Visibility & Password
Hide a gallery from the public, lock it behind a password, or hide it on particular devices.
Two separate mechanisms share the Advanced Settings → Visibility tab, and they do different jobs.
- Visibility decides who may see the gallery at all.
- Hide on <device> decides where it's shown.
Who can see it
| Setting | What happens |
|---|---|
| Public | Everyone sees it. The default. |
| Password | Visitors see a password form. Enter the right password and the gallery appears, and stays visible on that browser. |
| Private | Only logged-in users who can read private content see it. Everyone else sees nothing at all — no form, no placeholder, no hint that anything is there. |
Choosing Password reveals Set Password.
Using passwords well
Client proofing is the case this exists for: a reusable gallery per client, a password each, the link sent by email. Pair it with Watermark for proofs.
One password per gallery. There's no shared password and no user accounts — this is a simple gate, deliberately.
Changing the password locks everyone out again, including people who had already entered the old one. That's the intended behaviour: it's how you revoke access.
Repeated wrong guesses are throttled, so the form can't be brute-forced by a script.
What a password is and isn't
It keeps a gallery off a public page. It is not file-level security — the image files themselves still live at ordinary URLs on your server, and anyone with a direct link to a file can open it. For anything genuinely sensitive, don't publish it.
Private vs Password
| Private | Password | |
|---|---|---|
| Who gets in | Logged-in users with permission | Anyone with the password |
| What everyone else sees | Nothing | A password form |
| Good for | Staff-only content, work in progress | Client galleries, event photos shared by link |
Where it's shown
Four independent toggles, all off by default:
| Toggle | Hides the gallery when |
|---|---|
| Hide on Desktop | The viewport is 1025 px wide or more. |
| Hide on Tablet | The viewport is 601–1024 px wide and at least 601 px tall. |
| Hide on Mobile Portrait | The viewport is 600 px wide or less, in portrait. |
| Hide on Mobile Landscape | The viewport is 1024 px wide or less, 600 px tall or less, in landscape. |
Why height is part of it
Width alone can't tell a phone in landscape from a tablet. A modern phone turned sideways is about 850 px wide — squarely inside a naive "tablet" band — but only about 400 px tall. A tablet in landscape is wide and tall.
Adding the height condition is what makes the four bands cover the whole range without overlapping, so Hide on Tablet hides tablets and not phones, and Hide on Mobile Landscape actually fires on the phones it exists for.
Use these for device-specific alternatives
The classic pattern: one Perspective gallery hidden on all three mobile bands, and a simple Grid gallery hidden on desktop. Visitors get the spectacle on a big screen and something fast on a small one.
In the editor
A hidden gallery isn't removed from the canvas — it's dimmed and outlined, with a badge naming which devices it's hidden on. Otherwise you couldn't select it to switch the option back off.
The badge names Mobile Landscape in words even though WordPress has no preview for it.
Things worth knowing
Both mechanisms apply to the shortcode too. A reusable gallery set to Private or Password behaves the same wherever its shortcode is placed.
Private is a real capability check, not a CSS trick — the gallery's HTML isn't sent at all to someone who shouldn't see it.
Hide on <device> is CSS. The markup is still in the page; it just isn't displayed. That means it isn't a privacy feature — use Private or Password for that — and it means the images may still be fetched on a device where the gallery is hidden. Don't use it as a performance measure.