WordPress user roles security: least privilege without guesswork
Every WordPress account is a way in, and its role decides how far in. An administrator can install plugins, change settings and manage users. A subscriber can read. WordPress user roles security comes down to keeping that gap in mind: each account gets the role its work needs, and no more.
Sites drift away from that over time. A contractor keeps an administrator account after the job ends, a plugin widens what a role may do, registration hands out more than reader access. This guide shows what BetterShield checks about roles and accounts, how to require two-factor by role, and how role changes reach you.
Quick summary
- The audit’s Access area includes checks for an account named “admin”, the first account still being an administrator, dormant administrators, open registration into a powerful role, and roles that may publish unfiltered code.
- BetterShield does not set a number of administrators. It flags the accounts worth a second look, such as dormant administrators.
- Require two-factor of a role on BetterShield › Protect › Two-Factor asks the roles you pick to set up two-factor, after a 14-day grace period by default.
- A role change involving a role that can manage settings or users is rated High and emailed as it happens.
- Keep low-privilege accounts out of the dashboard sends roles such as Subscriber back to the front page.
Least privilege in WordPress, in plain terms
A WordPress role is a named set of capabilities. Out of the box there are five on a single site: Administrator, Editor, Author, Contributor and Subscriber. Plugins can add roles of their own and change what any role may do.
Least privilege means choosing the lowest role that does the job:
- Administrator for the people who install plugins, change settings or manage users.
- Editor for people who publish and manage everyone’s content.
- Author or Contributor for people who write their own posts.
- Subscriber, or a store’s customer role, for everyone who only needs an account.
Too many administrators? How to check
There is no right number, and BetterShield does not invent one. Start with the list: open Users and choose the Administrator filter, or run wp user list --role=administrator.
For each name, ask one question: does this person install plugins, change settings or manage users? If not, a lower role will do. If you are not sure whether they still need access at all, the audit can help, as below.
With an AI assistant connected, it can read users and roles by display name, so “who are my administrators?” is a question it can answer. See Connect an AI assistant.
WordPress user roles security: the Access checks
These findings appear on BetterShield › Findings. Each one changes nothing by itself; it tells you what to look at.
| Finding | Severity | What to do |
|---|---|---|
| Anyone can register, and new accounts get more than reader access | High | Set the default role to Subscriber, or turn off registration. Open the membership setting goes there. |
| An account that can change this site has not been used for a long time | Medium | Remove or demote accounts nobody uses. Open Users goes there. |
| Some administrator passwords use an older storage format | Medium | Ask each person to sign in once. WordPress stores the password the newer way as they do. |
| Some accounts signed in with passwords below the policy | Low or Medium | Ask them to choose a new password. Nobody is forced or locked out. |
| A user is named “admin” | Low | Create a new administrator with another name, then delete this one and reassign its content. |
| The first account created is still an administrator | Low | The same, because renaming the account does not change its number. |
| A role below administrator may publish unfiltered code | Low | Remove the capability with a role editor, or set DISALLOW_UNFILTERED_HTML in wp-config.php, which takes it from everybody. |
| Application passwords that nothing has used for months | Low | Revoke the stale ones. Open the agent surface lists them. |
Two more sit in the Exposure area: Accounts below administrator may upload files that can carry script, and An ability that changes the site is open to low-privilege users. Both mean a lower role can do more than its name suggests. All 54 checks are on the checklist.
Dormant administrators
The dormant-account check looks at the accounts that can manage the site. If one has not been used for 180 days, by signing in or by any other sign of use, such as an application password, it is named in the finding, up to ten names with a total.
It stays quiet until BetterShield itself has been active for longer than 180 days, because before then it cannot tell a dormant account from one it has not seen yet. It never removes or demotes anyone. In its own words: “Removing or demoting an account is yours to do, because getting it wrong locks out somebody who was on leave.”
Unfiltered code below administrator
WordPress gives Editors unfiltered HTML on a single site, and the check leaves that default alone. Any other role below administrator that holds the capability, and has an account in it, is reported. Some plugins grant it on purpose, so check what the role is for first.
