Three kinds of gate
“Password protected” can mean three different things. Most failed staging captures come from treating one as another.
| What you see | What it is | Common on |
|---|---|---|
| A browser pop-up asking for a username and password | A server password, also called HTTP basic auth | Agency staging servers and hosting-level protection |
| A login page, or a coming-soon page until you log in | A login form | WordPress in maintenance mode, membership sites |
| A box on the page asking only for a password | A page password | WordPress's built-in page protection |
The coming-soon version trips people up most. The site answers every address normally but shows the placeholder instead of the page. Nothing looks locked, so a screenshot tool captures the placeholder at every URL and calls the run a success. The first sign of trouble is opening the folder and finding the same page thirty times.
With a browser extension
If you can see the page in your own browser, an extension like GoFullPage will capture it, because it photographs the tab you're already signed in to. For a few pages that's the easiest route. It gets slow at scale: every page is a separate visit and capture, at every size you need.
With SiteHaul
SiteHaul has a setting for each kind of gate, under Advanced. It uses them for reading the sitemap as well as for capturing, so staging sites whose sitemap is locked away work too.
Server password (basic auth)
Enter the username and password the browser pop-up asks for. They're sent with every request, the sitemap included.
Site login
Enter the username and password for the site's own login form. SiteHaul signs in once, then captures every page as that user. WordPress logins are found automatically. For anything else, paste the address of the login page as well.
When you press Fetch pages, SiteHaul signs in first and reads the sitemap as that user, so a wrong password shows up straight away, with the site's own error message, before anything is captured. WordPress also draws its admin bar across the top of every page for a logged-in user, and SiteHaul leaves it out of the captures.
Page password
For WordPress's per-page protection, where a page asks for a password and nothing else. SiteHaul only tries it on pages that turn out to be protected.
Use a view-only account
Sign in with a user who can only view the site, such as a WordPress Subscriber, not an administrator. It sees the same pages, and if the password ever leaks, nobody can change the site with it. SiteHaul doesn't save login details or write them into the run folder.
What it can't sign in to
SiteHaul signs in with a username and password. It can't get past single sign-on, a code sent to your phone, or a link emailed to you. For a site behind one of those, capture from your own signed-in browser instead.
It also recognizes Elementor's coming-soon mode on its own and lists those pages as protected instead of capturing the placeholder. Other coming-soon plugins may not be spotted, so if a run comes back as one page repeated, that's the cause, and Site login is the fix.
Why staging is worth capturing
A staging site is where client sign-off happens, and it changes daily. A dated folder of every page at both sizes is a record of what was approved and when. It lets you show a new site in a portfolio before launch, and captured the same day as the live site it makes a fair before and after, which is covered in archiving a website before a redesign.
For everything else about capturing whole sites, start with how to screenshot every page in a sitemap, or see how SiteHaul compares to GoFullPage.