How to Audit Your WordPress User Accounts: Old Admins, Roles and Shared Logins
Audit WordPress user accounts step by step: remove ex-staff and old developer admins, use least-privilege roles, end shared logins and spot unknown admins.

On this page
- List every account by role and remove former staff, old developers, agencies and test logins that no longer need access.
- Give each person their own account with the lowest role they need, and attribute content to a current user when deleting.
- Treat unknown administrators as a hack sign to investigate, and repeat the audit quarterly and whenever someone leaves.
Most WordPress sites collect user accounts the way a drawer collects old keys: a developer from the launch three years ago, a marketing intern who left, an agency you stopped working with, a shared "office" login half the team knows. Each one is a way into your website, and often nobody is checking them. A user accounts audit takes under an hour on most business sites, and it closes some of the easiest doors attackers use.
If you're not sure what each role can do, read WordPress user roles explained first. This guide is about the clean-up itself.
Step 1: Get a full list of accounts
Go to Users in your dashboard. The links above the list show how many accounts each role has, such as Administrator (4) or Editor (2). Click through each role and note:
- Who the account belongs to, and whether that person still works with you
- The email address on it: a personal Gmail, an old agency address, or one you don't recognise at all?
- The role, and whether it still matches what they do
WordPress doesn't show when each user last logged in by default. An activity log or security plugin can record this, which makes future audits much easier; see WordPress activity logs.
One quick check: if the number next to Administrator doesn't match the administrators you can actually see in the list, something may be hiding an account. Ask a developer to check the database directly.
Step 2: Remove people who no longer need access
Accounts that commonly need removing:
- Former staff, including people who left on good terms
- Previous developers and agencies whose project or contract has ended
- Freelancers given access for a one-off job, such as a writer or SEO consultant
- Test and demo accounts created during the build
- Temporary support logins that some theme or plugin vendors create for troubleshooting
- An old "admin" username, once you've created a properly named replacement
If you're unsure whether someone still needs access, change their role to Subscriber and reset their password instead of deleting straight away. If nobody asks about it within a few weeks, delete the account.
Step 3: Apply least privilege
For everyone who stays, give the lowest role that still lets them do their job.
| Person | Usually needs |
|---|---|
| Business owner | Administrator, on their own personal account |
| Current developer or maintenance provider | Administrator on a separate named account, removed when the work ends |
| Marketing manager editing pages and posts | Editor |
| Staff writer | Author or Contributor |
| Staff handling WooCommerce orders and products | Shop Manager |
| Customers and members | Customer or Subscriber |
For most small businesses, the owner plus one trusted developer is enough administrators. If you have five, ask why each one needs full control.
Step 4: Stop shared logins
A single "office" or "website" login used by several people is convenient, but it causes real problems:
- You can't remove one person's access without changing the password for everyone
- Activity logs only say "office" did something, never who
- The password ends up in WhatsApp chats, notebooks and former employees' phones
- Two-factor authentication becomes awkward, so it often gets switched off
Create a separate account for each person, with their own work email, a strong password and 2FA. Then delete the shared account, moving its content to a real person as described below.
Step 5: Delete users without losing content
When you delete a user who has written posts or pages, WordPress asks what to do with their content: delete it all, or attribute it to another user. Almost always choose Attribute all content to and pick a current account. Otherwise pages and blog posts can disappear along with the user.
- Take a backup first, so a wrong click can be undone
- Delete staff and admin accounts one at a time, reading the content question carefully each time
- Be careful with WooCommerce customers. Past orders are business records, so don't bulk-delete customer accounts without checking how your store handles orders from deleted users
- Think about bylines: if a former writer's name should stay on their articles, keep their account as a Subscriber with an email address you control and a new password, rather than deleting it
Step 6: Treat unknown admins as a warning sign
An administrator account nobody in your business created, especially one with an odd username or an email on an unfamiliar domain, is one of the classic signs of a hacked WordPress site. Attackers create these accounts so they can get back in later. If you find one:
- Don't just delete it and move on. Note its username, email and registration date first; the date can show roughly when the site was compromised
- Check your activity log, if you have one, for what the account did
- Change the passwords of every remaining administrator, plus hosting and SFTP
- Look for the hidden code that often comes with these accounts; see how to find and remove backdoors
Deleting the account without closing the way in often means it reappears days later.
Beyond the Users screen
- Application passwords: on each administrator's profile page, revoke any application passwords nobody recognises. They let apps and services access the site without the main password.
- Active sessions: after removing someone's access or spotting something odd, use the option on your profile to log out of all other sessions.
- Other accounts: hosting, SFTP, Google Search Console and Analytics users also need removing when people leave.
Make it a routine
- Whenever someone leaves or a project ends: remove or downgrade their account the same day
- Every quarter: repeat Steps 1 to 4 and compare with your last list
- Always on: alerts for new administrator accounts, so you don't wait for the next audit to spot one
- Once a year: review application passwords, hosting users and other connected accounts too
Keep a short record of who has access and why. It makes each audit faster and helps when you hand the site to a new developer.
Want these checks done every month? User reviews and security alerts are part of my WordPress maintenance plans. Found an account you can't explain? Get help with WordPress malware removal.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


