SECURITY FINDING
Too many WordPress administrator accounts
What it is
This site has more administrator accounts than is typical for its size. Every admin account is a possible way in for an attacker, so the more there are — especially ones nobody remembers creating — the larger the attack surface.
How to fix it
Review the list of administrators and remove any account that's no longer used or not recognized.
In depth
Your WordPress site has more people with administrator access than it should. Each administrator account is like having another key to your front door, and the more keys that exist, the easier it is for someone bad to get in, especially if some of these accounts are old or forgotten. This matters because even if one administrator's password gets stolen or they leave your company, that account could still be sitting there letting attackers in. You need to go into your WordPress settings, look at the list of all administrator users, and delete or downgrade any accounts you don't recognize or that belong to people who no longer work with your site. Keep only the administrator accounts for people who actively manage your site right now. If you're unsure whether an account is still needed, ask your team members first, but err on the side of removing it—you can always add someone back later if necessary.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.