Opens in a new tab
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background
[wpps_ai_summarize]
On This Page
Last updated: 01/09/2026

Force SSL Admin

Always open your dashboard and login screen over a secure https:// link. Anyone using the old http:// address is sent to the encrypted URL automatically.

Overview

Force secure HTTPS connections for your WordPress dashboard and login page without redirecting the entire public website.

Force SSL Admin automatically redirects HTTP requests for selected administrative areas to their HTTPS equivalent. You can protect the WordPress dashboard, the login page, or both, while WordPress uses secure authentication behavior for protected admin sessions.

The module also includes trusted-proxy HTTPS detection, redirect-loop protection, compatibility with WP PowerSuite Change Login URL, and a one-time emergency disable link in case an SSL or proxy configuration causes access problems.

Force SSL Admin is a Free security module in WP PowerSuite.

Solid black square
Solid black square
Who is this for?
  • WordPress websites that want to enforce HTTPS for administrator access
  • Sites where the frontend and dashboard use different HTTPS requirements
  • Agencies hardening WordPress login and admin access for clients
  • Websites behind supported reverse proxies or HTTPS termination
  • Administrators who want HTTPS enforcement without manually editing wp-config.php

Features

Force HTTPS on wp-admin
Automatically redirect HTTP requests for the WordPress dashboard to their secure HTTPS equivalent.
Dashboard & Login Controls
Choose whether HTTPS should be enforced for the dashboard, login page, or both.
Trusted Proxy HTTPS Detection
Recognize HTTPS behind supported trusted proxy configurations instead of relying only on the direct WordPress connection state.
Emergency Disable Link
Generate a private one-time URL that can disable Force SSL Admin even when an incorrect SSL configuration prevents normal dashboard access.

Force HTTPS Where WordPress Credentials Matter Most

HTTPS encrypts communication between the visitor's browser and the web server. This is especially important around authentication because login requests contain credentials and administrative sessions provide access to sensitive website functionality.
Force SSL Admin lets you specifically enforce HTTPS around the WordPress dashboard and authentication screens. When someone attempts to open a protected area over HTTP, WP PowerSuite rebuilds the current request using HTTPS and redirects the browser before normal access continues.
This can be useful when you need WordPress-level enforcement for administrative areas without creating a blanket frontend redirect through this module. You can enable protection for wp-admin, the login screen, or both according to how the website is configured.
Force SSL Admin does not issue or install an SSL certificate. HTTPS must already work correctly for the relevant domain before you enable enforcement. The module's role is to ensure selected WordPress administrative requests use the secure connection that your server already provides.

Handle HTTPS Behind Trusted Proxies

Not every WordPress website connects directly to the public internet.
Cloud platforms, reverse proxies, load balancers, and CDNs can terminate HTTPS before forwarding the request to the origin server. In these configurations, the visitor may genuinely be using HTTPS even though the connection arriving at WordPress appears different.
Incorrect HTTPS detection in this environment can create redirect loops because WordPress repeatedly believes the secure visitor is still using HTTP.
Force SSL Admin checks WordPress's normal SSL state while also supporting WP PowerSuite's trusted-proxy HTTPS detection. Developers can additionally customize HTTPS detection through the provided filter when a particular infrastructure requires it.
This makes the module better suited to modern hosting environments than a simple redirect snippet that only checks one server variable.
Proxy configuration still needs to be correct. The module cannot compensate for an incorrectly configured reverse proxy that provides unreliable or untrusted connection information.

Recover With an Emergency Disable Link

An HTTPS enforcement tool needs a recovery mechanism because a broken SSL certificate, DNS change, reverse-proxy mistake, or incorrect server configuration can potentially make wp-admin difficult to access.
Force SSL Admin generates a private emergency disable URL containing a long random secret. Opening that URL disables the module without requiring normal WordPress authentication.
Once successfully used, the secret is immediately rotated so the same URL cannot be reused. Administrators can also generate a new emergency link manually, which invalidates the previous one.
The emergency link should therefore be treated like a password. Anyone who possesses a valid link can disable Force SSL Admin, so it should be stored securely and never published or shared unnecessarily.
This recovery mechanism gives administrators another way back into the site when the very feature intended to enforce secure access becomes difficult to manage because the surrounding SSL environment has changed.

Use Cases

  • Protect the Login Page
    Ensure users reaching the standard WordPress login screen are redirected to its HTTPS version before entering credentials.
  • Protect a Custom Login URL
    Combine Force SSL Admin with Change Login URL to enforce HTTPS on your private WordPress login path.
  • WordPress Behind a Reverse Proxy
    Use trusted-proxy-aware HTTPS detection where SSL is terminated before the request reaches WordPress.
  • Agency Security Configuration
    Apply consistent admin and login HTTPS enforcement across client sites without manually changing wp-config.php on each installation.

Frequently Asked Questions

Related Modules

Closes the old XML-RPC channel many password-guessing tools still target. Fine for most sites; skip if you rely on legacy apps or...
Disabled
Slow down password-guessing bots by locking out repeated failed logins for increasing cool-off periods—simple protection for your sign-in form.
Disabled
Blocks risky default usernames during registration so bots have fewer easy targets.
Disabled
Allow or block visitors by IP address—ideal for office-only dashboards or shutting out known troublemakers. Rules apply site-wide, including wp-admin and login.
Disabled
Automatically protects visible email addresses and mailto links from basic spam bots by safely encoding them while keeping them clickable for visitors.
Disabled
Bot protection with Cloudflare Turnstile on logins, forms, comments, and WooCommerce—low hassle for real people.
Disabled
Keep a clear record of important dashboard activity—who logged in, what changed, and when—so you can investigate issues or stay audit-ready without...
Disabled
Remove the dashboard screens that let anyone edit theme or plugin code from the browser—one less disaster if an account is compromised.
Disabled
Stops old-style trackbacks and pingbacks that often bring spam or junk alerts.
Disabled
Put your whole site behind one shared password—ideal for staging, client previews, or a soft launch before you go public.
Disabled