Too many keys to the kingdom — every administrator account is a potential entry point for attackers. Most of your users don't need full admin access.

Why This Matters

Administrator accounts can:

  • Install and delete plugins (including malicious ones)
  • Edit theme files (inject code)
  • Create and delete other admin accounts
  • Access the database through plugins
  • Change critical settings

Each admin account is a target. If any admin uses a weak password, reuses passwords, or falls for a phishing email, your entire site is compromised.

WordPress User Roles Explained

Role Can Write Can Publish Can Manage Plugins Can Manage Users
Subscriber No No No No
Contributor Draft only No No No
Author Yes Own posts No No
Editor Yes All posts No No
Administrator Yes All Yes Yes

Most people who have admin access only need Editor access.

How to Fix It

  1. Go to Users → All Users
  2. Filter by Administrator role
  3. For each admin, ask: "Does this person need to install plugins or manage the site?"
  4. If no → Click Edit on their profile and change their role to Editor or Author
  5. Keep only 1–2 administrator accounts

Who Should Be Admin?

  • The site owner — always keeps admin access
  • The primary developer/maintainer — needs it for plugin/theme management
  • That's usually it

Content writers, marketing team, guest bloggers — they all work fine as Editors or Authors.

What to Watch For

  • Some plugins require admin privileges to configure. That's fine — configure them with your admin account, then everyone else uses their Editor account for daily work.
  • If you're an agency managing client sites, use a single admin account and give clients an Editor account. This prevents accidental damage.
  • Consider adding two-factor authentication (2FA) for all remaining admin accounts using a plugin like WP 2FA or Wordfence Login Security.