PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteTo hide whether a failed WordPress login used an unknown username or the wrong password, use the login_errors filter to replace the displayed error with one neutral message. This changes only the text shown above the login form; it does not change how WordPress checks credentials.
Use login_errors for one generic message
Add this filter to a site-specific plugin or a child theme—not to WordPress core files:
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
WordPress For Dummies (For Dummies (Computer/Tech)) | $16.59 | Buy on Amazon |
| 2 |
|
WordPress All-in-One For Dummies | $25.51 | Buy on Amazon |
| 3 |
|
Wordpress for Dummies | $26.94 | Buy on Amazon |
| 4 |
|
WordPress Web Design For Dummies | $16.48 | Buy on Amazon |
| 5 |
|
WordPress Web Design For Dummies | $29.30 | Buy on Amazon |
add_filter( 'login_errors', function ( $error ) {
return __( 'Invalid username or password.' );
} );
The WordPress Developer Resources reference describes this hook as filtering “the error messages displayed above the login form.” It was introduced in WordPress 2.1.0. The filter replaces the rendered error string, so the same message appears for login errors that reach this display hook.
Install and check the change
- Choose a safe location. Put the code in a site-specific plugin or your child theme’s
functions.php. Avoid editing core files, which can be overwritten by updates. - Test a failed login. Open the login page and submit an incorrect username, then test an incorrect password. Check that both display the neutral message.
- Keep an administrator route available. Make the change when you can still access the site through a working administrator session or another recovery route, in case a code error affects the login flow.
The example uses WordPress translation functions so the message can be localized. Adjust the sentence to suit your site, but keep it equally general for each failed login.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Choose the right hook for the job
| Hook | What it filters | When to use it |
|---|---|---|
login_errors |
The error string displayed above the login form; introduced in WordPress 2.1.0. WordPress Developer Resources | Use it to replace detailed login errors with one generic sentence. |
wp_login_errors |
A WP_Error object and a redirect destination; introduced in WordPress 3.6.0. WordPress Developer Resources |
Use it when you need to change particular structured error entries rather than replace the displayed string wholesale. |
authenticate |
A lower-level filter involved in validating credentials. WordPress Developer Resources | It can affect authentication results, so it is generally unnecessary when your goal is only to change the message shown to visitors. |
What a generic message does—and does not—protect
When WordPress displays different errors for an unknown username and a wrong password, those differences can disclose information to someone comparing failed attempts. A generic response removes that distinction from the login message. It does not prevent login attempts, strengthen passwords, or by itself stop account compromise; treat it as one modest hardening measure alongside sound authentication and broader site security practices.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.If the login hint still appears
A theme or plugin can customize the login flow or its messages, so a filter that works on a standard login screen may not control every site’s output. Test on the actual site and check for custom login or security plugins if the detailed message remains.
Rank #2
WordPress’s login guide notes that users can sign in with a username or its associated email address and covers login cookies and troubleshooting. If you are investigating a customized login page, keep a working administrator route available while testing changes. Core login-message behavior can also be version-sensitive: a WordPress Core Trac issue records a login-message rendering fix with WordPress 6.4.3 as its milestone. Test the behavior with your current WordPress version and plugin stack rather than assuming all login flows render errors identically.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

