How to password-protect file downloads in WordPress Pro
A password-protected WordPress page doesn't protect the files it links to. Why the PDF URL stays public, and how to put a real password in front of downloads.
Updated September 26, 2026
Password-protecting a WordPress page hides the page’s text, not the files it links to. Uploads live in wp-content/uploads, and the web server hands them to anyone with the URL without asking WordPress. To password-protect a download, the file must be moved out of public reach and served only after the password is checked.
This guide explains why the page password isn’t enough, compares the real options, and shows how to set it up with FileDeck Pro.
What does WordPress’s password protection actually protect?
When you set a page’s Visibility to Password protected, WordPress replaces the page content with a password form. After a correct entry, WordPress stores a cookie in the visitor’s browser (for 10 days by default) and shows the content.
That protects the words on the page. It does not protect the PDF you linked from it. The PDF is a separate file at an address like https://example.com/wp-content/uploads/2026/09/board-pack.pdf. Requests for that address are answered by the web server directly, before WordPress loads, so no password check takes place.
The same applies to Private pages and to members-only pages built with a membership plugin: unless the plugin also protects the files, the page is locked and the files are not.
How can someone get a file from a password-protected page?
- The link gets forwarded. Anyone who unlocks the page can copy the PDF’s address into an email or chat, and it works for whoever receives it.
- Search engines find it. If the URL appears anywhere public — an old newsletter, a forum post — search engines can index the PDF itself.
- The address is predictable. By default, uploads are filed in year and month folders under their original filename.
Test it yourself: unlock the page, copy the PDF link, then open it in a private browsing window where you haven’t entered the password. If the PDF opens, the file isn’t protected.
What are the options for password-protecting downloads?
| Approach | Protects the file itself? | Trade-offs |
|---|---|---|
| Password-protected page | No | Hides the page content only |
| Password set inside the PDF | Yes — the PDF won’t open without it | The password travels with the file; you can’t revoke it or see who opened it; PDFs only |
| Password-protected zip | Yes, while zipped | Visitors must extract it; same revocation problem |
| Password-protected cloud-storage link | Depends on the provider and plan | The file lives outside your site and your library |
| A plugin that moves the file out of public reach | Yes — the file is served only after the password is checked | Needs a plugin, and one server rule on nginx |
A password inside the PDF is useful for a one-off send. For a library of documents that people return to, you want the last option: files that can’t be fetched directly, a password you can change at any time, and one place to manage it.
How to password-protect downloads with FileDeck
FileDeck Pro — password protection and file protection are included in all Pro plans, from $59/yr. See pricing
FileDeck Free publishes, searches and counts documents. Password protection and file protection are Pro, so the steps below need a Pro licence.
Step 1: Put the documents in a category
Go to Documents → Document Categories and create a category for the protected material — Board papers, say — then file the documents in it. If you have sub-categories, set the password on the parent: a restriction covers the whole branch beneath it. See categories and tags.
Step 2: Set the password
- Edit the category.
- Enter a password in the Password protect (FileDeck) field.
- Save.
Every document in the category is now covered. FileDeck stores the password hashed, so it can’t show it to you again — keep your own record. See password-protect documents and categories.
Step 3: Check what visitors see
In the library, the documents show with a padlock. To remove them from listings for anyone who hasn’t unlocked them, tick Hide restricted documents entirely under Documents → Settings → Features.
Visitors type the password into a form shown on a library scoped to that category — add the Document Library block with the category chosen, or [filedeck category="board-papers"], to the page you give them. A library listing every category shows the protected rows with a padlock but no password prompt. A visitor enters the password once and stays unlocked for 24 hours. Changing the password ends every existing unlock immediately, which is how you take access away from someone who shouldn’t have it any more.
Step 4: Confirm the file itself is protected
As soon as a document is restricted, FileDeck moves its file into a folder blocked from direct access and serves downloads through signed links that expire after 15 minutes, checking permission on every request. The link in your library stays the same, but the file’s old uploads URL stops working.
- Apache: FileDeck adds the blocking rule automatically.
- nginx: add one short location block — see protect files on nginx servers.
Then test in a private window: the library should show a padlock, the download should be refused until the password is entered, and the file’s old direct URL should no longer return the file. How it works: signed download links.
Protecting a single document
One document doesn’t need its own category. Edit it and, in the editor’s Status & visibility panel, set Visibility → Password protected with a password. FileDeck honours that password on downloads and in listings, and moves the file out of public reach like any other restricted document.
When is a shared password not enough?
A shared password is anonymous: you can’t tell who used it, and anyone it’s forwarded to gets in. Use something stronger when that matters:
- Role restriction — only logged-in users with chosen WordPress roles can download. See restrict documents by role.
- Client areas — named people each see only their own documents. See client areas.
- Single-use links — send one document to one person; the link works for one download and expires after 7 days if unused. See single-use download links.
- An activity log — record who downloaded what and when, for logged-in users. See download log and reports.
FAQ
Does password-protecting a page protect the PDFs on it?
No. WordPress’s page password hides the page content only. The PDF has its own URL in wp-content/uploads, and the web server serves it to anyone who has that URL.
Can I password-protect a single PDF?
Yes, two ways. Set a password inside the PDF with a PDF editor, which works anywhere but can’t be changed or revoked once sent. Or, with FileDeck Pro, set the document’s visibility to Password protected: downloads are refused until the password is entered, and the file moves out of public reach.
Can I see who entered the password?
No. A shared password is anonymous by design. If you need to know who downloaded a file, give people accounts, use role restriction, and turn on the activity log.
How long does a visitor stay unlocked?
24 hours for a category password, even if they close the browser. A single document protected with WordPress’s own password follows WordPress’s cookie instead, which lasts 10 days. Change the category password to end every unlock straight away (removing it lifts the protection altogether, and the documents become public).
Will Google index my password-protected files?
With file protection on, a protected file has no public URL to crawl. A file that was indexed before you protected it stops resolving at its old address, and search engines drop dead URLs over time — their removal tools can speed that up.
Next steps
Try the library itself — search, filters and layouts — on the live demo. For the wider picture, read how to stop direct URL access to files in WordPress uploads and the access control overview. If your members have accounts, how to restrict downloads to logged-in users is the better fit, and our security page sets out how file protection behaves.
Still stuck? Email support@getfiledeck.com.