Skip to content

Home · Blog · How to open the WordPress admin and restore access

Send a request

New format

How to open the WordPress admin and restore access

The WordPress admin is the panel where you publish posts, edit pages, and install plugins. Usual entry: `https://your-site.example/wp-admin/` or `/wp-login.php`.

Below: how to open the login form, what to do with a forgotten password, when to touch the database on hosting, and why cookies or cache get in the way. This is not a guide to hacking other people’s sites and not a call to live with the login `admin`.

Share
Telegram

How to open the admin login

In the address bar open `https://your-domain.example/wp-admin/`. If the form doesn't show, try `https://your-domain.example/wp-login.php`. Use your domain; prefer HTTPS.

After WordPress install, login and password are set at the install step (or come from the developer or host). "Remember me" is fine on a personal device and risky on a shared one.

Before typing the password check:

  • keyboard layout and Caps Lock
  • correct domain (www / non-www, staging subdomain)
  • that it's your site, not a phishing copy
  • whether a security plugin changed the login URL

Site admin panel WordPress security

If you forgot the password

On the login form click "Lost your password?" (wording may differ). Enter the admin username or email — WordPress sends a link to the user's email.

Mail sometimes lands in spam or never sends because of host mail settings. Then check the mailbox from `wp-config` or the user profile, or ask hosting or the developer to reset with their tool.

Try this order:

  • recovery link on the login form
  • email plus Spam folder
  • login from a device with a live session → change password in the profile
  • reset tool in the host panel
  • only then — edit users in the DB

Practice

Before resetting access

Email and hosting first, then the DB.

0 / 6 done

Reset via hosting and the database

Many hosts can reset the WordPress password from their panel — prefer that over hand edits. If you go into phpMyAdmin: back up the DB, find the users table (often `wp_users`; the prefix may differ), update the password the way current WordPress or host docs recommend.

Don't blindly copy 2018 screenshots that say "type the password and pick MD5": the hash algorithm changed. A mistake in the users table can lock everyone out.

Site security

Cache, cookies, and other failures

If the password is right but login "breaks," clear site cookies and browser cache; temporarily disable aggressive blockers. On the site side, cache plugins, firewalls, and login-attempt limits after brute force get in the way.

Check you're opening the same protocol and host you installed WP on. Mixing `http`/`https` or mirrors sometimes loops redirects on the login form.

What to check when login fails

SymptomWhere to look
Wrong credentialsLayout, another user, email reset
White screen / redirectPlugins, HTTPS, cache
No emailSpam, host mail, SMTP
404 on wp-loginChanged login URL, site move
IP blockProtection limits, host firewall

After login: hygiene minimum

Change a weak password, check the user list and extra accounts, update WordPress, themes, and plugins. For ongoing work a password manager and 2FA help.

General CMS and roles logic — in the site-admin article; WP hardening — in the security piece.

Right after restoring access:

  • new unique password
  • check users with the Administrator role
  • core and plugin updates
  • backup
  • 2FA / login-attempt limits

Password manager

Test yourself

Mini quiz: WordPress admin

Two checks.

1 The standard path into the admin…
2 The default login admin…

Takeaways

Standard path — `/wp-admin/` or `/wp-login.php`, then email recovery. Touch the DB only with a backup and a current hash-reset method.

Don't publish other people's logins and don't try to guess access to sites you don't manage.

FAQ

How does wp-admin differ from wp-login.php?

Both lead to auth. `/wp-admin/` opens the dashboard after login; `/wp-login.php` is the login form. On some sites a security plugin changes the login URL.

Why won't /wp-admin/ open?

Different login URL, HTTPS redirect, protection plugin, cache, wrong domain (www/non-www), or the site is down. Check the address from the host or developer email.

Is keeping the login admin safe?

No — it's a common brute-force target. Set a unique admin username and strong password; enable 2FA where possible.

How is this different from the site-admin article?

That one covers why a CMS and roles exist. Here — specifically WordPress login and access recovery.

Is the phpMyAdmin password still MD5?

Old guides said MD5. Modern WordPress uses stronger hashing; host panels often have a "reset WP password" tool without hand MD5. Check current docs.

Locked out of wp-admin — and about to edit the DB without a backup?

We’ll recover via email or the host panel first, then harden the admin account so login stops being a quest.

Discuss the task