Plugixa Advanced User Role Editor

Most role editors show you a grid of four hundred capability names and let you tick boxes. Plugixa Advanced User Role Editor shows each role as a page you can read: “Can publish and edit everyone’s posts and pages. Cannot install plugins or manage users.” You change it with plain choices, and the capability names stay one click away for when you need them.

Nothing is saved until you have reviewed it. Every change, to roles and to people, waits in one bar that says how many people it affects, and anything that hands over control of the site has to be confirmed by typing its name. A restore point is taken before every save, so History can put roles and the people a change touched back exactly as they were.

It is also built to refuse the mistakes that break sites. Nobody can give away a permission they do not hold themselves, a change that would lock you out of the editor is refused with the reason, and the last administrator cannot be demoted. Pro adds what an agency needs before handing a site over: a shorter admin menu per role, a cleaner admin screen per role, and an activity log.

WP 6.5+ PHP 8.2+ Tested up to 7.1
Download Now Documentation Changelog
Customer testimonial avatar Customer testimonial avatar Customer testimonial avatar +2
Trusted by WordPress professionals

Screenshots

See it in action

Features

Everything you need

Every role, as a page you can read

A role is described in words first. The capability names are still there when you want them.

  • A page per role

    A one-sentence summary of what the role can do, the people who hold it, and its recent changes.

  • What the role sees

    A preview of the admin menu that role gets, with a switch to show the items hidden from it.

  • Permission levels

    Write and edit, publish, delete and see private, each set to none, their own or all.

  • Honest when it does not fit

    A role whose capabilities match no level shows Custom and the exact capabilities, never the nearest level.

  • Full control is marked

    Permissions that amount to control of the site carry a badge and an explanation wherever they appear.

Start from a job, not a blank grid

Create a role in four steps, and change your mind at any of them: nothing exists until the last one.

  • Job templates

    Client, Content writer, SEO manager and Moderator, plus Shop assistant when WooCommerce is active.

  • Copy or start empty

    Duplicate any role you already have, or begin with sign-in and profile only and add the rest.

  • Rename, duplicate, delete

    People who hold a deleted role are moved to a role you choose first.

  • Reset WordPress roles

    Put WordPress's own roles back to their defaults.

  • Add a permission by name

    Create a permission for custom code or a plugin to check, and grant it like any other.

  • Blocks that stay blocked

    Grant, leave out or explicitly block a capability, stored the way WordPress itself understands it.

The person, not only the role

Open someone to see exactly what they can do and where each permission comes from.

  • Several roles, in order

    When two roles disagree WordPress uses the later one, and the page lets you change the order.

  • Extra permissions

    Grant or block a single permission on one account, on top of their roles.

  • What they can do

    Everything a person can do, with the role or account setting each permission comes from.

  • Move people between roles

    Move everyone from one role to another in the background, in batches, with a count of how many moved.

  • Built for large sites

    People are listed a page at a time and searched on the server.

Nothing is saved until you have read it

Changes collect, are read back to you in words, and are saved together with one restore point.

  • One bar for every change

    Edits to roles and to people wait together, with a count of the people they affect.

  • Review in words

    Each change is listed as a sentence before it is written.

  • Automatic restore points

    One is taken before every save, and you can name and save your own.

  • Restore puts people back too

    Restoring a point returns roles and the people it changed to how they were.

  • Your site before the plugin

    The first restore point is the site as it was before the plugin was installed.

Answers, not capability names

Find out who can do what, why, and what would change the answer.

  • Check access

    Pick a person and an action and get yes or no, with the reasons in the order WordPress decides.

  • One-click fixes

    Change the answer for the whole role or for that one person. The fix joins your unsaved changes.

  • Compare roles

    Every role side by side, grouped by area, with a switch for only the differences.

  • Where a permission comes from

    WordPress, a kind of content, a known plugin, or an unknown source.

  • Known plugins recognised

    WooCommerce, Yoast SEO, Rank Math, Gravity Forms, WPForms, Easy Digital Downloads, bbPress, BuddyPress, The Events Calendar, LearnDash and others.

Find the problem before it finds you

A read-only check of the whole site. Each finding points at the screen that fixes it.

  • Roles that can take over

    Roles below Administrator holding a permission that is a route to full control.

  • Only one administrator

    A site that depends on a single administrator account is flagged.

  • Accounts worth a look

    Accounts with no role, and accounts with permissions set directly on them.

  • Roles doing no work

    Roles nobody holds, and roles that are identical to another.

  • Leftover capabilities

    Capabilities still held by roles after the plugin that registered them has gone.

The mistakes that break sites are refused

These are not settings. They are checked on the server for the screens, the REST API, the importer, restores and role moves.

  • Cannot grant what you do not hold

    Nobody can give away a permission they lack, or hand out a role containing one.

  • Cannot lock yourself out

    A change that would remove your own access to the editor is refused, with the reason.

  • The last administrator stays

    The last administrator cannot be demoted.

  • Type the name to confirm

    Saving a full-control permission requires typing its name, checked by the server too.

  • No silent overwrites

    A change made on top of another administrator's is refused, and you are told to reload.

