Old wordpress login url after hiding choice decides what bots see when they probe /wp-login.php. 404 is the safest default. Redirect saves user mistakes. Decoy wastes bot time. Each option has merit. This guide covers the trade offs.
404: the safest default
A 404 response signals no page exists at the old URL. Bots see no WordPress site and remove you from their queue. Clean, silent, effective.
Most sites should pick 404 unless they have a specific reason for another option.
Redirect: helpful for human mistakes
Redirect the old URL to your homepage. Users who forget the new URL land somewhere sensible. Bots still get redirected and waste minimal time.
A small UX win over 404 if humans frequently hit the old URL.
Decoy: waste bot time
Decoy presents a fake login page that always fails. Bots try credentials and never succeed. The bot wastes time and gives up. Defyn Security Manager ships a decoy option built in.
the Defyn Security Manager plugin also logs the credentials bots try, which is interesting intelligence about which leaked credentials are in active use.
Always log the hits
Whatever option you pick, log every hit at the old URL. The data shows which IPs are probing, how often, and from where. Many of those IPs deserve permanent firewall blocks.
The log makes your defence visible.
How to pick
Most administrators pick 404 because simple is better. Marketing led sites pick redirect to capture lost users. Security focused sites pick decoy to gather intelligence. Each is valid.
Pick once. Stick with it. Change only with reason.
Frequently asked questions
Is old wordpress login url after hiding default 404?
Yes for most plugins. Decoy and redirect are alternative options you select.
Will decoy mess with my logs?
Decoy attempts log as failed login attempts. Filter them separately for cleaner reporting.
Should redirect be permanent or temporary?
301 permanent. Search engines drop the old URL faster.
Can I switch between options later?
Yes. Plugin settings update the behaviour without restart.
Related reading
- Hiding the login URL
- Choosing a secure custom URL
- Defyn Security Manager on WordPress.org – the plugin powering these techniques.



