Skink Insights - WordPress

Who Should Have Admin Access to Your WordPress Website?

By

As few people as possible. For most Australian small businesses, that means one administrator, or two at most: the site owner and the person or agency who maintains the site. Everyone else who works on the website, whether they write blog posts, update product photos or check enquiries, should have a lower level of access that matches what they actually do. WordPress makes this easy with built-in user roles, yet most sites we inherit have four or five full administrators and nobody can remember why.

Here is how the roles work, why too many admins is a genuine risk, and how to tidy things up in ten minutes.

What each WordPress role can actually do

WordPress ships with five standard roles, and each one is a superset of the one below it:

  • Administrator can do everything: install plugins, change themes, delete content, add and remove other users, and even delete the whole site.
  • Editor can publish, edit and delete any post or page, including other people’s. Ideal for whoever runs your content.
  • Author can write, publish and manage their own posts only. Good for regular contributors.
  • Contributor can draft posts but cannot publish them. Someone with more access approves their work first.
  • Subscriber can only manage their own profile. Mostly used for membership or comment features.

If you run a WooCommerce store there is also a Shop Manager role, which can manage products and orders without touching plugins or settings. It is the right choice for staff who look after the shop day to day.

Why too many administrators is a risk

Every administrator account is a set of keys to the whole site. The more sets of keys floating around, the more ways in for an attacker. If a staff member reuses a password that leaks in a data breach somewhere else, and that account is an admin, your entire website is exposed. With an Editor account, the damage is limited to content.

Admin accounts also make honest mistakes more expensive. A well-meaning colleague clicking update on a plugin at the wrong moment, or deactivating something they did not recognise, can take a site down. Giving people the smallest role that lets them do their job is the same principle good IT teams use everywhere, and it is one of the simplest steps in keeping a WordPress site secure.

How to tidy up your users in ten minutes

Log in and go to Users in the WordPress dashboard, then work through this checklist:

  1. Delete accounts for anyone who no longer works with you, including old developers and past staff. WordPress will ask what to do with their content; assign it to another user rather than deleting it.
  2. Downgrade anyone who only writes or edits content to Editor or Author.
  3. Keep one admin for the owner and one for whoever maintains the site. If an agency looks after your updates and backups, they need admin access; a casual blogger does not.
  4. Make sure every remaining account has a strong, unique password, and turn on two-factor authentication for administrators.
  5. Check that no account is named admin. It is the first username attackers try.

When you might need something more tailored

Sometimes the standard roles are not quite right. You might want a role that can edit pages but not blog posts, or manage bookings without seeing orders. Custom roles and permissions are a common part of our WordPress development work, and for bigger builds our parent studio Defyn handles the heavier custom engineering. Done properly, a tailored role gives each team member exactly the dashboard they need and nothing they do not.

User access is also one of the things we review on every site we take on. If you are not sure who has keys to your website, that is usually a sign it is time for a check-up as part of ongoing website care.

Not sure who has access to your site?

We can audit your users, tighten up access and set your site up so it stays secure. Call us on 02 9834 4119 or get in touch for a friendly chat.

Rachael Orlando

Need a WordPress website, theme or plugin built properly? We would love to help.

Start a project