Мазмунга өтүү
WordPress.org

Кыргызча

  • Темалар
  • Плагиндер
  • Биз тууралуу
  • Байланыш
  • WordPress'ти жүктөп алыңыз
WordPress'ти жүктөп алыңыз
WordPress.org

Plugin Directory

UserFlow – Disable Dashboard Access for Non Admin

  • Submit a plugin
  • My favorites
  • Кирүү
  • Submit a plugin
  • My favorites
  • Кирүү

UserFlow – Disable Dashboard Access for Non Admin

Автору Ga Satrya
Жүктөө
Көрүү
  • Кенен маалымат
  • Сын-пикирлер
  • Орнотуу
  • Development
Колдоо

Сүрөттөө

Remove dashboard access to non-admin users and easily control who can access your WordPress dashboard with simple configuration. By default, only administrators are allowed, but you can now whitelist specific trusted users by username—perfect for developers, VAs, or contractors.

Features include:

  • Whitelist specific users by username
  • Session expiration controls (1-24 hours)
  • Optional separate session timeout for administrators
  • Custom redirect URL for blocked users
  • Secure, validated, and sanitized settings
  • Hide admin toolbar for non-authorized users
  • Developer-friendly filters for advanced customization

Why Choose UserFlow?

  • Maximum Protection: Instantly block unauthorized users from accessing sensitive dashboard areas.
  • Effortless Whitelisting: Grant dashboard access to trusted users (developers, VAs, contractors) without changing their roles. Just add their usernames!
  • Session Security: Set session expiration from login, with an optional separate timeout for administrators. Choose from multiple intervals or enter a custom duration.
  • Custom Redirects: Guide blocked users to a branded page or helpful resource instead of the generic homepage.
  • Zero Configuration Needed: Works out of the box—only administrators can access the dashboard until you customize settings.

Perfect For:

  • Website owners who want peace of mind
  • Agencies and developers managing multiple sites
  • Teams needing granular dashboard access
  • Anyone serious about WordPress security

Protect your site, empower your workflow, and deliver a professional experience—all with one lightweight plugin.

Read more detail

Скриншоттор

Plugin settings
Plugin settings

Орнотуу

  1. In your WordPress dashboard, go to Plugins > Add New and search for “UserFlow” (by Ga Satrya), or upload the plugin ZIP file.
  2. Install and activate the plugin. By default, only administrators can access the dashboard.
  3. Go to Settings > UserFlow to allow specific users, set a redirect URL, or configure session timeouts. Save your changes.

Сын-пикирлер

Simple and to the point

esamzenhom Ноябрь 25, 2024-ж. 1 reply
I'm Wondering how their are no reviews for this plugin, but really its as simple as it is, very effective 🙂 thanks for the developer
Read all 1 review

Contributors & Developers

“UserFlow – Disable Dashboard Access for Non Admin” is open source software. The following people have contributed to this plugin.

Мүчөлөрү
  • Ga Satrya

Translate “UserFlow – Disable Dashboard Access for Non Admin” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Өзгөртүүлөр

1.3.3

  • Added: Optional administrator-specific session timeout (1-168 hours), with the general timeout as the default.
  • Improved: Clarified that session expiration is measured from login, not inactivity.

1.3.2

  • Updated WordPress compatibility declaration through version 7.1.

1.3.1

  • Security: Hardened settings reset handler with request-method check and nonce improvements.
  • Improved: Replaced per-username DB queries with single batched query for settings save performance.
  • Improved: Added explicit access-control fallthrough logic and removed stale static cache.
  • Improved: Separated settings-page capability filter from dashboard-access filter.
  • Improved: Settings sanitization now guarantees consistent option shape on save.
  • Improved: Added meta-refresh fallback when redirect headers cannot be sent.
  • Improved: Username validation errors now show count only to prevent enumeration.
  • Added: Plugin uninstall handler to clean up stored options on deletion.
  • Added: AJAX bypass behavior documented in settings help tab.
  • Added: Sidebar promotion box for developer services.
  • Dev: Improved test mock fidelity for wp_validate_redirect and WP_User_Query.
  • Dev: Fixed Composer license to valid SPDX identifier.

1.3.0

  • Rebranding: Formally renamed the plugin to UserFlow.
  • Added: Support for WordPress 7.0.
  • Refactor: Moved inline JavaScript and CSS to external files for better security and maintainability.
  • Improved: Updated settings sidebar to connect with the developer on LinkedIn.
  • Improved: Settings page formatting and code structure.
  • Improved: Updated settings labels for better clarity.
  • Improved: Use wp_validate_redirect for more robust same-site URL validation.
  • Added: admon_access_capability filter for developer customization of access rights.
  • Fix: Updated make-pot composer script for Windows compatibility.

1.2.5

  • Performance: Optimized access checks with static caching (memoization) to reduce redundant processing.
  • Fix: Ensured settings errors and success messages are correctly displayed on the settings page.
  • Improved: Better UI feedback when saving or resetting settings.
  • Improved: Added GitHub Actions automated deployment for WordPress.org SVN.
  • Assets: Added new plugin banners and icons for the WordPress.org repository.

1.1.1

  • Security Fix: Patched Open Redirect vulnerability in URL validation logic.
  • Improved: Stricter validation for custom redirect URLs.
  • Improved: Added Contextual Help tabs in settings page.

1.1.0

  • Added session timeout management with configurable intervals (1-24 hours)
  • Added custom timeout duration option (1-168 hours)
  • Added username whitelist for granting dashboard access to specific non-admin users
  • Added custom redirect URL for blocked users
  • Added option to apply session timeout to administrators
  • Added “Remember Me” override functionality
  • Enhanced security with proper input sanitization and validation
  • Improved user interface with comprehensive settings page
  • Added reset to defaults functionality
  • Updated to follow WordPress coding standards

1.0.0

  • First version

Мета

  • Нуска 1.3.3
  • Акыркы жаңыртуу 1 жума мурун
  • Активдүү орнотуулар 40+
  • WordPress нускасы 6.5 же андан жогору
  • Tested up to 7.1.2
  • PHP нускасы 7.0 же андан жогору
  • Тил
    English (US)
  • Тег:
    accessdashboardloginmembershiprestrict
  • Advanced View

Рейтинг

5 out of 5 stars.
  • 1 5-star review 5 жылдыз 1
  • 0 4-star reviews 4 жылдыз 0
  • 0 3-star reviews 3 жылдыз 0
  • 0 2-star reviews 2 жылдыз 0
  • 0 1-star reviews 1 жылдыз 0

Your review

See all reviews

Мүчөлөрү

  • Ga Satrya

Колдоо

Комментарийлер барбы? Жардам керекпи?

Колдоо форумун көрүү

Кайрымдуулук

Would you like to support the advancement of this plugin?

Кайрымдуулук кылуу

  • Биз тууралуу
  • Жаңылыктар
  • Хостинг
  • Купуялык
  • Көргөзмө
  • Темалар
  • Плагиндер
  • Паттерндер
  • Үйрөнүү
  • Колдоо
  • Иштеп чыгуучулар
  • WordPress.tv ↗
  • Кошулуу
  • Иш-чаралар
  • Кайрымдуулук ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Кыргызча

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Биздин Mastodon түрмөгүбүзгө баш багыңыз
  • Visit our Threads account
  • Биздин Facebook баракчабызга кириңиз
  • Биздин Instagram баракчабызга баш багыңыз
  • Биздин LinkedIn баракчабызга баш багыңыз
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Код деген бул — поэзия.
The WordPress® trademark is the intellectual property of the WordPress Foundation.