On This Page
On This Page
Force SSL Admin
Overview
Force secure HTTPS connections for your WordPress dashboard and login page without redirecting the entire public website.
Force SSL Admin automatically redirects HTTP requests for selected administrative areas to their HTTPS equivalent. You can protect the WordPress dashboard, the login page, or both, while WordPress uses secure authentication behavior for protected admin sessions.
The module also includes trusted-proxy HTTPS detection, redirect-loop protection, compatibility with WP PowerSuite Change Login URL, and a one-time emergency disable link in case an SSL or proxy configuration causes access problems.
Force SSL Admin is a Free security module in WP PowerSuite.

- WordPress websites that want to enforce HTTPS for administrator access
- Sites where the frontend and dashboard use different HTTPS requirements
- Agencies hardening WordPress login and admin access for clients
- Websites behind supported reverse proxies or HTTPS termination
- Administrators who want HTTPS enforcement without manually editing wp-config.php
Features
Force HTTPS on wp-admin
Dashboard & Login Controls
Trusted Proxy HTTPS Detection
Emergency Disable Link
Use Cases
- Protect the Login PageEnsure users reaching the standard WordPress login screen are redirected to its HTTPS version before entering credentials.
- Protect a Custom Login URLCombine Force SSL Admin with Change Login URL to enforce HTTPS on your private WordPress login path.
- WordPress Behind a Reverse ProxyUse trusted-proxy-aware HTTPS detection where SSL is terminated before the request reaches WordPress.
- Agency Security ConfigurationApply consistent admin and login HTTPS enforcement across client sites without manually changing
wp-config.phpon each installation.
Frequently Asked Questions
What does Force SSL Admin do?
It redirects selected WordPress dashboard and login requests from HTTP to HTTPS.
Does it force HTTPS on the entire website?
No. The module specifically targets the WordPress dashboard and/or login page.
Can I force HTTPS only on wp-admin?
Yes. Dashboard and login enforcement can be controlled independently.
Can I force HTTPS only on the login page?
Yes. You can protect the login page without enabling the dashboard option.
Are both options enabled automatically?
No. Both are off initially. At least one area must be selected and the settings saved before HTTPS redirects begin.
Does it work with Change Login URL?
Yes. HTTP requests to the custom login path created by Change Login URL are redirected to HTTPS when login enforcement is active.
Does it set FORCE_SSL_ADMIN?
When dashboard protection is enabled, WP PowerSuite tells WordPress to use its force-SSL-admin behavior at runtime. It does not write
FORCE_SSL_ADMINintowp-config.php.Does it modify wp-config.php?
No.
Does it install an SSL certificate?
No. Your website must already have a working SSL/TLS certificate and functional HTTPS configuration.
What redirect types are available?
You can choose 301 Permanent or 302 Temporary. 301 is the default, while 302 can be useful during testing.
Does it work behind a reverse proxy?
It includes trusted-proxy HTTPS detection and a developer filter for environments requiring custom detection. Your proxy still needs to be configured correctly.
What happens if HTTPS causes a redirect loop?
WP PowerSuite stops forcing redirects after three detected HTTPS redirects within five minutes, helping prevent an endless loop.
What is the emergency disable link?
It is a private, secret URL that can disable Force SSL Admin if an SSL or redirect configuration prevents normal dashboard access.
Does the emergency link require login?
No. This is intentional so it remains useful during an admin-access problem. Treat the URL as a sensitive credential.
Can the emergency link be reused?
No. After successful use, its secret is rotated. Creating a new emergency link also invalidates the old one.
Does it redirect admin AJAX requests?
No. AJAX is excluded from this redirect behavior.
Does it redirect admin-post.php submissions?
No.
admin-post.phpis excluded so form POST requests are not upgraded in the middle of submission.Does it force REST or XML-RPC to HTTPS?
No. Those interfaces are outside this module’s scope. Disable REST API and Disable XML-RPC provide separate security controls when those interfaces need to be restricted.
Does Password Protection force HTTPS?
No. Password Protection controls frontend access. HTTPS should be configured separately.
Is HTTPS enough to secure the WordPress login?
No. HTTPS protects credentials and session data while they travel between browser and server. Consider combining it with Limit Login Attempts, Two-Factor Authentication, and an appropriate CAPTCHA module for additional login protection.
Is Force SSL Admin free?
Yes. Force SSL Admin is a Free module included with WP PowerSuite.


