Contents

Troubleshooting - Plugixa Advanced User Role Editor

Start here. Most reports fall into one of these, and many of them are the plugin doing exactly what it should.

Somebody is locked out of the editor

The plugin refuses changes that would lock you out, but one administrator can still remove another’s access. The way back is a recovery link, made from the command line by anyone with SSH access to the site:

wp plugixa-aure rescue <user>

<user> is the account’s ID, login or email. The command prints a link. Sign in as that account, then open the link. It gives the account the Administrator role, takes you to the editor, and is recorded in History.

Message when opening the link Cause
“This recovery link is for a different account. Sign in as that user first, then open the link again.” You are signed in as somebody else, or not signed in. The link only works for the account it was made for.
“This recovery link has expired. Generate a new one with: wp plugixa-aure rescue ” Links last 15 minutes and work once.
“That recovery link is not valid.” The link was copied incompletely, or a newer link has replaced it.

No command line? Ask your host to run it, or have another administrator give the role back in People.

The menu entry is missing

Plugixa Role Editor appears directly below Users, and only for people allowed to use the editor. On a new install that is administrators only. Add a role under Settings -> Who can use this editor. See Settings.

A save is refused

The review dialog shows This cannot be saved with the reason, and nothing is written. These are the reasons.

Message Cause and fix
“Administrator is locked, so nobody changes the role the site depends on by accident. Turn on editing Administrator in Settings first.” Turn on Settings -> Allow editing the Administrator role.
“That change would remove your own access to this editor …” The change, taken as a whole, would lock you out. Give the access to another role you hold first.
“This is the only administrator on the site …” or “This change would leave the site with no administrator …” Give another account the Administrator role first.
“A user needs at least one role …” Give the person another role before removing the last one.
“You cannot grant “…” , because you do not hold it yourself.” You can only give out what you hold. Ask somebody who holds it.
“You cannot revoke “…” , because you do not hold it yourself.” The same rule for taking away.
“This account holds permissions you do not have yourself …” See the next section.
“… was changed by someone else after you opened this screen. Reload to see their change, then make yours again.” Another person saved the same role or account first. Reload and repeat your change.
“Some of these changes hand over control of the site. Confirm each of them before saving.” Type the name shown in each confirmation box in the review.
“”…“ is the name of a role this user holds, so it cannot also be set as a personal capability …“ Choose a different permission name.
“You are not allowed to change roles.” / “You are not allowed to change what people can do.” Your access does not cover that kind of change, or the Users feature is switched off.

If a save stops part-way, which should be rare, the message ends: “Part of the change may already be saved - restore point N puts everything back as it was.” Restore that point from History.

Each rule is explained in Safety guardrails.

“This account holds permissions you do not have”

A person’s page is greyed out with “This account holds permissions you do not have, so you cannot change it.” Changing somebody who can do more than you would be a way of doing something you cannot do, so it is refused. This is typical when a role with delegated access looks at an administrator. Ask somebody who holds those permissions.

On multisite the page may instead say “This is a network administrator. Their access does not come from roles on this site, so there is nothing to change here.”

A permission shows “Unknown source”

A role holds it, but nothing active on the site registers it.

Detail shown What it means
“Probably from [plugin]” An installed plugin most likely uses it. Leave it.
“Probably from [plugin], which is switched off” The plugin is deactivated. It will be used again if you reactivate.
“It may be left over from a plugin that was removed.” A leftover. Remove it under All permissions -> Unknown source, or keep it with Manage as added by you.

Remove from all roles is refused for anything an installed plugin probably uses: “”…“ looks like it belongs to [plugin], which is installed on this site, so it is not removed from every role at once.“

A redirect was refused, or does nothing

Symptom Cause
“”…“ is not an address this site may redirect to.“ The address is on another host. Redirects must stay on this site.
The refused-screen rule does nothing Its destination is the very screen the person was refused. The plugin skips it to avoid a loop. Choose a different destination.
The wrong role’s rule is used When a person holds several roles, the first role in the list on the Redirects screen that has a rule decides.
The first-time rule did not fire for an existing user It is used only at the first sign-in the plugin sees for an account.

See Login redirects.

A restore is refused

“At this restore point the role “…” did not exist, and people hold it now. Move them to another role first, then restore.” Move those people in People, then restore again.

A restore button that is greyed out with “The site already matches this point.” means there is nothing to put back.

Check access says No after I fixed it

The answer uses saved permissions. A fix chosen under Change the answer only adds to your unsaved changes. Review and save, and the answer updates.

A screen is missing

Missing Check
Admin menu, Screen clean-up, Activity log PRO They are part of the Pro edition. The free edition does not contain them. See Free vs Pro.
A Pro screen, with Pro installed Its switch under Settings -> Features. Admin menu also needs Health switched on.
People, Health, Redirects, Check access, All permissions, Export and import The matching switch under Settings -> Features. Reload after changing it.
History, Redirects, Export and import for one person only These need permission to change roles.
Settings shows “You do not have permission to change these settings.” Settings needs its own permission, which roles added under Who can use this editor do not get.

The app shows an error instead of a screen

The editor loads everything from your site’s REST API, under plugixa-aure/v1.

What you see Likely cause
“This could not be loaded” with Try again The request failed. Try again; if it persists, check the points below.
“You do not have access to this” Your account is not allowed to see that part.
“Request failed with status …” The reply did not come from WordPress. With status 404 on every screen, the REST API address is not reaching WordPress: re-save Settings > Permalinks so the rewrite rules are written again. Otherwise a security plugin, firewall or server rule is blocking or altering REST API requests for signed-in users.
“Something went wrong and nothing was changed.” An unexpected error on the server. Nothing was saved. With WP_DEBUG on, the cause is written to the PHP error log, prefixed [Plugixa AURE].
Every request starts failing in a tab left open for a long time Your sign-in session for that page has expired. Reload the page.

Check that https://yoursite.com/wp-json/ answers at all. If the REST API is disabled or blocked, the editor cannot work.

The “Which screen each capability opens” tab is empty

“Not captured yet. Open any WordPress admin page and come back.” The list is taken from the admin menu while an administrator browses the admin area. Open any admin page as an administrator, then return.

An import fails

See the table in Export and import. The most common cause is choosing a file that is not a role export.

Still stuck

  • Read the page for the screen you are using.
  • Look at History: it shows what changed, who changed it and when, and can put it back.
  • Contact support through plugixa.com, and include the exact message you saw.

What to do next

Quick Links