Securing your WooCommerce backend helps prevent brute-force attacks and unauthorised access. This guide shows you how to restrict your WordPress login page (wp-login.php) and admin dashboard (/wp-admin/) to a single trusted IP address using .htaccess.
This method only protects admin areas. Customers can still browse, add items to their cart, and check out without interruption.
Prerequisites
- A static public IP address (if your ISP changes your IP, you’ll be locked out when it changes)
- Access to your website’s root directory via FTP or cPanel File Manager
- A backup of your current .htaccess file before making changes
Access your .htaccess file
- Log in to the Ecenica Dashboard
- Click Manage next to your hosting service
- Click File Manager and navigate to the root directory of your WordPress installation
- Find the .htaccess file. If you don’t see it, click Settings and enable Show Hidden Files (dotfiles)
Alternatively use FTP, or SFTP to access and edit your .htaccess file.
How-to edit your .htaccess file
Add the IP restriction code
Open your .htaccess file and paste the following block at the very top, above the # BEGIN WordPress line:
# ====================================================================
# SECURITY: RESTRICT BACKEND ACCESS TO A SINGLE TRUSTED IP
# ====================================================================
<IfModule mod_rewrite.c>
RewriteEngine On
# 1. ALLOW SYSTEM AJAX (prevents breaking checkout/cart functionality)
RewriteCond %{REQUEST_URI} (admin-ajax\.php) [NC]
RewriteRule .* - [L]
# 2. WHITELIST TRUSTED ADMIN IP (replace 10.0.0.1 with your actual IP)
RewriteCond %{REMOTE_ADDR} ^10\.0\.0\.1$
RewriteRule .* - [L]
# 3. BLOCK ALL OTHER TRAFFIC FROM LOGIN AND ADMIN
RewriteCond %{REQUEST_URI} ^/wp-login\.php [NC,OR]
RewriteCond %{REQUEST_URI} ^/wp-admin/ [NC]
RewriteRule .* - [F,L]
</IfModule>
# ====================================================================
Replace 10\.0\.0\.1 with your own IP address. Keep the backslash (\) before each dot. For example, 192\.168\.1\.5.
Save the file and close it.
How this affects your site
For you nothing changes when you visit from your allowed IP. You can log in, edit products, and manage orders as normal. From any other IP, you’ll see a 403 Forbidden error.
For customers browsing and checkout work as usual. The admin-ajax.php exception ensures shipping calculations, tax totals, and other dynamic features keep working. Customers can still log in and manage their account from the frontend /my-account/ page.
Troubleshooting
I’m getting a 403 error from my own IP.
Check that you entered the correct IP address in the code. Make sure the backslashes before each dot are in place.
My IP changed and I’m locked out.
Log into cPanel File Manager or connect via FTP, open .htaccess, and either update the IP address or delete the code block entirely. Access will be restored immediately.
FAQs
Can I add multiple IP addresses?
Yes. Duplicate the whitelist line for each additional IP:
RewriteCond %{REMOTE_ADDR} ^10.0.0.1$ [OR]
RewriteCond %{REMOTE_ADDR} ^198.51.100.20$
RewriteRule .* - [L]
Will this affect WordPress REST API or WooCommerce API calls?
Only if those calls go through /wp-admin/. Standard API routes are not affected.