Hide My WP Ghost is a lightweight WordPress security plugin that hides and protects your website from hackers and bots by masking common WordPress paths, blocking vulnerabilities, and adding smart firewall rules. It works with any theme or plugin, speeds up security hardening, and reduces attack surfaces without changing core files. Ideal for site owners, agencies, and WooCommerce stores that want stronger, stealthy protection with easy setup.
- Hide wp-admin, wp-login, and wp-login.php behind custom URLs
- Change common paths: wp-content, wp-includes, plugins, themes
- Firewall rules to block SQL injection, XSS, and brute-force attacks
- Disable XML-RPC, REST API endpoints, and author scans
- Spam and bot protection with bad IP and user-agent blocking
- Login security with 2FA, reCAPTCHA, and login attempt limits
- Security check and auto-hardening for common vulnerabilities
- Core, plugin, and theme vulnerability scanner alerts
- Change and hide default WordPress version and assets
- CDN and caching compatible (Cloudflare, LiteSpeed, etc.)
- Works with WooCommerce, Elementor, Divi, and major plugins
- No core file changes; clean uninstall without leftovers
- Import/export settings for quick site migrations
- Multisite and Nginx/Apache compatible configuration
- Detailed activity logs and email notifications