SECURITY FINDING

Too many WordPress administrator accounts

What it is

This site has more administrator accounts than is typical for its size. Every admin account is a possible way in for an attacker, so the more there are — especially ones nobody remembers creating — the larger the attack surface.

How to fix it

Review the list of administrators and remove any account that's no longer used or not recognized.

In depth

Your WordPress site has more people with administrator access than it should. Each administrator account is like having another key to your front door, and the more keys that exist, the easier it is for someone bad to get in, especially if some of these accounts are old or forgotten. This matters because even if one administrator's password gets stolen or they leave your company, that account could still be sitting there letting attackers in. You need to go into your WordPress settings, look at the list of all administrator users, and delete or downgrade any accounts you don't recognize or that belong to people who no longer work with your site. Keep only the administrator accounts for people who actively manage your site right now. If you're unsure whether an account is still needed, ask your team members first, but err on the side of removing it—you can always add someone back later if necessary.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.