keeps working, and how to extend the same lock to wp-login.php.

Key takeaways

In cPanel, open Files › Directory Privacy, go into public_html, click Edit next to wp-admin, tick Password protect this directory, save, then create a username and password. Then add a small rule to wp-admin/.htaccess so admin-ajax.php stays open, or contact forms, carts and search can break. Use it only over HTTPS, and do not protect the login if your visitors log in to your site.

1. What this protects, and what it does not

Directory Privacy uses HTTP basic authentication. The browser shows a small username and password box, and the web server checks it before any WordPress code runs. Bots that hammer /wp-admin/ get a 401 error instead of your dashboard, and they use far less of your account's resources doing it.

Three limits to know before you start:

  • wp-login.php is not inside wp-admin. It sits in your WordPress root folder, and it is what most password-guessing bots actually attack. Section 5 shows how to put the same lock in front of it.
  • It is a second lock, not a replacement. A strong, unique WordPress password with two-factor authentication is still the main control. See installing Wordfence and setting up two-factor authentication.
  • It does not suit sites where visitors log in. Membership sites, forums, learning platforms and shops that use the standard WordPress login would put your customers in front of a password box they cannot pass.

2. Before you start

  1. Make sure the site uses HTTPS.
    Basic authentication sends the password with every request. Over plain HTTP it can be read on the network. See how to enable free SSL.
  2. Back up .htaccess files.
    Download public_html/.htaccess and, if it exists, public_html/wp-admin/.htaccess with the File Manager. If something goes wrong, you can put them back.
  3. Choose credentials that differ from your WordPress login.
    Two different passwords are the whole point. Store both in a password manager.

3. Protect wp-admin with Directory Privacy

  1. Log in to cPanel.
    From the client area, open your hosting service and use the login button, or see how to log in to cPanel.
  2. Open Directory Privacy.
    It is in the Files section.
  3. Go to your WordPress folder.
    Click the public_html folder name to open it. If WordPress is in a subfolder or an addon domain's folder, open that instead.
  4. Click Edit next to wp-admin.
    This opens the privacy settings for that folder.
  5. Turn protection on.
    Tick Password protect this directory, type a label such as "Admin area" in the name box, and click Save. The label appears in the browser's login box.
  6. Create a user.
    On the same page (click Go Back if cPanel shows a confirmation first), under Create User enter a username and a strong password, confirm it and click Save. Add one user per person who manages the site.
cPanel Directory Privacy settings for public_html: a Password protect this directory checkbox, a name field for the protected directory and a Save button
The Directory Privacy settings page; for WordPress, open it for the wp-admin folder.

cPanel writes the rules into wp-admin/.htaccess and stores the password file outside your website folder, at /home/USERNAME/.htpasswds/public_html/wp-admin/passwd. You need that path in section 5.

4. Keep admin-ajax.php open (do not skip this)

Many themes and plugins send requests from the public site to /wp-admin/admin-ajax.php: contact forms, add-to-cart buttons, live search, "load more" buttons, cookie banners. Once wp-admin is protected, every visitor who triggers one of those gets a password box or a silent failure.

Open public_html/wp-admin/.htaccess in the File Manager's editor and add this at the end:

apache
# Let the public site use admin-ajax.php
<Files "admin-ajax.php">
    Require all granted
</Files>

# Show the real 401 response instead of a WordPress page
ErrorDocument 401 default

The first block exempts one file from the password. The second stops WordPress from answering the 401 error with its own page, which can otherwise show a "page not found" or loop instead of the login box.

If a front-end feature still asks for a password, open your browser's developer tools, look at the Network tab for the /wp-admin/ file that returned 401 (often admin-post.php), and add a matching Files block for it.

Changing Directory Privacy later can rewrite this file

cPanel edits wp-admin/.htaccess whenever you change the protection settings. After any change, reopen the file and check that your admin-ajax.php block is still there.

5. Also protect wp-login.php

Protecting wp-admin leaves the login form itself open. To put the same password in front of it, add this to the .htaccess in your WordPress root folder, above the # BEGIN WordPress line:

apache
<Files "wp-login.php">
    AuthType Basic
    AuthName "Admin area"
    AuthUserFile "/home/USERNAME/.htpasswds/public_html/wp-admin/passwd"
    Require valid-user
</Files>

Replace USERNAME with your cPanel username, and adjust the folder part of the path if WordPress is not in public_html. It reuses the users you created in Directory Privacy, so there is one list to manage.