Require two-factor by role
Roles that can change the site should not rely on a password alone. On BetterShield › Protect › Two-Factor, under What the site requires:
- In Require two-factor of a role, tick the roles, such as Administrator and Editor.
- Set Grace period, in days: 0 to 90, counted from when each account first meets the requirement. The default is 14.
- Press Save requirement.
In the screen’s words: “They keep working normally during the grace period, and see a countdown; after it, the dashboard takes them to the enrollment screen until they have.” Signing in is never blocked by it, and safe mode stands it down. Adding a role first checks that your recovery link or printed recovery codes work.
Sign in with a passkey only goes further for the roles you tick: once an account has added a passkey, its password stops signing it in. A line per role shows how many accounts have one. See Two-factor and passkeys, and on a network, Multisite networks.
Role-change alerts and the activity log
Every role change is written to the activity log as “Role changed”, “Role granted” or “Role removed”. A change to what a role may do is recorded as “What a role may do changed”, with the role and the capabilities named.
The severity follows the power involved:
- A role change that gives or takes away a role able to manage settings or users is High.
- A new administrator or editor account, or one deleted, is High.
- A change to what a role may do is usually High, because it changes every account in that role at once.
- Moves between ordinary roles, such as a membership changing a customer’s level, are Medium and wait for the weekly summary.
High events are emailed as they happen, so a new administrator reaches your inbox the same day. See Email alerts. An account given a privileged role can also open an incident, joined by related changes around it. See Incidents.
To keep the earlier value of such changes, turn on Record supported previous values in the log’s Previous values and reversible responses panel. A change to what a role may do, or a new administrator, recorded after that offers Review change. With Ultra, Suspend this account stops a new administrator signing in without deleting anything.
Keep low-privilege accounts out of the dashboard
Subscribers and customers have no work in wp-admin. Keep low-privilege accounts out of the dashboard, under Signing in on Protect › Login & Access, sends the roles you choose to the front page, with Subscriber preselected. They keep their own profile, where their password, two-factor and signed-in devices are.
It never applies to a role that can manage the site or has work in the dashboard. Monitor first can count the dashboard requests it would turn away before you enforce it. See Hardening.
If you use Ultra
Ultra adds a few role tools for people who look after sites for others. Ultra › Temporary access gives someone a role for anything from an hour to thirty days, then puts their previous roles back on its own, and never removes the last administrator. Ultra › Sign-in report shows two-factor and passkey coverage per role, with a CSV export. And once a required role’s grace period is up, Ultra opens the enrollment screen at the next sign-in, right after the password.
Common mistakes
- Promoting someone “just for today”. Promotions are easy to forget. Note it somewhere you will see it, and take it back.
- Deleting an account without reassigning its content. WordPress asks what to do with the posts. Choose another account.
- Requiring two-factor with no recovery in place. Check your recovery link and printed codes first. BetterShield checks them when you add a role.
- Leaving registration open with a writing role. Set the default role to Subscriber unless the site needs more.
Frequently asked questions
How many administrators should a WordPress site have?
As few as the work needs, usually the people who install plugins, change settings or manage users. BetterShield does not set a number, but it flags dormant administrators and an account named “admin”.
Can BetterShield change a user’s role for me?
Not on its own. The audit only reports, and never removes or demotes anyone. An incident’s response plan can remove an account’s roles when you tick that action and confirm it, and with Ultra, Temporary access and Automatic incident response change roles only as you set them up. An AI assistant can never create accounts or credentials through the connection.
Will requiring two-factor by role lock anyone out?
No. It is enforced in the dashboard after the password, with a grace period, and signing in is never blocked by it. Safe mode stands it down, and the recovery link still works.
Do I get an alert when someone becomes an administrator?
Yes, by default. A new administrator, or a role change involving a role that can manage settings or users, is rated High and emailed as it happens. Muting alerts stops that, and planned maintenance holds such alerts for one summary when it ends.
Conclusion
WordPress user roles security is mostly housekeeping: fewer administrators, no forgotten accounts, and a second factor for the roles that can change the site. BetterShield’s audit points at the accounts to look at, two-factor by role covers the powerful ones, and role-change alerts tell you the day something moves.
BetterShield is free on WordPress.org. The features page shows the rest of its sign-in protection.