=== Hide My WP - WordPress Security Plugin ===
Contributors: johndarrel
Tags: security, wordpress security,security plugin,hide wp-admin,hide wp-login,hide wordpress,hide my wp nulled, wordpress security plugin,hide my site,hack,malware,secure,security check,hide my wp,hide my wordpress,tips,apps,wordpress apps,wordpress plugin,plugin,url,admin,login,path,paths
Requires at least: 4.0
Tested up to: 4.9
Stable tag: trunk
Donate link: https://wpplugins.tips/wordpress
Hide My WP Ghost Lite is a WordPress Security plugin. You can change and hide WordPress common paths and URLs to increases your WP Security against hacker's bots.
== Description ==
[youtube https://www.youtube.com/watch?v=gwRKHQTNkh0]
**Hide My WP Ghost Lite** is a **WordPress Security plugin**. You can change and hide WordPress common paths and URLs to increases your WP Security against hacker's bots.
Protect your WordPress website by hiding the authentication paths like wp-admin and wp-login and change the common WordPress paths like wp-content, wp-includes, uploads and more.
Please support us and **translate the plugin in your language**:
https://translate.wordpress.org/projects/wp-plugins/hide-my-wp
Thank you all for your trust, support and positive reviews!
> **Hide My WP Ghost Lite Security Features**:
>
> * Hide WordPress wp-admin URL and redirect it to 404 page or a custom page
> * Hide WordPress wp-login.php and redirect it to 404 page or a custom page
> * Change the wp-admin and wp-login URLs
> * Change lost password URL
> * Change register URL
> * Change logout URL
> * Change admin-ajax URL
> * Change wp-content URL
> * Change wp-includes URL
> * Change comments URL
> * Change author URL
> * Change plugins URL
> * Change themes URL
> * Change category URL
> * Change tags URL
> * Hide WordPress HTML comments
> * Hide Version and WordPress Tags
> * Brute Force with Math Captcha
> * Backup and Restore settings
> * Fix relative URLs
> * Remove custom text from HTML code
> * Cache CSS, JS and Images to optimize the loading speed
> * Weekly security check and reports
>
Compatible with: WP Multisite, Apache, Litespeed, Nginx and IIS.
Plugins Compatibility updates: **W3 Total Cache, WP Super Cache, WP Fastest Cache, Cache Enabler, CDN Enabler,
WOT Cache, Autoptimize, Jetpack by WordPress, Contact Form 7, bbPress, All In One SEO, Yoast SEO, Squirrly SEO,
WP-Rocket, Minify HTML, iThemes Security, Sucuri Security, Back-Up WordPress, Elementor Page Builder,
Weglot Translate, AddToAny Share Btn**
Hosting Compatibility checked: **WP Engine, Inmotion Hosting, Hostgator Hosting, Godaddy Hosting, Host1plus,
Payperhost, Fastcomet, Dreamhost**
To **hide all the common WordPress paths** you need Hide My WP Ghost version. Check all the Ghost security features below.
The admin URL is the most common path that hackers use to break your WordPress site.
Being able to cover up the common paths is critical because you get to keep intruders away from sensitive website data.
This is crucial, and it will provide you with a great experience and really good results in the long term.
It will surely be worth it, not to mention that hiding the common paths will make hacking a lot harder as well.
If you don't protect yourself, you will end up having a hacked website sooner or later.
**This is a free version of the plugin so you can use it for all your blogs without any restrictions.**
No theme or other plugins functionality will be blocked, everything will function the same
Note: The plugin requires custom permalinks. Make sure you have it activated at Settings > Permalinks
> **Hide My WP Ghost security features:**
>
> * Hide WordPress wp-admin URL
> * Hide WordPress wp-login.php
> * Custom wp-admin and wp-login URLs
> * Custom lost password URL
> * Custom register URL
> * Custom activate URL
> * Custom logout URL
> * Custom wp-includes path
> * Custom wp-content path
> * Custom wp-json API path
> * Custom plugins name
> * Custom themes name
> * Custom themes style name
> * Custom plugins path
> * Custom uploads path
> * Custom authors path
> * Custom comment URL
> * Custom category path
> * Custom tags path
>
> * Hide plugins name
> * Hide themes name
> * Hide style IDs and META IDs
> * Hide author by ID URL
> * Hide WordPress common paths like: wp-content, wp-includes, /plugins, /themes,upgrade.php
> * Hide WordPress common files like: upgrade.php, install.php, activate.php, wp-config.php, etc.
