跳至内容
WordPress.org

China 简体中文

  • 主题
  • 插件
  • 新闻
    • 文档
    • 论坛
  • 关于
  • 获取 WordPress
获取 WordPress
WordPress.org

Plugin Directory

UserFlow – Disable Dashboard Access for Non Admin

  • 提交插件
  • 我的收藏
  • 登录
  • 提交插件
  • 我的收藏
  • 登录

UserFlow – Disable Dashboard Access for Non Admin

作者:Ga Satrya
下载
实时预览
  • 详情
  • 评价
  • 安装
  • 开发进展
支持

描述

Remove dashboard access to non-admin users and easily control who can access your WordPress dashboard with simple configuration. By default, only administrators are allowed, but you can now whitelist specific trusted users by username—perfect for developers, VAs, or contractors.

Features include:

  • Whitelist specific users by username
  • Session expiration controls (1-24 hours)
  • Optional separate session timeout for administrators
  • Custom redirect URL for blocked users
  • Secure, validated, and sanitized settings
  • Hide admin toolbar for non-authorized users
  • Developer-friendly filters for advanced customization

Why Choose UserFlow?

  • Maximum Protection: Instantly block unauthorized users from accessing sensitive dashboard areas.
  • Effortless Whitelisting: Grant dashboard access to trusted users (developers, VAs, contractors) without changing their roles. Just add their usernames!
  • Session Security: Set session expiration from login, with an optional separate timeout for administrators. Choose from multiple intervals or enter a custom duration.
  • Custom Redirects: Guide blocked users to a branded page or helpful resource instead of the generic homepage.
  • Zero Configuration Needed: Works out of the box—only administrators can access the dashboard until you customize settings.

Perfect For:

  • Website owners who want peace of mind
  • Agencies and developers managing multiple sites
  • Teams needing granular dashboard access
  • Anyone serious about WordPress security

Protect your site, empower your workflow, and deliver a professional experience—all with one lightweight plugin.

Read more detail

屏幕截图

Plugin settings
Plugin settings

安装

  1. In your WordPress dashboard, go to Plugins > Add New and search for “UserFlow” (by Ga Satrya), or upload the plugin ZIP file.
  2. Install and activate the plugin. By default, only administrators can access the dashboard.
  3. Go to Settings > UserFlow to allow specific users, set a redirect URL, or configure session timeouts. Save your changes.

评价

Simple and to the point

esamzenhom 2024 年 11 月 25 日 1 回复
I'm Wondering how their are no reviews for this plugin, but really its as simple as it is, very effective 🙂 thanks for the developer
阅读所有1条评价

贡献者及开发者

「UserFlow – Disable Dashboard Access for Non Admin」是开源软件。 以下人员对此插件做出了贡献。

贡献者
  • Ga Satrya

帮助将「UserFlow – Disable Dashboard Access for Non Admin」翻译成简体中文。

对开发感兴趣吗?

您可以浏览代码,查看SVN仓库,或通过RSS订阅开发日志。

更新日志

1.3.3

  • Added: Optional administrator-specific session timeout (1-168 hours), with the general timeout as the default.
  • Improved: Clarified that session expiration is measured from login, not inactivity.

1.3.2

  • Updated WordPress compatibility declaration through version 7.1.

1.3.1

  • Security: Hardened settings reset handler with request-method check and nonce improvements.
  • Improved: Replaced per-username DB queries with single batched query for settings save performance.
  • Improved: Added explicit access-control fallthrough logic and removed stale static cache.
  • Improved: Separated settings-page capability filter from dashboard-access filter.
  • Improved: Settings sanitization now guarantees consistent option shape on save.
  • Improved: Added meta-refresh fallback when redirect headers cannot be sent.
  • Improved: Username validation errors now show count only to prevent enumeration.
  • Added: Plugin uninstall handler to clean up stored options on deletion.
  • Added: AJAX bypass behavior documented in settings help tab.
  • Added: Sidebar promotion box for developer services.
  • Dev: Improved test mock fidelity for wp_validate_redirect and WP_User_Query.
  • Dev: Fixed Composer license to valid SPDX identifier.

1.3.0

  • Rebranding: Formally renamed the plugin to UserFlow.
  • Added: Support for WordPress 7.0.
  • Refactor: Moved inline JavaScript and CSS to external files for better security and maintainability.
  • Improved: Updated settings sidebar to connect with the developer on LinkedIn.
  • Improved: Settings page formatting and code structure.
  • Improved: Updated settings labels for better clarity.
  • Improved: Use wp_validate_redirect for more robust same-site URL validation.
  • Added: admon_access_capability filter for developer customization of access rights.
  • Fix: Updated make-pot composer script for Windows compatibility.

1.2.5

  • Performance: Optimized access checks with static caching (memoization) to reduce redundant processing.
  • Fix: Ensured settings errors and success messages are correctly displayed on the settings page.
  • Improved: Better UI feedback when saving or resetting settings.
  • Improved: Added GitHub Actions automated deployment for WordPress.org SVN.
  • Assets: Added new plugin banners and icons for the WordPress.org repository.

1.1.1

  • Security Fix: Patched Open Redirect vulnerability in URL validation logic.
  • Improved: Stricter validation for custom redirect URLs.
  • Improved: Added Contextual Help tabs in settings page.

1.1.0

  • Added session timeout management with configurable intervals (1-24 hours)
  • Added custom timeout duration option (1-168 hours)
  • Added username whitelist for granting dashboard access to specific non-admin users
  • Added custom redirect URL for blocked users
  • Added option to apply session timeout to administrators
  • Added “Remember Me” override functionality
  • Enhanced security with proper input sanitization and validation
  • Improved user interface with comprehensive settings page
  • Added reset to defaults functionality
  • Updated to follow WordPress coding standards

1.0.0

  • First version

额外信息

  • 版本 1.3.3
  • 最后更新:2 周前
  • 活跃安装数量 40+
  • WordPress 版本 6.5 或更高版本
  • 已测试的最高版本为 7.1.3
  • PHP 版本 7.0 或更高版本
  • 语言
    English (US)
  • 标签
    accessdashboardloginmembershiprestrict
  • 高级视图

评级

5 星(最高 5 星)。
  • 1 条 5 星评价 5 星 1
  • 0 条 4 星评价 4 星 0
  • 0 条 3 星评价 3 星 0
  • 0 条 2 星评价 2 星 0
  • 0 条 1 星评价 1 星 0

您的评价

查看全部评论

贡献者

  • Ga Satrya

支持

有话要说吗?是否需要帮助?

查看支持论坛

捐助

您愿意支持这个插件的发展吗?

捐助此插件

  • 关于
  • 新闻
  • 主机
  • 隐私
  • 陈列窗
  • 主题
  • 插件
  • 区块样板
  • 学习
  • 支持
  • 开发者
  • WordPress.tv ↗︎
  • 参与
  • 活动
  • 捐赠 ↗
  • 周边商品 ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

China 简体中文

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • 关注我们的 X(原 Twitter)账号
  • 访问我们的 Bluesky 账号
  • 关注我们的 Mastodon 账号
  • 访问我们的 Threads 账号
  • 访问我们的 Facebook 公共主页
  • 关注我们的 Instagram 账号
  • 关注我们的 LinkedIn 主页
  • 访问我们的 TikTok 账号
  • 访问我们的 YouTube 频道
  • 访问我们的 Tumblr 账号
代码如诗