Exposed Admin Panel: How to Protect Your Website’s Login Page

Updated 5 min read

An exposed admin panel is a login page or management tool for your website that anyone on the internet can reach, such as /wp-admin, /admin or a database tool. For a login page, being reachable is normal. The danger is a password that can be guessed or was used elsewhere, no second step at login, or a tool that asks for no password at all.

In short

  • Bots try passwords on well-known login addresses automatically, whether or not anyone has heard of your business.
  • A second step at login means a stolen or guessed password is no longer enough on its own.
  • The worst doors need no password at all: an unfinished installer, a forgotten test copy, or a device still on its default login.

Why admin pages get attacked

The addresses are predictable. Every WordPress site has /wp-login.php and /wp-admin, and many other systems use /admin or /administrator. Attackers don’t need to know your site exists: their software tries these addresses everywhere.

Two kinds of password attack do most of the work:

  • Brute force: trying one password after another. WordPress.org’s own guide notes that these attempts are automated and often spread across networks of hijacked computers, so even failed attempts can swamp a site with requests.
  • Credential stuffing: trying email and password pairs leaked from other websites, on the bet that people reuse them. The UK’s National Cyber Security Centre (NCSC) recommends 2-step verification because it keeps criminals out of your accounts even if they know your password.

And one admin account is often the key to everything. In March 2021, an intruder exploited a flaw in a customer support server at Verkada, a security camera company, and got “Super Admin” access. Through it, they could reach more than 150,000 live customer cameras, according to the US Federal Trade Commission’s complaint against the company.

The doors that need no password

Some of the most dangerous admin pages don’t ask for a password at all:

  • An unfinished installer. If WordPress is uploaded but its setup screen is never completed, the first person to open it can finish the installation themselves and become the administrator. From there they can run their own code on your hosting account, and possibly reach other sites on it. Wordfence reported attackers scanning for exactly these screens (/wp-admin/setup-config.php) in 2017.
  • Default passwords. Routers, cameras, hosting tools and admin panels that ship with a well-known password. CISA, the US cyber defence agency, says its studies show default credentials are a top weakness attackers exploit to get into systems.
  • Forgotten copies. A staging site, a test install on a subdomain, or an old database tool like phpMyAdmin that someone set up once and never removed.

Check your own site in five minutes

  1. Open a private window and go to yoursite.com/wp-admin on WordPress, or /admin and /administrator on other systems. A login page is normal. A page that lets you straight in, or a setup screen, is not.
  2. Check that your own login asks for a second step, such as a code from an app or a passkey. If it only asks for a password, set up two-step login today, using the steps below.
  3. Review who is an admin. In WordPress, go to Users and filter by Administrator. Remove anyone who no longer needs access, and make sure no account is called admin, which WordPress.org advises against.
  4. Look for forgotten copies: subdomains such as staging., dev., test. or old., and old installations listed in your hosting control panel. Delete what you don’t use.
  5. Turn on two-step login for your hosting and domain accounts as well. Whoever controls those controls the site.

How to lock the door on your platform

WordPress

WordPress.org’s advice for protecting the login comes down to:

  • Two-factor authentication for every administrator account. On a self-hosted WordPress site it usually comes from a plugin, such as Two Factor, which is maintained by WordPress contributors. WordPress.org also suggests considering passkeys.
  • Strong passwords used nowhere else, kept in a password manager, and no admin username.
  • Limiting login attempts at your host or firewall, and a CAPTCHA on the login form to slow bots down.
  • Restricting wp-login.php and xmlrpc.php to your own IP addresses where you can, and turning off XML-RPC if nothing on your site needs it.
  • Keeping WordPress, themes and plugins up to date.

Shopify

Click your store name in the top bar, then your profile, then Security. In the Two-step authentication section, click Turn on two-step and choose an authenticator app, a security key or text messages.

Wix

Go to Account Settings, scroll down to 2-Step verification and click Enable next to the method you want: the Wix app, text message, an authenticator app, email or a passkey.

Squarespace

Turn on two-factor authentication in your account’s security settings. Squarespace supports passkeys, authenticator apps and, in some countries including the UK and US, text messages.

What Teyna checks

Teyna’s free check looks for admin pages, installers and forgotten copies of your site that answer to anyone, and proves each finding twice before it tells you. It sets false alarms aside instead of reporting them, such as an “admin panel” that turns out to be a page that answers yes to any address. It only reads: it never tries passwords on your login and never submits anything.

Is your website safe? Find out in a minute.

The free check reads only what anyone on the internet can already see: the padlock, email protection, open backups and signs of a hack. No sign-up and no card. We only ask for your email to send you the link to your report.

Scan my site for free

Questions

Is it a problem that anyone can see my WordPress login page?

Not by itself: every WordPress site has one. What matters is what stands behind it: a strong password used nowhere else, a second step at login, and a limit on how many times someone can guess.

Should I change my wp-admin login address?

A new address isn’t a lock. Anyone who finds it faces the same password box, and WordPress.org’s advice leads with two-factor login, strong unique passwords and limiting login attempts. If you do change it, do those first.

Is two-factor authentication enough?

It stops a stolen or guessed password from being enough on its own. It doesn’t help when a hole in a plugin lets someone skip the login altogether: in 2024, attackers used holes in the LiteSpeed Cache and WP Automatic plugins to create their own admin accounts without logging in. That’s why updates matter as much as passwords.

What is credential stuffing?

It’s trying email and password pairs leaked from other websites on your login, in case you reused them. The defence is a different password for every account, kept in a password manager, plus two-step login.

Can I block my admin area to everyone but me?

On a self-hosted WordPress site, often yes: WordPress.org suggests restricting the login page to known IP addresses where you can, and your host may be able to put an extra password in front of the admin folder. On Shopify, Wix and Squarespace, the login belongs to the platform, so two-step login is your lock.

sources