> * Hide RSD (Really Simple Directory) header
> * Disable directory browsing
> * Add Firewall against SQL/Script injection
>
> * Hide wp-image and wp-post classes
> * Hide Emojicons if you don't use them
> * Disable XML-PRC access
> * Disable Rest API access
> * Disable Embed scripts
> * Disable DB-Debug in Frontend
> * Disable WLW Manifest scripts
>
> * Brute Force Protection with Math Captcha
> * Brute Force Protection with Google reCaptcha
> * Custom attempts, timeout, message
> * Manage Blacklist and Whitelist IPs
>
> * Log user activity
> * Set security alerts by email if users login from different IPs
> * Set security alerts by email on Brute Force attacks
> * Set security alerts by email if users delete articles
> * Set security alerts by email if users delete articles
> * Security Check with over 30 check points
>
> * Support for WP Multisite
> * Support for Nginx
> * Support for IIS
> * Support for LiteSpeed
> * Support for Apache
> * Support for Bitnami Servers
>
> * Recommended by Wp Rocket plugin
> https://goo.gl/VTPYWV
>
> **Protection against: **
>
> * Brute Force Attacks,
> * SQL Injection Attacks
> * Cross Site Scripting (XSS)
> * and more
>
> See all the **Ghost features**:
> https://hidemywp.co/wordpress
>
> Hide My WP **Knowledge Base**:
> https://hidemywp.co
Once you use the Hide My WP Ghost plugin you will get custom upload paths, author paths, plugin paths and so on.
You will also have the ability to remove unwanted classes, hide content, disable scripts and so on.
Hide My WP Ghost does an optimal job at helping you get support for WP Multisite, for Bitnami Servers, Apache, LiteSpeed, Nginx, IIS, Wp Rocket Plugin and many others.
It is worth it! You may want to check it out.
Also, just because you want to add a WordPress Security plugin that hides the common paths, that doesn't mean the plugin has to be slow.
Hide my WordPress PRO is very fast, and it won't impact your website in any negative way.
On the contrary, it will hide the common paths, deliver all the WordPress Security features above and much more while also keeping the site faster at all times!
Note! This is not the Hide My Wp Nulled version of the Hide My Wp Codecanyon plugin.
== Installation ==
Manually install the plugin:
1. Log In as an Administrator on your WordPress site.
2. In the menu displayed on the left, there is a “Plugins” tab. Click it.
3. Now click “Add New”.
4. There, you have the “Upload” button. Click the "Upload" button
5. Upload the hide-my-wp.zip file.
6. After the upload it’s finished, click Activate Plugin.
7. Connect the plugin using your email to get a free access token
8. Set the plugin in Lite Mode and click Save
9. Enjoy!
Install Hide My WP Ghost Lite directly from WordPress directory:
1. Log In as an Administrator on your WordPress site.
2. In the menu displayed on the left, there is a “Plugins” tab. Click it.
3. Search for "Hide My WP".
4. After the plugin is shown, click Activate Hide My WP
5. Connect the plugin using your email to get a free access token
6. Set the plugin in Lite Mode and click Save
7. Enjoy!
[youtube https://youtu.be/zhvRGHMjKic]
> Hide My WP **Knowledge Base**:
> https://hidemywp.co
== Screenshots ==
1. Choose the desired level of WordPress Security for your site
2. Change the URLs wp-admin and wp-login.php to different URLs. This is a very important WordPress Security step.
3. Choose to hide the wp-admin and wp-login.php to increase the WordPress Security and hackers will get 404 errors
4. Login to your site with the new Hide My WP login URL
5. You'll be redirected to the new Hide My WP admin URL
6. Activate the Brute Force Protection with Math reCaptcha
7. Add custom paths for wp-content, wp-includes, plugins, themes and more
8. Run a security check for your website and see all the vulnerabilities
== Upgrade Notice ==
Since version 1.1.022 if you hide the admin path you will not be able to access the admin path as a visitor. You need to go to the login path.
