xpay✦ Commerce
Directory
WooCommerce plugins
Limited Admin Role
Limited Admin Role
Adds a custom "Admin Panel Manager" role with granular capability controls, per-plugin access rules, and a configurable session timeout.
Will this break my store?
What the WordPress.org registry says about keeping Limited Admin Role running.
Tested to 6.9.5 — 1 branch behind 7.0
Tested against the WordPress branch in use today.4 months ago
7.4
Your host must be running at least this version.6.0
1
A single maintainer. Worth knowing if the plugin is load-bearing for your store.Maintenance & trust
Scored on how Limited Admin Role is looked after — not on how many stores run it.
Maintenance
35 / 35WordPress compatibility
14 / 20Support responsiveness
Not enough dataMerchant satisfaction
Not enough dataListing transparency
3 / 10Ratings
No one has rated this plugin on WordPress.org yet. That is a statement about the ratings page, not about the plugin — plenty of well-kept plugins never collect them.
Limited Admin Role adds a custom WordPress role called Admin Panel Manager that gives a user broad content and product management access — but blocks access to WooCommerce Orders, Customers, Users, and sensitive reports.
Key Features:
- 🔐 Granular capability grid — enable or disable every WordPress & WooCommerce capability from the settings UI, organized into 15 categories
- 🚫 Block WooCommerce Orders, Customers, Analytics, and WordPress Users (menu + URL + REST API)
- 🧩 Plugin Access Deny — per-plugin admin page blocking via a dedicated submenu
- 🔑 Plugins view-only — can see installed plugins list but cannot install/activate/deactivate/update/delete
- 🕐 Configurable session timeout (default 12 hours) — forces logout regardless of “Remember Me”
- ✅ Compatible with Rank Math, Yoast SEO, WooCommerce HPOS, and Cloudflare
Capability Categories:
- Core Access, Posts, Pages, Media, Appearance & Themes
- Plugins, Users, WordPress Updates
- WooCommerce Products, Orders, Coupons, Reports & Analytics, Settings, Customers
- Comments
License
This plugin is licensed under the GNU General Public License v2.0 or later.
Full license text: https://www.gnu.org/licenses/gpl-2.0.html
Go to Users → Add New and set the Role dropdown to Admin Panel Manager. Or edit an existing user and change their role.
Yes. Go to Limited Admin Role → Settings → Capabilities tab. Every capability is listed with a checkbox — check to grant, uncheck to deny. Changes apply immediately on save.
On login, the plugin records a timestamp. On every admin page load, it checks if the elapsed time exceeds the configured limit (default: 12 hours). If so, the session is destroyed and the user is redirected to the login page with a “Session expired” message. The auth cookie is also clamped so “Remember Me” cannot extend beyond the limit.
No. Plugin installation, activation, deactivation, update, and deletion are always blocked. The user can view the installed plugins list (read-only). You can toggle even view access from the Capabilities tab (activate_plugins cap).
Go to Limited Admin Role → Plugin Access Deny. Every active plugin and its detected admin pages are listed. Check any pages to block them for the Admin Panel Manager role.
Yes. Both the legacy post_type=shop_order URL and the new HPOS page=wc-orders URL are blocked.
Yes. Both plugins show their meta boxes to any user with edit_posts capability, which this role has by default.
Categories
Plugin details
Tags on WordPress.org
