If more than one person works on your WordPress website, user roles become important. Roles control what each person can see and do, from writing drafts to installing plugins. Giving everyone administrator access might seem convenient, but it increases security risks and the chance of accidental changes.
This guide explains WordPress’s default user roles, their capabilities and best practices for managing users securely.
Default WordPress Roles
| — | — | — |
|---|---|---|
| Administrator | Full control: settings, plugins, themes, users, content | Site owner, trusted technical manager |
| Editor | Publish and manage all posts and pages, moderate comments | Content managers |
| Author | Write, edit, publish and delete their own posts, upload media | Regular writers |
| Contributor | Write and edit their own posts but cannot publish or upload media | Guest writers, new team members |
| Subscriber | Manage their own profile | Members, registered readers |
Administrator
Administrators can change everything, including themes, plugins, settings and other users. Limit this role to as few people as possible. A compromised administrator account can affect the whole site.
Editor
Editors manage content across the site. They can publish, edit and delete any post or page, manage categories and moderate comments, but cannot change plugins, themes or settings. Ideal for content managers.
Author
Authors can write and publish their own posts and upload images. They cannot edit others’ posts. Suitable for trusted regular writers.
Contributor
Contributors can write and edit their own drafts but cannot publish or upload media. An editor reviews and publishes their work. Useful for guest writers and new team members.
Subscriber
Subscribers can log in and manage their profile. Used for membership sites or comment registration.
How to Add a User
- Go to Users → Add New
- Enter username, email and optional name
- Generate a strong password or send a password setup link
- Choose the appropriate role
- Click Add New User
Best Practices for Managing Users
- Least privilege: give users only the access they need
- Unique accounts: never share login details between people
- Strong authentication: require strong passwords and two-factor authentication for privileged roles
- Regular reviews: remove users who no longer work on the site
- Correct emails: use work email addresses you can recover
- Content attribution: when removing a user, reassign their content to another user
Custom Roles and Capabilities
Plugins can create custom roles or adjust capabilities, such as allowing an SEO specialist to edit SEO settings without full administrator access. Use reputable role management plugins and document custom permissions.
Role Assignment Examples
| — | — |
|---|---|
| Developer (temporary) | Administrator during project, then remove |
Security Risks of Poor User Management
- Former employees retaining access
- Too many administrators increasing attack surface
- Shared passwords that cannot be traced to individuals
- Weak passwords on high-privilege accounts
- Unknown accounts created by attackers
Review your Users list regularly and investigate unfamiliar accounts immediately.
Removing Users Safely
When deleting a user, WordPress asks whether to delete or reassign their content. Usually, reassign posts to another user to keep them published. Consider downgrading roles instead of deleting if you may need the account later.
Common Mistakes
- Making every team member an administrator
- Leaving old freelancer accounts active
- Sharing one login among several people
- Using personal email addresses that may become inaccessible
- Not enabling two-factor authentication for administrators
Real-World Example
A small news blog gave all six writers administrator access. One writer accidentally deactivated a key plugin, breaking the homepage during peak traffic. The owner restructured access: one administrator, one editor and authors for the rest, enabled two-factor authentication for privileged roles and removed old accounts. Accidental site-wide changes stopped completely.
Frequently Asked Questions
How many administrators should a site have?
As few as possible, often one or two trusted people.
Can contributors upload images?
Not by default. Editors can add images, or you can adjust capabilities with a plugin.
What role should a guest writer have?
Contributor is usually best, allowing drafts without publishing rights.
Can I change a user’s role later?
Yes, from the Users screen.
What happens to posts when a user is deleted?
You can delete them or reassign them to another user. Reassigning is usually safer.
How do I spot suspicious users?
Look for unfamiliar usernames, emails or recently created administrator accounts.
Conclusion
WordPress user roles help you collaborate safely. Assign the lowest role needed, protect privileged accounts with strong authentication, review users regularly and remove access when it is no longer required. Thoughtful user management protects your content and your website’s security.