Take precise control of WordPress roles, capabilities, content access, admin-area visibility, and user permissions — with safety, recovery, audit history, WooCommerce awareness, and Multisite support built in.
WPStore+ Membership & User Role Manager is an advanced WordPress access-control and role-management plugin designed for websites that need more than basic user roles.
Create and clone custom roles, manage capabilities with Allow, Deny, and Not Set states, assign multiple roles to users, restrict content by role or capability, control individual Gutenberg blocks, limit access to selected WordPress admin screens, and inspect exactly why a user can or cannot perform an action.
Unlike a basic role editor, WPStore+ Membership & User Role Manager includes safety and diagnostic layers designed for production websites. Permission snapshots can be created before sensitive changes, administrator protections reduce the risk of accidental lockouts, audit history records permission changes, and the Recovery Center provides controlled recovery options when role configurations go wrong.
Powerful Role & Capability Management
Create, clone, edit, export, import, and migrate custom WordPress roles.
The capability editor provides clear Allow, Deny, and Not Set states, capability grouping, search tools, and protection for WordPress built-in roles and critical Administrator permissions.
Users can also be assigned multiple roles when a single role is not enough to represent their responsibilities.
Content Access Control
Restrict Posts, Pages, WooCommerce Products, and supported public custom post types using:
- Everyone
- Logged-in users
- Selected roles
- Selected capabilities
Choose what should happen when access is denied:
- Display a custom message
- Redirect to WordPress login
- Redirect to a safe same-site URL
- Return a 404 response
Restricted content is protected beyond the visible frontend, including REST responses, feeds, excerpts, comments, and other supported exposure paths.
Gutenberg Block Permissions
Control visibility at the individual Gutenberg block level without restricting the entire page.
Blocks can be displayed to:
- Everyone
- Logged-in users
- Logged-out visitors
- Selected roles
- Selected capabilities
Denied blocks are removed during server-side rendering rather than merely hidden with CSS.
This makes it possible to create role-aware landing pages, member sections, staff-only notes, protected download buttons, login CTAs, and other conditional content inside the same WordPress page.
Advanced Admin Access Control
Create role-specific WordPress administration policies.
Hide selected admin menus, restrict direct access to protected wp-admin pages, hide Dashboard widgets, and configure role-specific login destinations.
Admin Access policies are designed to reduce access only. They never grant WordPress capabilities that a user does not already possess.
Critical Administrator accounts retain a permanent safety bypass to reduce accidental administrative lockouts.
WooCommerce-Aware Permissions
When WooCommerce is active, WPStore+ Membership & User Role Manager recognizes WooCommerce-related capabilities and provides role presets for common store responsibilities such as:
- Product Manager
- Order Manager
- Coupon Manager
- Store Operator
Presets create new custom roles and do not silently overwrite WooCommerce’s existing customer or shop_manager roles.
User & Capability Inspector
Troubleshoot complex WordPress permissions without changing them.
Select a user and inspect:
- Assigned roles
- Effective capabilities
- Explicit Deny states
- Capabilities that are not granted
- Direct user capability overrides
- Allow/Deny conflicts
- Capability source chain
- Winning permission source
The Capability Test can also evaluate contextual WordPress capabilities such as edit_post against a specific object ID and show the primitive capabilities produced by WordPress capability mapping.
The Inspector is intentionally read-only.
Permission Snapshots & Recovery
Sensitive role changes can create recovery snapshots before modifications are applied.
Snapshots can be restored when necessary and are protected by integrity verification.
The Recovery Center includes:
- Security self-checks
- Administrator recovery snapshots
- Critical Administrator capability repair
- Role registry integrity baseline
- External permission-drift detection
- Emergency Admin Access reset
- Controlled
wp-config.phpRecovery Mode
No anonymous recovery URL or public recovery backdoor is created.
Audit Log & Permission History
Track permission-related changes across the site with:
- Actor information
- Event type
- Role or user affected
- Before / After state
- Capability Added / Removed / Allowed / Denied
- Permission timeline
- Snapshot linkage
- Filters
- Pagination
- CSV export
- Retention controls
Audit events and recovery snapshots include integrity verification to help identify unexpected database modifications.
Role Migration
Move role definitions between WordPress installations using a controlled migration workflow.
Migration includes:
Export → Preview → Conflict Handling → Dry Run → Apply → Migration Report
Conflict actions include:
- Create
- Skip
- Overwrite existing custom role
- Map to a new role slug
Built-in WordPress roles cannot be overwritten through the migration workflow.
User assignments and site-specific access policies are intentionally excluded from portable role migration to prevent accidental cross-site permission changes.
WordPress Multisite Support
WPStore+ Membership & User Role Manager understands WordPress Multisite site contexts.
Super Administrators can inspect role information across sites and copy selected custom roles between sites within the same network through a preview and dry-run workflow.
Network Role Copy does not automatically copy:
- User assignments
- Content Access rules
- Gutenberg Block Permissions
- Admin Access policies
- Super Administrator status
Commercial License & Secure Updates
v2.0.0 includes WPStore+ commercial licensing and authenticated WordPress update integration.
A valid license provides access to commercial updates while the plugin’s existing role and access rules continue working even if the license server is temporarily unavailable or a license later expires.
This safety-first policy prevents licensing state from unexpectedly changing a production site’s authorization behavior.
The plugin also includes:
- Verified offline license grace
- Force Update Check
- Update metadata caching
- Site Instance ID
- Commercial System Status
- Privacy-safe Support Report
Built for Production WordPress Sites
WPStore+ Membership & User Role Manager is suitable for:
- Business websites
- WooCommerce stores
- Membership websites
- Editorial teams
- Agencies
- Client websites
- Internal company portals
- Multi-author websites
- WordPress Multisite networks
- Websites with multiple administrators, editors, store staff, or support staff
Manage who can do what — while keeping permission changes visible, recoverable, and controlled.
Looking for more WordPress solutions? Explore our complete collection of WPStore+ plugins and find the right tools for your website.
















Reviews
There are no reviews yet.