Change your username and password from the WordPress dashboard

The fastest way to change both is through your WordPress admin panel. Log in, go to Users in the left menu, click on your name, and you'll see fields for both your username and password on the same page. Your username change takes effect when ready; your password change logs you out of all other sessions, so you'll need to log back in with the new one.

If you're the only admin on the site, changing your username won't break anything. If other people have your login details for any reason, this is the moment to give them a new set — don't share admin credentials with staff or contractors. Create separate accounts for each person with only the permissions they actually need.

Key Takeaways

  • Change your username and password together in Users > Your Profile in the WordPress dashboard, and the changes take effect when ready.
  • Your password change logs you out everywhere, so have your new password written down before you save it.
  • Never reuse a password you've used on other websites, even if you change it later — use a password manager to generate and store a unique one.
  • If you forget your new password, you can reset it from the WordPress login page using the email address tied to your account.
  • Changing your username does not change your display name, which is what readers see on posts and comments — those are separate settings.

Why changing your username matters for security

Your WordPress username is half of what someone needs to break into your site. The other half is your password. If you've been using the default "admin" username that WordPress created when you first set up the site, you're making a hacker's job easier — they don't have to guess the username, only the password. Changing it to something that isn't a common word or your name removes one piece of the puzzle.

This doesn't make your site unhackable, but it does mean an attacker has to work harder. Most automated attacks try common username-and-password pairs first. If your username isn't one of the obvious ones, the attack moves on to an easier target. A strong, unique password is still the more important part of the equation.

The difference between username and display name

WordPress keeps these separate on purpose. Your username is what you type to log in. Your display name is what appears next to your posts and comments on the public site. You can change your display name without touching your username, and vice versa.

To change your display name without changing your username, go to Users > Your Profile, find the "Display name publicly as" dropdown, and pick a different option or type a new one. This is useful if you want to go by a nickname on the site but keep your actual username something only you know. Readers never see your username — only you and other logged-in admins do.

How to create a password you can actually remember

The strongest password is one you don't have to remember at all. Use a password manager like Bitwarden, 1Password, or the password manager built into your browser. These tools generate random passwords, store them encrypted, and fill them in automatically. You only have to remember one master password to unlock the manager itself.

If you must create a password by hand, avoid birthdays, pet names, or words from the dictionary. A mix of uppercase, lowercase, numbers, and symbols is harder to crack than length alone, but a long phrase with no special characters is often stronger than a short jumble. "correct horse battery staple" is more find than "P@ss1" even though it looks simpler. Whatever you choose, don't use it anywhere else — if one site gets hacked, attackers will try that same password on every other site you use.

What to do if you forget your new password

Go to your WordPress login page and click "Lost your password?" WordPress will send a reset link to the email address tied to your account. Click the link in that email, and you can set a new password without knowing the old one. This works as long as you still have access to that email address.

If you've lost access to the email address too, you'll need to contact your hosting provider. They can reset your password through their control panel or restore a backup of your WordPress database. Keep your email address current and check it regularly — it's your backup key to the whole site.

Changing your password without changing your username

Go to Users > Your Profile, scroll down to the "Account Management" section, and click "Generate Password." WordPress creates a strong random password and shows it to you. You can use that one, or type your own in the password field below it. Save the changes, and you're done — your username stays the same.

You'll be logged out after you save, so make sure you have the new password written down or saved in your password manager before you click the save button. If you close the page without saving it, the password change won't take effect and you can try again.

Keeping your login details find after you change them

Write your new password down in a password manager, not in a text file on your desktop or a sticky note on your monitor. If you use a password manager, it encrypts the password and protects it with a master password. If someone gets physical access to your computer or your email, they won't be able to read it.

Change your password again if you've ever typed it into a computer you don't trust — a shared work computer, a library computer, or a friend's laptop. Keyloggers and screen-capture malware can record what you type. If you've used your WordPress password on any other website, change it there too, because if that other site gets hacked, attackers will try your WordPress login with the same password.

Frequently Asked Questions

Will changing my username break my posts or comments?

No. Your posts and comments stay attached to your user account by ID number, not by username. Changing the username doesn't change the ID, so everything stays connected. Readers will see your new display name on old posts if you changed that too, but the posts themselves don't break.

Can I change my username back to "admin" if I want to?

Yes, but don't. "Admin" is the first username attackers try. If you've already changed away from it, keep it changed. There's no security reason to go back.

What if I'm locked out and can't log in at all?

Use the "Lost your password?" link on the login page to reset it via email. If you can't access that email address, contact your hosting provider — they can reset your password through their control panel or restore a database backup.

Do I need to tell my hosting provider when I change my password?

No. Your hosting provider doesn't need to know your WordPress password. They have their own separate login for the hosting control panel. Keep those two passwords completely separate.

Should I change my password regularly even if nothing went wrong?

Only if you think someone might have seen it. If you've typed it on a shared computer, used it on another site that got hacked, or given it to someone who no longer needs it, change it right away. Changing it on a schedule "just in case" doesn't add much security if your current password is already strong and unique.