  • A way back in

    A WP-CLI command prints a one-time rescue link when every account is locked out.

Move roles between sites, and people to the right place

Take a role setup with you, and decide where each role lands.

  • Export as JSON

    Download every role and its capabilities. The file contains no users and no content.

  • Import with a preview

    See the difference role by role and choose what happens to each before anything is written.

  • Reads other plugins' files

    Imports exports from Members and role CSV files from User Role Editor.

  • Redirects per role

    After signing in, after signing out, and when a role reaches a screen it cannot open.

  • On your own site only

    Custom redirect addresses must be on the same site.

The admin you can hand to a client

Decide what each role sees. Permissions still decide what they may do.

  • Admin menu per role Pro

    Tick what each role sees, by hiding chosen items or by showing only the ones you allow.

  • Hidden screens are refused Pro

    A hidden item's screen is refused as well, so typing its address does not open it.

  • Dashboard and toolbar Pro

    Choose which dashboard widgets and toolbar items a role is shown.

  • Plugin notices off Pro

    Hide banners, reminders and offers from plugins and themes for a role. WordPress's own messages still show.

  • Edit screens Pro

    Choose which boxes and block editor panels a role sees when editing.

Who changed what, when, and from where

History keeps whole states to go back to. The activity log keeps each change.

  • Every change, one line each Pro

    Changes to roles, to people and to the plugin's own rules, newest first.

  • Where it came from Pro

    The editor, a restore, an import, an undo, the command line, a background task or the REST API.

  • Undo a single change Pro

    Reverse one entry without restoring a whole restore point.

  • Filters and CSV export Pro

    Filter by source, by what changed and by date, and export the result.

  • Retention you choose Pro

    Keep entries for a set number of days, or keep them all.

Simple pricing

Choose your growth plan

Start building with Plugixa Advanced User Role Editor today. Upgrade anytime as your needs grow.

Free

€ 0

Free forever

The complete role editor, not a trial

  • A readable page for every role
  • Permission levels in plain words
  • People, several roles & extra permissions
  • Review before save & restore points
  • Check access, compare roles & health
  • Export, import & redirects per role
  • Every guardrail
  • Community support
Start with Free
Most Popular

Pro

€ 39

1-Year License

The role editor you can safely hand to a client

  • Everything in Free
  • Admin menu control per role
  • Hidden screens refused, not only hidden
  • Dashboard widgets & toolbar per role
  • Plugin and theme notices off per role
  • Edit-screen boxes & editor panels per role
  • Activity log of every change
  • Undo a single change
  • Filters & CSV export
  • 1 year of updates
  • Priority email support

Instant Digital Delivery

Download immediately after checkout

Secure Payment

Encrypted, PCI-compliant checkout

Auto-Updates

One-click updates from WordPress admin

Trusted by Pros

Used on thousands of WordPress sites

FAQ

Frequently asked questions

Getting Started

It changes what people are allowed to do, which is the point, so it is built to make that reversible. Nothing is saved until you review it, a restore point is taken before every save, and changes that would lock you out are refused.
Open Plugixa Role Editor in the admin menu, directly below Users. Administrators have access straight away. To let somebody else use the editor without making them an administrator, add their role under Settings, in “Who can use this editor”.
No. Each role reads as a sentence and you change it with levels such as none, their own or all. The capability names stay one click away for when you need them.
WordPress 6.5 or later and PHP 8.2 or later.

Roles and People

When two roles disagree about a permission, one grants it and a later one blocks it, WordPress uses the one that comes later on the account. So “Editor, then No publishing” cannot publish, and “No publishing, then Editor” can. The person page shows the order and lets you change it.
Yes. Extra permissions are granted or blocked on a single account, on top of that person’s roles.
Yes. People are listed a page at a time and searched on the server, head counts can be switched off with a filter, and moving people between roles runs in the background in batches.
It runs per site. Network-wide role synchronisation is not in this version.

Safety and Moving

Run wp plugixa-aure rescue <user> over SSH. It prints a one-time link, valid for fifteen minutes and only while signed in as that account, which gives the account the Administrator role back. It is recorded in History like any other change.
They stay exactly as you left them. Roles and capabilities are WordPress’s own data. Uninstalling removes the plugin’s own settings, restore points, scheduled tasks and its own capabilities, and nothing else. Restore points do not survive uninstalling, so use Export and import first if you want to keep a copy of your roles.
No. Roles made by another plugin are ordinary WordPress roles and appear as they are. The importer also reads exports from Members and role CSV files from User Role Editor.
Yes. Export and import downloads every role as a JSON file and imports it on another site, showing you the difference role by role and letting you choose what happens to each one before anything is written.

Free and Pro

No. The free version is the whole role editor, including History and restore, and nothing in it is switched off. It does not contain the Pro code at all.
Three things for people who hand a site to a client: control of the admin menu per role, a cleaner admin screen per role (dashboard widgets, toolbar, notices and edit screens), and an activity log with undo and CSV export.
The hidden item’s screen is refused too, so typing its address does not open it. It changes what people see, though, not what they are allowed to do: their permissions still decide what they can change through other screens and through the REST API. To take something away for real, change the role’s permissions.