Open dashboard doors
- —Every non-admin account can reach /wp-admin
- —Former contractors remain an access risk
- —Blocked users receive inconsistent feedback
Set a clear boundary around wp-admin without redesigning WordPress roles. This guide shows how to keep the dashboard available to administrators and explicitly trusted users.
WordPress accounts do not always need dashboard access. UserFlow adds a clear boundary without forcing a role redesign.
UserFlow keeps the default secure and gives site owners a small set of focused controls for exceptions.
Allow specific non-admin users to access the dashboard without changing their role.
Set a session timeout from 1 to 24 hours and apply it to all users or only non-admins.
Keep the WordPress backend out of the frontend view for unauthorized users.
Send blocked visitors to a branded page, login screen, or help document instead of a generic error.
The secure default works immediately, while the settings screen handles trusted exceptions and messaging.
Install UserFlow from the WordPress plugin directory and activate it.
Non-admin users are blocked from /wp-admin immediately after activation.
Open Settings → UserFlow and whitelist the usernames that need dashboard access.
Choose a custom redirect URL and configure session timeouts, then save.
No. You can whitelist trusted usernames while leaving their existing WordPress roles unchanged.
Yes. UserFlow is designed to protect non-admin dashboard access while administrators retain access.
Yes. Configure a custom redirect URL for a branded landing page, login screen, or help document.
Review the plugin features, requirements, and other implementation guides, or install it directly from WordPress.org.