Skip to content

Bits of .NET

Daily micro-tips for C#, SQL, performance, and scalable backend engineering.

  • Asp.Net Core
  • C#
  • SQL
  • JavaScript
  • CSS
  • About
  • ErcanOPAK.com
  • No Access
  • Privacy Policy
Wordpress

WordPress: Understand User Roles and Capabilities for Better Security

- 07.06.26 - ErcanOPAK

👥 Never Give Admin to Everyone

Admin has all powers. User roles limit access. Editor writes, Author edits own, Subscriber reads only. Least privilege principle.

📝 Default Roles

Administrator:
- Full control over site
- Add/delete users, install plugins, edit themes
- Risk: Can break everything

Editor:
- Publish and manage all posts/pages
- Moderate comments, manage categories
- Cannot install plugins or change theme

Author:
- Publish and manage own posts
- Upload files
- Cannot edit others' posts

Contributor:
- Write and edit own posts (not published)
- No upload rights
- Editor/Admin must publish

Subscriber:
- Read-only access
- Manage own profile only

🎯 Custom Roles

// Add custom role
add_role('store_manager', 'Store Manager', array(
    'read' => true,
    'edit_products' => true,
    'publish_products' => true,
    'edit_orders' => true
));

// Check capabilities
if (current_user_can('edit_products')) {
    // Show product editor
}

// Capability check in template
if (is_user_logged_in() && user_can($user_id, 'publish_posts')) {
    echo '<a href="post-new.php">New Post</a>';
}

💡 Best Practices

  • Only 1-2 Administrator accounts (use for maintenance only)
  • Regular users as Subscriber or Contributor
  • Use plugins to audit user capabilities
  • Never give admin to untrusted users

“Content writer accidentally deleted plugin. Changed role to Author (can’t access plugins). Problem solved. Least privilege saves headaches.”

— WordPress Security Consultant

Related posts:

WordPress — REST API Auth Failures Behind CDN

WP-Cron Runs on User Requests (Not Real Cron)

WordPress: Use WP-CLI for Command-Line Site Management

Post Views: 0

Post navigation

Photoshop: Use Match Color to Unify Colors Across Photos
Kubernetes: Use Namespaces to Organize Your Cluster

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

June 2026
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
2930  
« May    

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (953)
  • How to add default value for Entity Framework migrations for DateTime and Bool (882)
  • Get the First and Last Word from a String or Sentence in SQL (838)
  • How to select distinct rows in a datatable in C# (808)
  • How to make theater mode the default for Youtube (804)
  • Add Constraint to SQL Table to ensure email contains @ (580)
  • How to enable, disable and check if Service Broker is enabled on a database in SQL Server (579)
  • Average of all values in a column that are not zero in SQL (538)
  • How to use Map Mode for Vertical Scroll Mode in Visual Studio (505)
  • Find numbers with more than two decimal places in SQL (454)

Recent Posts

  • C#: Use String Interpolation Instead of Concatenation
  • C#: Use Tuples to Return Multiple Values from Methods
  • SQL: Use ISNULL and NULLIF for Smart NULL Handling
  • .NET Core: Use Data Annotations for Model Validation
  • Git: Use Git Clean to Remove Untracked Files
  • Ajax: Add Custom Headers to Fetch Requests
  • JavaScript: Use console.table to Display Arrays as Tables
  • HTML: Use Spellcheck Attribute to Enable Browser Spell Check
  • CSS: Use user-select to Prevent Text Selection
  • Windows 11: Use Snipping Tool for Instant Screenshots

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (953)
  • How to add default value for Entity Framework migrations for DateTime and Bool (882)
  • Get the First and Last Word from a String or Sentence in SQL (838)
  • How to select distinct rows in a datatable in C# (808)
  • How to make theater mode the default for Youtube (804)

Recent Posts

  • C#: Use String Interpolation Instead of Concatenation
  • C#: Use Tuples to Return Multiple Values from Methods
  • SQL: Use ISNULL and NULLIF for Smart NULL Handling
  • .NET Core: Use Data Annotations for Model Validation
  • Git: Use Git Clean to Remove Untracked Files

Social

  • ErcanOPAK.com
  • GoodReads
  • LetterBoxD
  • Linkedin
  • The Blog
  • Twitter
© 2026 Bits of .NET | Built with Xblog Plus free WordPress theme by wpthemespace.com