== Changelog ==
= 2.0.07 (9 Oct 2018) =
* Fix - Memory check error when the memory is over 1G
* Fix - Htaccess error when the plugin has spaces in the name
= 2.0.06 (1 Oct 2018) =
* Update - Compatibility with top WordPress cache plugins
* Update - Compatibility with top WordPress themes
* Update - Compatibility with other WordPress security plugins
* Fix - Minor bugs
= 2.0.05 (25 Sept 2018) =
* Fix - Memory limit error wne the memory is under 64MB
* Fix - Setting other paths when the admin or login paths are already set by other plugins or theme
* Update - Security Check table
* Update - Compatibility check with top WordPress plugins
= 2.0.04 (21 Sept 2018) =
* Update - Compatible with Gutenberg 3.8
* Update - Compatible with WP Super Cache 1.6
* Update - Compatible with All In One WP Security & Firewall 4.3
* Update - Compatible with iThemes Security 7.1
* Update - Compatible with Beaver Builder 2.1
* Update - Compatible with Elementor Editor 2.2
* Update - Compatible with Thrive Architect 2
* Update - Compatible with Woocommerce 3.4
* Fix - Compatibility with WP-Rocket
* Fix - Compatibility with Autoptimize
* Fix - Rewrite paths when moving from Lite mode to Default in Apache, Nginx and IIS
* Fix - Restore settings didn't save the config rewrites
= 2.0.03 (15 Sept 2018) =
* Update - Compatibility with WP Super Cache CDN
* Update - Checked and fixed the compatibility with Woocommerce
* Update - Cookie Test for WP Multisite
* Update - Security updates for SQL Injection and Script Injection
= 2.0.02 (03 Sept 2018) =
* Update - Made Security Check Notification optional
* Fixed - Don't change the paths on update from version 1 to 2
* Fixed - remove wp-config.php admin cookie line if it remains from other plugins
= 2.0.01 (10 Aug 2018) =
* Update - New Settings design
* Update - Works with WP Multisite
* Update - Works with Apache, Nginx, IIS, and Litespeed
* Update - Firewall Against Script Injection
* Update - Customize the Hide My Wp safe link
* Update - Security Check and options to fix the issues
* Update - Install and Activate recommended plugins
= 1.1.042 (03 Aug 2018) =
* Hide My Wp is compatible with WP 4.9.8
= 1.1.041 (19 July 2018) =
* Hide My Wp is compatible with WP 4.9.7
* Small Bugs fixed
= 1.1.040 (8 June 2018) =
* Update Compatibility with Inmotion Hosting
* Update Compatibility with Powered Cache
* Update Compatibility with W3 Total Cache
* Update Compatibility with WP Super Cache
* Update Compatibility with WP Fastest Cache
* Update Compatibility with Cache Enabler
* Update Compatibility with WOT Cache
* Update Compatibility with Autoptimizer
* Update Compatibility with CDN Enabler
* Update Compatibility with Squirrly SEO
* Update Compatibility with Yoast SEO
* Update Compatibility with All In One SEO
* Update Compatibility with bbPress
* Update Compatibility with Contact Form 7
* Update Compatibility with Jetpack by WordPress
= 1.1.039 (10 May 2018) =
* Add WordPress Vulnerability Detector in Setttings > Hide My WP
* Update WordPress Security for more plugins and themes
= 1.1.038 (07 April 2018) =
* Hide My Wp is compatible with WP 4.9.5
* Remove Fatal error when DOM extension is not loaded in PHP
= 1.1.037 (08 Feb 2018) =
* Hide My Wp is compatible with WP 4.9.4
* Increased WordPress Security in Frontend
= 1.1.036 (20 Jan 2018) =
* Update compatibility with more themes and plugins
* Fixed .htaccess duplicate issue (security update)
= 1.1.034 (11 Dec 2017) =
* Hide My Wp is compatible with WP 4.9.1
= 1.1.033 (13 Nov 2017) =
* Hide My Wp is compatible with WP 4.9
* Compatible with more WP Themes and Plugins
= 1.1.032 (27 Sept 2017) =
* Hide My Wp is compatible with WP 4.8.2
= 1.1.031 (18 Sept 2017) =
* Hide My Wp is compatible with WP 4.8.1
* Update wp-admin script injection (security update)
* Compatible with more WP themes
* Increased wp-login security
= 1.1.028 (17 July 2017) =
* WordPress Security Updates
= 1.1.027 (3 July 2017) =
* Fixed Logout 503 error
* Call the remove_filter with the wrong number of parameters
= 1.1.026 (9 June 2017) =
* Compatible with WP 4.8
= 1.1.025 (11 May 2017) =
* Added login redirect for *WordPress security loop protection*
* Added the option to hide the new admin path. This is optional now
* You can call the new admin path without /
= 1.1.023 (2 May 2017) =
* Compatible with BoddyBoss Theme (security update)
* Fixed small bugs
* Fixed the $user->has_cap error on WordPress security login
= 1.1.022 (21 Apr 2017) =
* Fixed rewrite for automatic upgrades
* Compatible with WP 4.7.4
* Increased the speed in Hide My Wp
= 1.1.021 =
* Fixed redirect for Forgot Password and Register options (security update)
* Fixed redirect for /login for several themes (security update)
* Protect from errors in case the user enters both admin and login with the same name
