Access Governance for WordPress (aka AAM)

Beschreibung

Advanced Access Manager (AAM) is an Access Governance platform for WordPress. It helps you understand and control how users, roles, applications, APIs, and other identities interact with your website.

WordPress security is not only about stopping attackers at the perimeter. Security also depends on what authenticated users, applications, integrations, and automated systems are allowed to do once they have access.

A user may have more capabilities than their job requires. An old account may still have administrative privileges. An Application Password may expose unnecessary API access. A plugin may introduce new capabilities or endpoints. An AI agent may be connected through an account with far more authority than it needs.

These are access governance problems.

AAM provides the tools to discover, define, enforce, and audit access across WordPress so you can reduce excessive privileges, prevent broken access controls, and build a security model based on the principle of least privilege.

Security starts from within.

What is Access Governance?

Access Governance is the continuous practice of answering four fundamental questions:

Who has access?
What can they access?
Why do they have that access?
Should they still have it?

In WordPress, the answers are rarely determined by a user’s role alone.

Effective access can be influenced by roles, capabilities, direct user permissions, content-level rules, plugins, authentication methods, API endpoints, Application Passwords, integrations, and custom application logic.

AAM brings these controls together so that WordPress access can be intentionally designed, consistently enforced, and periodically reviewed.

Access Governance with AAM

  • Discover Effective Access – Understand how roles, capabilities, inherited permissions, and access rules determine what an identity can actually do.

  • Enforce Least Privilege – Give users, applications, and integrations only the access required to perform their legitimate responsibilities.

  • Mitigate Broken Access Controls – Reduce the risk of unauthorized actions caused by excessive permissions, misconfigured roles, exposed endpoints, or inconsistent access rules.

  • Govern Users & Roles – Manage WordPress roles, capabilities, user permissions, and access inheritance with greater precision.

  • Protect WordPress Resources – Control access to posts, pages, media, taxonomies, custom post types, administrative areas, and other WordPress resources.

  • Govern API Access – Control access to REST API endpoints, XML-RPC functionality, and other programmatic interfaces.

  • Audit Access Continuously – Identify excessive privileges, risky configurations, unnecessary credentials, and other access-related security concerns before they become incidents.

  • Define Access as Policy – Use JSON Access Policies to describe portable, auditable, and automation-friendly access rules.

  • Build Custom Access Controls – Use the AAM PHP Framework and developer APIs to implement application-specific authorization and governance requirements.

Hauptfunktionen

  • Security Audit – Evaluate WordPress for access-related security risks, configuration problems, excessive privileges, and other potential weaknesses.

  • Role & Capability Management – Create and manage roles and control WordPress capabilities beyond the default role system.

  • User-Level Access Controls – Refine access for individual users without creating unnecessary roles.

  • Content Access Governance – Control who can view, edit, publish, delete, or otherwise interact with WordPress content.

  • Backend Access Control – Restrict administrative functionality and control access to WordPress backend menus and features.

  • Frontend Access Control – Define access rules for visitors, authenticated users, roles, and individual accounts.

  • API Access Control – Govern access to REST API endpoints, XML-RPC, and programmatic WordPress functionality.

  • Authentication & Identity Controls – Manage authentication-related functionality and additional mechanisms for securely accessing WordPress.

  • JSON Access Policies – Define complex access requirements as structured, reusable policies.

  • Developer Framework – Extend AAM or build custom authorization logic using its PHP APIs, hooks, and services.

Beyond Roles and Capabilities

WordPress roles and capabilities are an important part of authorization, but they are only part of the complete access model.

Modern WordPress websites may expose functionality through the admin dashboard, frontend requests, REST APIs, XML-RPC, Application Passwords, plugins, integrations, automation platforms, and AI agents.

That means securing WordPress requires looking beyond the question:

„What role does this user have?“

The more important question is:

„What can this identity actually do?“

AAM is designed around this broader view of effective access.

Built for Modern WordPress Security

AAM is built for site owners, developers, agencies, and security professionals who need more than basic role management.

Use AAM to establish a repeatable access governance process:

Discover Evaluate Define Enforce Verify Audit

Whether you manage a single website or hundreds of client installations, the goal remains the same: maintain a clear, intentional, and defensible access model.

AAM is used on 150,000+ WordPress websites and has been developed specifically around WordPress authorization and access control for more than a decade.

Most core functionality is available for free, with advanced capabilities available through premium extensions.

