Who can log into your website? A ten-minute audit

Every account with access to your site is a door. Most sites we look at have a few nobody remembers opening.

Log into WordPress, go to Users, and look down the list. Most site owners have not done this since the site launched. Somewhere on that list is an agency that finished the job in 2022, a plugin’s support account from an install three years ago, or a login the whole office has shared since nobody remembers when. Each one can publish, edit or delete, exactly as if it were you.

This takes ten minutes and needs nothing installing.

Go to Users and read the list properly

Users → All Users in your WordPress admin. Ignore the avatars and the display names for a moment and look at three columns: username, email address and role.

The email address is the useful one. A username can be anything. An email address tells you whose inbox gets the password reset link, which is closer to who controls the account. If it points at a developer who left, an agency’s shared inbox, or a domain you do not recognise, that account belongs to someone else now, whatever the display name says.

Sort by role. That is where the risk sits.

What each role can do

WordPress ships five roles, and the names undersell how much distance sits between them.

  • Administrator. Everything. Install and delete plugins, edit any page, add and remove other users, edit theme files directly from the admin screen. A plugin editor is a way to run any code on your server, from inside your browser.
  • Editor. Publish and edit any post or page on the site, including ones somebody else wrote. Cannot touch plugins, themes or users.
  • Author. Publish and edit their own posts only.
  • Contributor. Write posts, cannot publish them. Somebody else has to approve.
  • Subscriber. Log in, manage a profile, nothing else. WooCommerce and membership plugins use this for customer accounts, which is why a site can have hundreds of them and that is normal.

The gap that catches people out is between Editor and Administrator. Editor sounds senior. It cannot install a plugin or add a user, which are the two things that matter most for security. If somebody only needs to run the blog, Editor does the job without handing over the keys to the server.

The four logins that should not still be there

An agency or freelancer who finished the job. Whoever built the site needed admin access to build it. Once it launched, they did not. A developer relationship ending well is exactly when this gets forgotten, because nobody is angry enough to think about access.

A plugin’s own support account. Some plugins create a WordPress user during setup so their support team can log in and help you directly, usually with a name like the plugin’s own. Useful during a support ticket. Left active afterwards, it is a permanent administrator account belonging to a company you have no ongoing relationship with.

A shared office login. One password, several people, used because setting up individual accounts felt like a faff. Nobody can tell you who published a change or clicked a link in a phishing email, because the account could have been any of them. When someone leaves the business, changing the shared password means telling everyone left, which is exactly the step that gets put off.

An account you do not recognise at all. This is the one to treat as urgent rather than tidying. A hacked WordPress site is a common way for an attacker to add a new administrator with a plausible-looking name, so they can walk back in after the obvious hole gets patched. If a name on that list means nothing to you and nobody in the business can explain it, suspend it now and read the rest of the site for anything else out of place before you do anything else.

What to do with each one

Do not delete an account you are unsure about. Deleting removes the audit trail of what that account did, and WordPress will ask you to reassign or bin their content on the way out, which is not a decision to make in a hurry.

Change the role instead. Drop anyone who does not need to install plugins or manage other users down to Editor or Author. That single change closes most of what an old login could do if the password ever leaked, without deciding anything permanent.

For an account finished with, drop it to Subscriber rather than deleting it straight away. That strips every permission while keeping the record of what the account did, so you can delete it properly once you are sure nothing else refers to it. For a shared login, split it into named accounts, one per person, each with the role that person needs. It costs five minutes per person and means the next audit takes five minutes instead of an afternoon.

For the account nobody recognises, change the WordPress admin passwords for every account that should stay, and if the business has never enabled two-factor authentication for administrators, this is the point to do it.

Put a date on the next one

An audit that happens once is worth doing once. The accounts that cause problems are the ones added for a reason that made sense at the time and then never removed, so the fix is a habit rather than a one-off clean-up. Put a reminder in the calendar every six months: open Users, read the list, ask whether each administrator still needs to be one.

If you would rather this sat on somebody else’s list, it is one of the checks in our free website review, and ongoing account hygiene is part of what our Care & Hosting covers at £49 a month.

Would you rather somebody sorted this for you?

We look after websites for £49 a month — hosting, updates, backups, security and small changes. Moving an existing site over is free. Or get a free review first and we will tell you what is actually wrong with the one you have.

Get a free website review See Care & Hosting