* **WordPress Security Updates**
= 1.1.019 =
* Fixed the Submenus for the last version of WordPress
= 1.1.018 =
* Added the custom redirect page for the hidden paths
* Removed the generator information (security update)
= 1.1.017 =
* Fixed the notification issue for some themes
* Fixed wp-admin redirect to login in some cases (security update)
* Compatible with WP 4.7.3
= 1.1.016 =
* Better hide the wp-admin path from not logged in users in the Lite Mode
* We added the support feature for you
* WordPress security updates
= 1.1.015 =
* Compatible with WP 4.7.2
* Improved the hide URLs feature
* Removed the wp-config.php insertion
* Fixed the loop on the sign in
* Prevent errors for IIS server
* Added recommended websites
= 1.1.012 =
* Compatible with WP 4.7
* Hide My WP knowledge base released
* Fixed memory load alert
* Fixed small security bugs
= 1.1.011 =
* Fixed https ajax in HTTP frontend
* Settings are not lost after plugin or theme activation
= 1.1.010 =
* Fixed redirect if the 404 page doesn't exists
= 1.1.009 =
* Changed the Lite options
* Fixed small bugs
* Compatible with the last version of WordPress
* Compatible with WordPress 4.6.1
* WordPress security updates
= 1.1.007 =
* Remove all data on plugin deactivate
* Update saved data on user logout
* Don't change the settings unless the user logs out from admin
= 1.1.006 =
* Send URLs and safe parameter by email on important changes
* Fixed small bugs in Hide My WP
= 1.1.005 =
* Fixed save_mod_rewrite_rules issue
* Compatible with WordPress 4.6
* Fixed small bugs for plugin css
= 1.1.003 =
* Fixed issues with Nginx, IIS, and Litespeed servers
* Prevent hiding the wp-admin and wp-login in Lite Mode
* Improved login with the safe parameter
= 1.1.002 =
* Hide the /wp-login path
= 1.1.001 =
* Compatible with WordPress 4.5
* Main WordPress security features
* Hide My WP first release
== Frequently Asked Questions ==
= Is Hide My WP working on WP Multisite? =
Yes, the plugin works on WP Multisite and you will configure it for the entire network.
The plugin also works with Apache, Nginx, IIS and LiteSpeed servers
= Is Hide My WP working on Nginx Server? =
Yes, the plugin works on Nginx Server and you will be guided for the redirects and nginx.conf settings.
The plugin also works with Apache, IIS and LiteSpeed servers
= My website theme is not loading correctly after I change the paths =
This issue is most likely from setting the rewrite rules.
1. Make sure you purge the cache if you have cache plugins after you save the Hide My WP settings.
2. In case the .htaccess (for apache) or nginx.conf (for Nginx) or web.config (for IIS) are not writable you need to add the rewrites manually.
3. If you have Nginx server make sure you reload the Nginx after you save the settings.
4. If the theme is still not loading okay, contact us and we can set up the plugin for you for free.
You can find useful information here: https://hidemywp.co/knowledge-base/
= I forgot the custom login and admin URLs. What now? =
Don't panic.
You can still access your site with the secure parameter
http://domainname/wp-login.php?hmw_disable=[your_code]
= Locked out of my site! I set the plugin, and when I left I can't manage to get in =
Rename the plugin directory /wp-content/plugins/hide-my-wp so that the plugins wouldn't hide the wp-login.php path anymore
Login using http://domainname/wp-login.php and activate the plugin again.
Make sure you remember the secure parameter, and it will be much easier.
= Is this plugin working if I don't have custom permalinks on my site? =
No. You need to have custom permalinks set on in Settings > Permalinks.
You will get a notification in the Settings page if something is not set up right.
= What to do before I deactivate the plugin? =
It's better to switch to the Default mode in Settings > Hide my wp.
If you don't, the plugin will automatically change your site back to the safe URLs, and it will tell you what to do in case you don't have write permission for the config files
_______________________________________________________________________
= Is this Plugin free of charge? =
Yes. The Lite features of Hide My WP plugin will always be free.
We will include all the required WordPress Security updates.
To unlock all the features, please visit: https://hidemywp.co/wordpress
= Is this plugin enough to protect my website from all hackers? =
The Free version of Hide My WP hides the wp-admin and wp-login as described but will not protect you from all the hackers attack.
Hide My WP Ghost hides all the common paths and patterns used but bots to detect that you are using WordPress.
We also recommend you to install Premium Themes and Plugins and not just any WordPress plugin because the free plugins are usually made by beginners and they don't have security knowledge.