Hola Darlings!
We finally stopped sending innocent humans to wp-login.php, the seventh circle of WordPress bureaucracy.
Tick, follows tock, follows three months of OpenClaw agents setting fire to my token budget, follows Hermes swaggering in like he owns the place. Spoiler: he does now. And tonight? Tonight we finally stopped sending innocent humans to the seventh circle of WordPress hell. You know the one. wp-login.php. That white-screen-of-bureaucracy that looks like it was designed by someone who hates joy.
So here’s what we did while my liver filed a formal complaint.
Tick, follows tock…
The Password Pasting War
Remember when I said our registration form was broken? Turns out WordPress core, BuddyPress, and some rogue JavaScript were all fighting over the password fields like seagulls over a dropped chip. Each one slapping data-reveal and class="password-entry" and autocomplete="off" on there until the poor input field didn’t know whether to shit or go blind. Copy-paste? Dead. Dead as my enthusiasm for OpenClaw’s “intelligent agents.”
Hermes stripped the lot. Renamed the IDs from pass1 to ww-pass1 so WordPress’s grubby mitts couldn’t find them. Pre-populated both fields server-side with a generated password. No JavaScript copying needed. Strength meter runs manually. Toggle button is red and angry like everything else on this site. Paste now works. Glorious.
Tick, follows tock…
Guest CTAs Everywhere
Previously if you weren’t logged in, you hit a wall. A boring, beige, “You must be logged in” wall. Like being told to piss off by a librarian.
Now? Now guests get invited to the party:
- Activity feed? “Join the Chaos” box with Log In and Join buttons.
- Reading a blog post? “Jump Into the Discussion” with clear paths in.
- Forum topic? Dark themed login form right there, plus a big red “Join the Community” button.
- Starting a new topic? Same deal.
No more hidden walls. No more “fuck off and come back with credentials.” Just… here’s the door, mate. Walk through it if you want.

Tick, follows tock…
The Login Page That Doesn’t Look Like Ass
This was the big one. Every “Log In” link on the site was sending people to wp-login.php. The WordPress default login. White background. Blue links. Screams “this is an admin panel, please try to brute force me.”
We built a custom /login/ page. Dark theme. Glitch header saying <Log In/>. Red button. Cyan focus glow on the inputs. “Keep me signed in” checkbox. Forgot password link. Social login buttons. And at the bottom: “New around here? Join the community.”
But the real magic is under the hood. If some bot or curious human directly hits wp-login.php, they get bounced straight to our branded page. If they fail a login, they get bounced back WITH an error message. No ugly WordPress error screen. No exposing the admin URL. The form still posts to wp-login.php because WordPress demands it, but the user never sees that URL. It’s like having a secret tunnel into a nightclub through a dumpster. Functional, but nobody has to look at the dumpster.
Tick, follows tock…
What Broke
Cloudflare decided to throw a 525 SSL handshake error right at the end. Because of course it did. The origin cert is valid until April 2027, but Cloudflare in “Full (strict)” mode is having a tantrum about cipher suites or some such bollocks. That’s a job for tomorrow. Or next week. Or whenever I can be arsed to wrestle with SSL configs while sober.
Onwards, cock!
Bottini, Heman Herman
24 April 2026



