ArticlesWebsite advice

How to Give Your Web Developer WordPress Access Safely

Illustration of website care and support with a shield and maintenance tools

Do not share your own WordPress password. Create a separate account for the person helping you, give it only the access they need and remove or reduce that access when the work is finished.

Why a separate account matters

Individual accounts create a clearer record of who made a change. They also let you revoke one person’s access without changing the password used by everyone else.

Your account should remain yours. A developer, editor, staff member or support provider should have an account in their own name.

Create the account inside WordPress

  1. Sign in to WordPress.
  2. Go to Users → Add New User.
  3. Use the person’s real work email address.
  4. Let WordPress generate a strong password and send the account email.
  5. Select the appropriate role.

An Editor can manage website content but cannot normally install plugins or alter important site settings. An Administrator can make structural and technical changes, so use that role only when the work genuinely requires it.

Hosting and domain access are separate

WordPress access does not automatically provide access to hosting, DNS, domain registration or business email. When those systems are involved, invite the support provider as a user where the provider offers that feature. Avoid sharing the primary account unless no safer option exists.

Use temporary access where practical

For a short project, note when the access was created and review it as soon as the work is finished. Ongoing care-plan access can remain active, but it should still be checked periodically.

Before sending anything

Never send passwords in ordinary email or place them in a support ticket. Ask for a secure transfer method, or create an invitation that lets the recipient set their own password.

Review access after the work

When the task is complete, remove accounts that are no longer needed or change an Administrator to a lower role. Also review old hosting collaborators, temporary FTP accounts and unused API tokens.

If someone leaves your business, disable their access promptly rather than simply assuming they will not use it.

Keep ownership with the business

The business owner should control the primary domain registrar, hosting account and recovery email. A developer may administer those services, but the client should not depend on one individual’s private account to keep the website online.

Good access management is not about distrust. It creates clean ownership, easier handovers and fewer emergencies later.

Need help with this?

Clients can open a secure support request and keep the conversation in one place.

Scroll to Top