Customise Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorised as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

Performance cookies are used to understand and analyse the key performance indexes of the website which helps in delivering a better user experience for the visitors.

Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.

Other uncategorised cookies are those that are being analysed and have not been classified into a category as yet.

Skip to content

Login protection

Login protection is available for all Patchstack paid plan users.
Protection is available for WordPress sites only.

To manage your WordPress site’s login protection, and set up 2FA (two factor authentication) for it, navigate to Sites > yourdomain.com > Hardening > Login protection in Patchstack App.

On the Login protection subpage you can:

  • Block access to default /wp-admin page and set up a custom login URL
  • Ban IPs that fail on multiple login attempts
  • Set a specific time, where in between users can log in to WordPress
  • Enable WordPress users to set up the 2FA from WordPress profile page
  • Add IP addresses to WordPress login whitelist
  • Block certain IP addresses from being able to log into WordPress

If you define a new URL for login, it works like a security token for your wp-admin. Entering your custom URL once, will whitelist your IP to access regular wp-admin URL again.

Let’s say you enter “myadmin” to the New URL field.
To log in to your WordPress admin panel, you need to:

  1. First visit your secret URL (for example yourdomain.com/myadmin)
  2. Your IP gets whitelisted
  3. You can now log in from the regular yourdomain.com/wp-admin again
  4. Other visitors are blocked from wp-admin page, unless they know your security token (in this case /myadmin)