• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
NameHero® Blog

NameHero® Blog

Web Hosting Tips & Resources From NameHero

  • AI Agents
    • OpenClaw
    • Claude Code
    • n8n
    • Hermes Agent
    • Open WebUI
    • Docker
  • Hosting
    • Web Hosting
    • WordPress Hosting
    • WooCommerce Hosting
    • Enterprise Hosting
    • Email Hosting
    • HeroicGuard
    • GPU Hosting
    • Website Builder
  • VPS
    • Managed VPS
    • Unmanaged VPS
    • Flex VPS
  • Reseller
  • Gaming
  • Domains
  • Account
  • Blog Home
  • Categories
  • Authors

How To Block wp-login.php With Cloudflare

Bhagwad Park

Published on: December 30, 2020

Categories: WordPress 2

Yesterday when I was checking up on the Cloudflare cache performance for my site WP-Tweaks.com, I saw this:

Bots Hammering my Site at wp-login.php
Bots Hammering my Site at wp-login.php

After filtering traffic that made it past my cache to hit the origin server directly, I saw a huge spike of requests in an incredibly short time. What’s more, they were either redirected or gave a 404. Which meant that my server had to work for each of these requests instead of sending a static file. Needless to say, I don’t want this happening. Ideally, I want bad requests to be rejected directly at my firewall and not make it to my site. Or if a request does hit my site, I want the response to be cached, and not use the database.

Analyzing further, I saw that the requests were made to wp-login.php. Now I’ve already written about my solution for masking wp-login.php using the iThemes plugin so that hackers can’t waste your resources by brute-forcing the page. But as you can see, nothing stops them from just pinging a useless URL anyway. In my logs, I saw that the most common action that bots were trying to do, was register a new user.

So I decided to implement a new Cloudflare firewall rule to block out all direct wp-login.php requests.

My Existing Setup Uses a “Keyword” in the URL

If you read my linked article above, I’ve set up my site to change the login URL to this:

www.example.com/newlogin

instead of this:

www.example.com/wp-login.php

I accomplish this with no fuss using iThemes, which then redirects to something like:

https://www.wp-tweaks.com/wp-login.php?itsec-hb-token=newlogin

So what I want in my Cloudflare rule is the following:

Block all requests to wp-login.php that don’t contain “newlogin” in my query string. Turns out this is easy to accomplish with a simple Cloudflare rule.

Cloudflare Firewall Rule to Block wp-login.php

In your Cloudflare dashboard, go to the “Firewall” section and click “Firewall Rules”. Now click “Create a Firewall Rule” and enter the details as shown here:

Firewall Rule Blocking wp-login.php
Firewall Rule Blocking wp-login.php

What we’re doing here, is creating two conditions for a request to be blocked:

  1. The request URL must have wp-login.php
  2. The query parameters must NOT contain our “magic” keyword

If these two conditions are met, it’s blocked outright as shown above. Save your changes and you’re done!

Impact of the New Cloudflare Rule

I implemented these changes yesterday and this morning, here’s the report I get about what was blocked:

Stats for Firewall Rule
Stats for Firewall Rule

As you can see, the rule was used to block a good number of requests that would otherwise have gone through to my server. It’s possible that without this rule, there would have been a lot more since bots can just “give up” if they encounter a hard block like this, so there’s no point in trying anymore.

So I’d call this a success!

Using a VPN to Restrict Access to wp-login.php and wp-admin

A tempting solution is to set up a VPN to access the admin areas of your site. That way, only you or others who are authorized can reach these sensitive sections of your site. My only objection to that is that it requires quite a bit more work to set up a VPN with a static IP, and make that VPN available to all your devices, and the devices of those you trust.

And if you’re stuck somewhere one day without access to your VPN, there’s nothing you can do. My solution here is not only free, but I feel it’s more robust. There are fewer things that can go wrong such as the VPN failing, or the certificate expiring, or something like that. Plus it’s far easier to set up!

Bhagwad Park Profile Picture
Bhagwad Park

I’m a NameHero team member, and an expert on WordPress and web hosting. I’ve been in this industry since 2008. I’ve also developed apps on Android and have written extensive tutorials on managing Linux servers. You can contact me on my website WP-Tweaks.com!

Related Posts

Blogger vs. WordPress: Which One to Use?

Let's compare WordPress and Blogger across five key areas. Then, we'll show you how to set up a professional blog with WordPress.

How to Eliminate Render-Blocking Resources in WordPress (& Why You Should)

Many things can slow down your site, including render-blocking resources. These are CSS and JavaScript files that delay the loading of content on your site. As a result, visitors will have to wait longer to interact with your page, which could lead to frustration and instant exits.  So, what can you do to eliminate render-blocking […]

What Is Self-Hosted WordPress?

In this post, we’ll differentiate self-hosted WordPress from WordPress.com, and discuss the benefits of the former.

How To Back Up Your WordPress Site (And Why You Should Do It Today)

In this post, we’ll take a closer look at why backups matter. We’ll also show you different ways to back up your WordPress website.

Reader Interactions

Comments

  1. JS says

    April 9, 2021 at 8:05 pm

    How do you modify this tutorial with the new URL Normalization that Cloudflare introduced this around 8 April 2021?

    Reply
    • Bhagwad Park says

      April 12, 2021 at 12:09 pm

      Based on what I’ve seen so far, there’s no need to change anything. Let me know if you find out something I don’t!

      Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Primary Sidebar

Follow & Subscribe

Exclusive promos, content and more!


Most Popular Posts

NameHero’s Recommended WordPress Plugin and Theme Setup

WordPress Hosting vs. Web Hosting – What’s The Difference?

How To Increase The InnoDB Buffer Pool Size

How To Fix A Stuck All-in-One WP Migration Import

How To Add A Subdomain In Cloudflare

Top Categories

  • WordPress
  • WordPress Tutorials
  • OpenClaw Hosting
  • Enterprise Hosting
  • WooCommerce
  • Web Hosting
  • Resellers
  • Website Security
  • Website Development
  • Website Performance
  • VPS Hosting
  • SEO Tips
  • Announcements
  • Domain Registration
NameHero

NameHero® proudly provides web hosting to over 40,000 customers with 99.9% uptime to over 750,000 websites.

  • Master Card
  • Visa
  • American Express
  • Discover
  • Paypal
Products
  • Web Hosting
  • Managed VPS Hosting
  • Unmanaged VPS Hosting
  • Flex VPS Hosting
  • WordPress Hosting
  • WooCommerce Hosting
  • Reseller Hosting
  • Enterprise Hosting
  • GPU Hosting
  • Email Hosting
  • HeroicGuard
  • Domains
  • Website Builder
  • AI Agent Hosting
Help & Support
  • NameHero Blog
  • NameHero Gaming Blog
  • Support
  • Help Center
  • Migrations
  • Affiliates
  • Gaming Affiliates
  • Call 1-855-984-6263
Company
  • About Us
  • Contact Sales
  • Reviews
  • Uptime
  • We're Hiring

Copyright © 2026 Name Hero, LLC. All rights reserved.
NameHero® is a registered trademark.

  • Privacy Policy
  • Terms of Use
  • Acceptable Use Policy
  • Payment Policy
  • DMCA