Skink Insights - WordPress

Who Should Have Admin Access to Your WordPress Website?

By

Very few people. As a rule, one or two trusted people inside your business should hold Administrator access, plus whoever looks after the site technically. Everyone else should get the smallest role that still lets them do their job. WordPress has five built-in user roles for exactly this reason, and handing out Administrator to every staff member is one of the quietest ways a site ends up broken, cluttered or hacked.

Here is how the roles work and how to decide who gets what.

The five WordPress roles in plain English

  • Administrator. Total control. Can install and delete plugins, edit theme files, change every setting, and add or remove other users, including you.
  • Editor. Can write, edit, publish and delete any post or page, and moderate comments. Cannot touch plugins, themes or settings.
  • Author. Can write and publish their own posts, and upload images. Cannot edit anyone else’s work.
  • Contributor. Can write and edit their own drafts but cannot publish them or upload images. Someone else has to press publish.
  • Subscriber. Can only manage their own profile. Useful for membership sites and not much else.

If you run a store, WooCommerce adds two more. Shop Manager can handle products, orders and coupons without being an Administrator, which is usually the right role for the person packing your parcels. Customer is just an account holder.

Why extra Administrators are a risk

Most trouble we get called in to fix is not malicious. It is a well meaning person clicking update on a plugin at the wrong moment, deactivating something that turns out to be holding the layout together, or deleting a page that was quietly driving enquiries.

The security side matters too. Every Administrator account is another password an attacker can guess, or another person who might click a convincing phishing email. Automated bots try admin logins on Australian small business sites constantly. Fewer admin accounts means fewer doors.

There is also a plain accountability benefit. When three people have admin access and something changes, nobody is quite sure who did it. When two people do, you can ask.

A simple way to decide

Ask one question about each person: what is the smallest thing they actually need to do? Then match it.

  • Writes blog posts and updates the About page: Editor.
  • Writes their own articles only: Author.
  • A guest writer or a student on placement: Contributor.
  • Manages products and orders in your store: Shop Manager.
  • Runs the business and needs the keys: Administrator.
  • Just wants to see the numbers: no WordPress account at all. Give them access in Google Analytics instead.

You can always promote someone later. It is much harder to undo a bad afternoon.

Ten minutes of housekeeping, twice a year

  • Open Users in your dashboard and read the list properly. Do you recognise every name?
  • Remove accounts for people who have left. When you delete a user, WordPress asks whether to reassign their posts. Say yes, or the content goes with them.
  • Never share one login between staff. Individual accounts cost nothing and tell you who did what.
  • Turn on two-factor authentication for every Administrator. It is the single biggest improvement you can make in five minutes.
  • Use long, unique passwords stored in a password manager, not a shared spreadsheet.
  • Avoid a username of “admin”. Bots try it first.

What about your web developer?

Your developer or maintenance provider does need Administrator access, and they should have their own named account rather than borrowing yours. That way you can see their changes in the logs, and you can remove their access cleanly when a project finishes or you decide to move on. If anyone tells you that you cannot have your own admin account on your own site, that is a red flag worth acting on.

Sensible roles work best alongside the rest of the basics: regular backups, prompt updates and hosting that is actually looked after. We cover that side of things in our WordPress development and ongoing care work, and you can see the full range on our services page. Skink is part of the Defyn family of studios, so there is always someone around who knows your site.

Not sure who has access to your site?

If you have inherited a website and have no idea who is still holding a key, we can audit your users, tidy the roles and lock things down without disrupting your team. Give us a ring on 02 9834 4119 or get in touch and we will take a look.

Rachael Orlando

Need a WordPress website, theme or plugin built properly? We would love to help.

Start a project