Skip this step if customers or members log in, register or reset their passwords through wp-login.php.

6. Test it properly

  1. Open a private browser window
    so no saved login is used.
  2. Visit https://yourdomain.com/wp-admin/.
    A browser login box should appear. Cancel it and you should see a 401 "Unauthorised" message, not a WordPress page.
  3. Log in through both locks.
    Enter the Directory Privacy credentials, then your WordPress username and password.
  4. Test the public site.
    Submit your contact form, add a product to the cart, run a search. None of them should ask for a password.

The browser may ask twice if you switch between http and https, or between www and the bare domain, because it remembers the password per address. Always use one address; see how to redirect non-www to www.

7. If something goes wrong

ProblemLikely causeFix
Contact form, cart or search brokenadmin-ajax.php is behind the passwordAdd the section 4 block
Page not found or a loop instead of a login boxWordPress is answering the 401Add ErrorDocument 401 default
Login box keeps coming backWrong username or password, or mixed http and httpsReset the user in Directory Privacy; use one address
Site suddenly will not load at all from your officeToo many failed attempts blocked your IPWait, or ask support to check the firewall
Forgot the Directory Privacy passwordLost credentialsSet a new password for the user in Directory Privacy
500 error after editing .htaccessA typo in the rulesRestore your backup copy and add the rules again carefully

On our cPanel server, the firewall is configured to block an IP address for an hour after 10 failed logins to password-protected folders (measured 23 September 2026). That stops bots, and it can also stop you if you mistype repeatedly. If you are locked out, open a ticket from another connection, such as mobile data, and include your IP address.

To remove the protection, open Directory Privacy, click Edit next to wp-admin, untick the box and save. Delete any wp-login.php block you added to the root .htaccess as well.

8. Where this fits in WordPress security

This lock cuts noise and brute-force load. It does not fix an outdated plugin, which is still the most common way WordPress sites are hacked. Pair it with the basics in useful tips to secure WordPress from hackers, and read why and how WordPress websites get hacked for the routes attackers really use.

On Domain India's cPanel server, Imunify360's WordPress protection and web application firewall are already on for every account, measured on 20 September 2026. Directory Privacy adds a lock you control on top.

DirectAdmin and Webuzo also offer password-protected directories from their panels; the admin-ajax.php rule in section 4 applies there too. For password-protecting folders other than WordPress, see can I password protect directories.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

The plan card shows the Domain India list price on 19 September 2026, excluding 18% GST.

Frequently asked questions

Where is Password Protect Directories in cPanel?

In current cPanel it is called Directory Privacy and is in the Files section. Open it, go into the folder that contains WordPress, click Edit next to wp-admin, tick Password protect this directory, save, and then create a user.

Why did my contact form stop working after I protected wp-admin?

Many forms and plugins send their requests to wp-admin/admin-ajax.php. Add a Files block for admin-ajax.php with Require all granted to wp-admin/.htaccess so that one file stays open to visitors.

Does protecting wp-admin also protect wp-login.php?

No. wp-login.php is in the WordPress root folder, not inside wp-admin. To protect it, add a Files block for wp-login.php to the root .htaccess that points to the same password file Directory Privacy created.

Should I use this on a WooCommerce or membership site?

Protecting wp-admin with an admin-ajax.php exception is usually fine. Do not protect wp-login.php if customers or members log in, register or reset passwords through it, because they would face a password box they cannot pass.

Is directory password protection safe without SSL?

No. Basic authentication sends the password with every request, so without HTTPS it can be read on the network. Enable the free SSL certificate and use https addresses before protecting any folder.

How do I remove the password from wp-admin?

Open Directory Privacy in cPanel, click Edit next to wp-admin, untick Password protect this directory and save. Remove any wp-login.php block you added to the root .htaccess file as well.

Ready to lock it down? Log in to cPanel from the client area, follow the steps above, then work through useful tips to secure WordPress. If you lock yourself out or a rule breaks the site, open a support ticket.

WordPress hosting with server-side protection built in

Imunify360, a web application firewall, CloudLinux account isolation and free SSL on every Domain India cPanel plan.

See cPanel hosting plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Password Protect WordPress wp-admin in cPanel