On This Page
On This Page
Password Protection
Overview
Protect an entire WordPress website behind a shared password while keeping wp-admin and the login screen accessible to administrators.
Password Protection creates a site-wide frontend gate for websites that should not yet be publicly accessible. Visitors must enter the password before they can browse protected pages, while administrators can continue managing the website normally. Protection also extends to anonymous REST API and XML-RPC access so visitors cannot simply bypass the frontend gate through WordPress APIs.
Customize the password screen with your own logo, message, colors, background image, and button styling, while built-in failed-attempt limits help protect the shared password from repeated guessing.
Password Protection is a Pro module in WP PowerSuite.

- Agencies sharing development or staging websites privately with clients
- Businesses preparing a new website before its public launch
- Developers restricting access to work-in-progress WordPress sites
- Private projects that need a simple shared-password website gate
- Site owners who want temporary frontend protection without creating user accounts for every viewer
Features
Protect the Entire Frontend
Keep Administrator Access
Custom Password Screen
Failed-Attempt Protection
Protect REST & XML-RPC Access
Block Crawlers From the Gate
Use Cases
- Client Website PreviewsShare an unfinished WordPress website with clients using one password without creating a WordPress account for every reviewer.
- Development & Staging WebsitesKeep work-in-progress frontend pages unavailable to ordinary visitors while administrators continue developing the site normally.
- Pre-Launch WebsitesRestrict the actual website until launch when a public Coming Soon page is not required.
- Private Project ReviewsGive stakeholders access to a complete project for review while keeping the frontend closed to everyone else.
Frequently Asked Questions
What does Password Protection do?
It places a shared-password gate in front of the WordPress frontend so visitors must unlock the site before browsing protected pages.
Is this the same as WordPress password-protected posts?
No. WordPress’s built-in post password feature protects individual pieces of content. WP PowerSuite Password Protection gates the frontend website as a whole.
Is this HTTP Basic Authentication?
No. The protection runs through WordPress rather than at the web-server authentication layer.
Does the module start protecting the site immediately when enabled?
A site password must first be saved. If the password is empty, the module can be enabled without an active frontend gate.
Can administrators still access wp-admin?
Yes. wp-admin and wp-login.php remain available, and administrators can bypass the frontend gate by default.
Do all logged-in users bypass the password?
No. The default bypass is for users with administrative manage_options access. Other logged-in roles remain subject to the gate unless behavior is customized.
How long does a visitor stay unlocked?
Access lasts for the current browser session through the wpps_pwd_access session cookie.
What happens if I change the site password?
Existing access cookies are invalidated because the access value is tied to the current password hash.
Is the site password stored as plain text?
No. The current password is stored as a WordPress password hash.
Is there brute-force protection?
Yes. Five failed attempts trigger a 15-minute IP lockout.
Can administrators clear password lockouts?
Yes. Active lockouts can be cleared from the module controls.
Can I customize the password page?
Yes. You can customize its title, message, button text, logo, background, overlay, form-card colors, and button styling.
Does it protect the REST API?
Anonymous REST access is blocked while the gate is active unless the request has valid access or qualifies for a bypass.
Does it protect XML-RPC?
Unauthenticated XML-RPC requests are blocked while Password Protection is active.
Should I also enable Disable REST API or Disable XML-RPC?
Only if you want those interfaces restricted independently of the site password. Disable REST API and Disable XML-RPC remain separate permanent security controls.
Does it work with Temporary Login?
Yes. Valid Temporary Login token requests can bypass the frontend gate so the temporary authentication flow remains accessible.
Can I use it with Coming Soon & Maintenance?
No. Both modules control the site’s frontend experience, so use one at a time.
Which should I use: Password Protection or Coming Soon?
Use Password Protection when visitors should need a password to see the actual website. Use Coming Soon & Maintenance when visitors should see a public temporary landing page instead.
Does it protect files in wp-content/uploads?
Not necessarily. Files served directly by the web server or CDN do not pass through the WordPress gate.
Does it prevent search engines from indexing the site?
The gate uses noindex,nofollow, and recognized crawlers receive a 403 response. However, it is not a search-index removal service and does not erase URLs that search engines may already know.
Do I need to configure my cache or CDN?
Yes, when full-page caching is active. Protected pages should be excluded from public caching or the cache must vary according to the wpps_pwd_access cookie so unlocked HTML is not served to unauthorized visitors.
Is Password Protection free?
No. Password Protection is a Pro module and requires an active WP PowerSuite license.