No ads. No hidden tracking. No unnecessary data collection.

Just access controls you can understand, enforce, audit, and trust.

Screenshots

Installation

  1. Upload advanced-access-manager folder to the /wp-content/plugins/ directory
  2. Aktiviere das Plugin in WordPress über das Menü „Plugins“

Rezensionen

17. Januar 2025
I have been looking for a plugin to manage user access and AAM is by far the best of all. Highly recommended.
11. September 2024
This plugin is the best out there. I use it every time I have a client that needs to have access to the backend. I can easily make changes to permissions for every user role. 10 stars guys
10. Juni 2024 2 Antworten
When we started using this plugin a year or so ago it was good. But now it conflicts with many other plugins and misses out plugins like WPCode. It actually locked me out of the plugin as an administrator, so I had to uninstall AAM.It is a shame because it was once a great plugin.
18. März 2024
I am looking to hide "metaboxes" in Gutenberg editors, but as far as I understand in the "Metaboxes and Widgets", in the "Articles" section, when I click hide (Comments, Slug…) .it does nothing.Does it only work in classic editor ?
29. Februar 2024
Very comprehensive plugin that was able to do a lot of the things that I needed (especially in comparison to other ones out there when it comes to access management). Support was prompt, professional and very helpful and actually went above and beyond to help me out even after I had misunderstood some of the terms and conditions. They really know their stuff when it comes to WP so you are in good hands!
Alle 423 Rezensionen lesen

Mitwirkende und Entwickler

„Access Governance for WordPress (aka AAM)“ ist Open-Source-Software. Folgende Menschen haben an diesem Plugin mitgewirkt:

Mitwirkende

„Access Governance for WordPress (aka AAM)“ wurde in 9 Sprachen übersetzt. Danke an die Übersetzer für ihre Mitwirkung.

Übersetze „Access Governance for WordPress (aka AAM)“ in deine Sprache.

Interessiert an der Entwicklung?

Durchstöbere den Code, sieh dir das SVN-Repository an oder abonniere das Entwicklungsprotokoll per RSS.

Änderungsprotokoll

8.0.0

  • New: Completely new UI
  • New: The Abilities & MCP service
  • New: Security Audit implementation

7.1.3

7.1.2

7.1.1

7.1.0

7.0.11

7.0.10

7.0.9

7.0.8

7.0.7

7.0.6

7.0.5

7.0.4

7.0.3

7.0.2

7.0.1

7.0.0

  • Official 7.0.0

6.9.51

6.0.0

  • Complete rewrite of the entire plugin. For more information, check this article

5.0

  • Added ACCESS COUNTER option to Posts & Pages
  • Added premium MONETIZE option to Posts & Pages
  • Added ability to turn off „Secure Login“ feature
  • Added ability to toggle extension status (active/inactive)
  • Added ability for AAM to filter out Admin Top Bar based on restricted admin menus
  • Deprecated AAM Role Filter extension and merged it to the AAM core
  • Deprecated AAM Payment extension and merged it with AAM E-Commerce extension
  • Deprecated ConfigPress options that manage access to AAM UI. All is based on capabilities from now.
  • Split UI to three areas: Access, Settings and Extensions
  • Fixed over 25+ reported bugs and discovered during internal refactoring
  • Removed deprecated „Security“ feature. Replaced with Secure Login Widget
  • Removed deprecated „Teaser“ feature. Replaced with Teaser Message per post base

4.0

  • Added link Access to category list
  • Added shortcode [aam] to manage access to the post’s content
  • Moved AAM Redirect extension to the basic AAM package
  • Moved AAM Login Redirect extension to the basic AAM package
  • Moved AAM Content Teaser extension to the basic AAM package
  • Set single password for any post or posts in any category or post type
  • Added two protection mechanism from login brute force attacks
  • Added double authentication mechanism
  • Few minor core bug fixings
  • Improved multisite support
  • Improved caching mechanism

3.0

  • Brand new and much more intuitive user interface
  • Fully responsive design
  • Better, more reliable and faster core functionality
  • Completely new extension handler
  • Added „Manage Access“ action to the list of user
  • Tested against WP 3.8 and PHP 5.2.17 versions

2.0

  • New UI
  • Robust and completely new core functionality
  • Over 3 dozen of bug fixed and improvement during 3 alpha & beta versions
  • Improved Update mechanism

1.0

  • Fixed issue with comment editing
  • Implemented JavaScript error catching