Some links on this page are affiliate links. If you buy through them, we may earn a commission at no extra cost to you. It never decides what we recommend —read how we make money.

Not everything on your server is meant for the public. A site you’re still building, a folder of client files, or an internal tool sometimes needs a password in front of it, separate from WordPress’s own login. On SiteGround, that tool is called Protected URLs (older guides and other hosts call it “directory protection” or “password-protected directories”).

This guide covers setting it up, what visitors see, and the WordPress quirks to test for. Details are from SiteGround’s knowledge base, checked in September 2026.

Where It Fits

Diagram of three gates a request passes on SiteGround before WordPress sees it. Gate one, where from: Security, Blocked Traffic blocks an IP, a range, or a whole country for one domain, used for persistent bad IPs and abusive networks. Gate two, who: Security, Protected URLs shows a browser password prompt on a path before any page loads, used for sites in development and private folders. Gate three, how many tries: the Security Optimizer plugin adds login attempt limits, two-factor authentication, and a custom login URL against password guessing. SiteGround warns that blocking a whole country also blocks services there, such as Let’s Encrypt and Googlebot if you block the USA, and advises against blocking countries where it has data centers

Protected URLs answers the question who may see a path. If your problem is where traffic comes from, use Blocked Traffic. If it’s people guessing WordPress passwords, login limits and two-factor authentication in the Security Optimizer plugin are the better fix; see our WordPress security guide.

Good Reasons to Use It

  • A site in development that shouldn’t be seen, or indexed by search engines, before launch
  • A folder of files for a client, without creating WordPress accounts
  • An extra layer in front of wp-admin on a site where only a few people ever log in

Setting It Up

  1. In Site Tools, go to Security › Protected URLs.
  2. On the URLs tab, choose the Domain.
  3. Enter the Path to protect. Leave it as / to protect the whole site, or enter a folder such as /client-files or /wp-admin.
  4. If you haven’t created a user yet, enter a username and password. If you have, pick one from the User dropdown.
  5. Click Protect.

Save the username and password in your password manager. They’re separate from your WordPress and SiteGround logins.

Managing Who Has Access

In the Manage Users list, use Manage Access (the key icon) next to a user to choose which protected URLs they can open. Give each person their own user, so you can remove one without changing everyone’s password.

What Visitors See

Opening a protected URL shows the browser’s own username and password box before any page loads. It isn’t a WordPress screen, so it can’t be styled, and it isn’t affected by WordPress plugins. Canceling or entering the wrong details shows a 401 Unauthorized error.

Because the prompt appears before WordPress runs, it also stops search engine crawlers, which makes it a reliable way to keep a site in development out of search results.

WordPress Side Effects to Test

Password-protecting parts of a WordPress site can break things that don’t expect a password prompt:

  • Protecting /wp-admin can break front-end features. Some themes and plugins load data for visitors through wp-admin/admin-ajax.php. With the folder protected, visitors may get a password prompt or a feature silently fails, such as a filter, a form, or a “load more” button. After protecting it, test the public site logged out, in a private window.
  • Protecting the whole site blocks services that call it: payment gateway callbacks, uptime monitors, and some plugin license checks. That’s fine for a site in development and a problem on a live store.
  • Remember to remove it at launch. A forgotten password prompt on a newly launched site stops visitors and search engines alike.

Removing Protection

  1. Go to Security › Protected URLs and open the URLs tab.
  2. Find the path under Manage Protected URLs.
  3. Click Delete (the bin icon).

Then open the site in a private window to confirm it loads without a prompt.

FAQ

How do I password protect a folder on SiteGround?

In Site Tools, go to Security › Protected URLs. On the URLs tab, choose the domain, enter the path, create or select a user, and click Protect. Visitors then see a browser password prompt before the folder loads.

Is SiteGround's directory protection the same as Protected URLs?

Yes. SiteGround's Site Tools calls the feature Protected URLs. It does what other hosts often call directory or folder password protection.

Can I password protect a whole WordPress site while I build it?

Yes. Protect the path / for the domain. The prompt appears before WordPress loads, which also keeps search engines out. Remove the protection when you launch.

Should I password protect wp-admin?

It adds a layer, but test carefully: some themes and plugins use wp-admin/admin-ajax.php for visitors, and those features can break. Login limits and two-factor authentication are often a simpler way to protect WordPress logins.

How do I remove a Protected URL on SiteGround?

Go to Security › Protected URLs, open the URLs tab, find the path under Manage Protected URLs, and click Delete.

Next: Blocking by Location

Protected URLs control who gets in. To control access based on where visitors connect from, see blocking IPs and countries on SiteGround.