Opens in a new tab
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background
[wpps_ai_summarize]
On This Page
Last updated: 01/09/2026

Password Protection

Put your whole site behind one shared password—ideal for staging, client previews, or a soft launch before you go public.

Overview

Protect an entire WordPress website behind a shared password while keeping wp-admin and the login screen accessible to administrators.

Password Protection creates a site-wide frontend gate for websites that should not yet be publicly accessible. Visitors must enter the password before they can browse protected pages, while administrators can continue managing the website normally. Protection also extends to anonymous REST API and XML-RPC access so visitors cannot simply bypass the frontend gate through WordPress APIs.

Customize the password screen with your own logo, message, colors, background image, and button styling, while built-in failed-attempt limits help protect the shared password from repeated guessing.

Password Protection is a Pro module in WP PowerSuite.

Solid black square
Solid black square
Who is this for?
  • Agencies sharing development or staging websites privately with clients
  • Businesses preparing a new website before its public launch
  • Developers restricting access to work-in-progress WordPress sites
  • Private projects that need a simple shared-password website gate
  • Site owners who want temporary frontend protection without creating user accounts for every viewer

Features

Protect the Entire Frontend
Require visitors to enter a shared password before accessing normal frontend WordPress pages.
Keep Administrator Access
WordPress administrators can continue accessing the dashboard and frontend without repeatedly passing through the password gate.
Custom Password Screen
Customize the title, message, button text, logo, background, overlay, form card, and button colors to create a branded access screen.
Failed-Attempt Protection
After five incorrect password attempts, further attempts from that IP are temporarily locked for 15 minutes.
Protect REST & XML-RPC Access
Anonymous REST API and unauthenticated XML-RPC requests are blocked while the site is protected.
Block Crawlers From the Gate
Known search engines and crawler user agents receive an access-denied response instead of being shown the password form.

Protect a Complete WordPress Website With One Password

There are many situations where a WordPress website needs to exist online without being publicly accessible.
An agency may be building a new client website on a staging domain. A company may be preparing a redesign before launch. A developer might need stakeholders to review a project remotely while preventing ordinary visitors from browsing unfinished pages.
Creating individual WordPress accounts for every reviewer can be unnecessary, while relying only on obscure URLs does not actually make the website private.
Password Protection adds a shared access gate in front of the WordPress frontend. Visitors who have not unlocked the site see the password screen instead of the requested page. Once they enter the correct password, they can browse the protected website normally for the remainder of their browser session.
The site password itself is stored using WordPress password hashing rather than as readable plain text. Changing the configured password also invalidates previously granted access, making it easy to revoke an old shared password when a project moves to another stage.

Create a Branded Password Screen

A client reviewing a development website should not necessarily see a generic WordPress access form.
Password Protection includes controls for customizing the gate so it can better match the project or company brand. You can set your own title, introductory message, and button text, upload or specify a logo, and control the logo width.
The page background can use a solid color or a full-screen image. When using an image, an adjustable overlay can improve readability and help the access form stand out against the background. Form-card colors, button colors, and hover styling can also be adjusted.
This makes the gate suitable for client previews and pre-launch sites where presentation still matters even though the website is not yet public.
The password screen itself is marked noindex,nofollow, reinforcing that the gate is an access screen rather than content intended for search results.

Protect More Than the Visible Frontend

Showing a password form on normal pages would provide incomplete protection if anonymous visitors could still retrieve site data through other WordPress interfaces.
While the gate is active, anonymous REST API requests are rejected until the visitor has valid access or qualifies for an administrative bypass. Unauthenticated XML-RPC access is also blocked.
This helps keep the protection consistent beyond ordinary browser page requests.
WP PowerSuite also handles public AJAX conservatively. Logged-in users can continue using admin-ajax.php, while anonymous AJAX requests are denied unless a developer explicitly allowlists the required action.
That distinction is important for custom websites. If a protected frontend depends on an anonymous AJAX action, that action may need to be intentionally allowed rather than opening every anonymous AJAX request by default.
For sites that want REST or XML-RPC restricted even after Password Protection is removed, the separate Disable REST API and Disable XML-RPC modules provide permanent controls for those interfaces.

Keep Search Engines and Crawlers Out of the Private Site

A protected development website should not present its password screen to search crawlers as though it were ordinary public content.
WP PowerSuite identifies common search-engine and crawler user agents and returns an HTTP 403 Access Denied response rather than showing them the password form. The gate HTML itself is also marked noindex,nofollow.
This helps communicate that the protected frontend is not intended for indexing.
However, Password Protection should not be treated as a search-engine removal tool. URLs that were already discovered or indexed do not automatically disappear simply because the site is now password protected, and static files or previously known sitemap URLs may still exist independently of the frontend gate.
For production SEO checks, WP PowerSuite's Search Visibility Warning can separately alert administrators when WordPress's own "Discourage search engines from indexing this site" setting remains enabled.

Use Cases

  • Client Website Previews
    Share an unfinished WordPress website with clients using one password without creating a WordPress account for every reviewer.
  • Development & Staging Websites
    Keep work-in-progress frontend pages unavailable to ordinary visitors while administrators continue developing the site normally.
  • Pre-Launch Websites
    Restrict the actual website until launch when a public Coming Soon page is not required.
  • Private Project Reviews
    Give stakeholders access to a complete project for review while keeping the frontend closed to everyone else.

Frequently Asked Questions

Related Modules

Google reCAPTCHA on logins, forms, comments, and WooCommerce to block bots and spam signups.
Disabled
Ask a quick math question, custom prompt, or image check before someone can submit a form or log in. Everything runs on...
Disabled
Blocks risky default usernames during registration so bots have fewer easy targets.
Disabled
Removes WordPress version from public HTML generator tags, feed generator output, and the admin footer. Does not change ver= on script and...
Disabled
Closes the old XML-RPC channel many password-guessing tools still target. Fine for most sites; skip if you rely on legacy apps or...
Disabled
Block anonymous access to WordPress core REST endpoints (users, settings, themes, and similar) while leaving logged-in staff and third-party plugin REST routes...
Disabled
Remove the dashboard screens that let anyone edit theme or plugin code from the browser—one less disaster if an account is compromised.
Disabled
Stops old-style trackbacks and pingbacks that often bring spam or junk alerts.
Disabled
Allow or block visitors by IP address—ideal for office-only dashboards or shutting out known troublemakers. Rules apply site-wide, including wp-admin and login.
Disabled
Turn off public "forgot password" self-service for everyone. Use only when you reset passwords another way (manual admin password, WP-CLI, or admin-sent...
Disabled