Prevent a digital mutiny: How to safeguard your admin user on client sites with security “speed bumps”
Talk to any web designer who has been in the business for a number of years and they’ll likely have a story or two about a client going rogue.
Typically they move their site somewhere else without saying anything, deleting your admin account in the process. Or they downgrade your role to subscriber as the “change content” screen looks a bit scary and they don’t know what to do with assigning existing content.
A disturbance in the Force.
The first you’ll know about it is either an invoice going unpaid, unexplained up-time alerts due to their “cheaper” replacement hosting, or finding something a little different when you try to log in to do routine maintenance as part of your support / care plan (dude, where’s my car admin menu?).
Or worse, the looming signs of a potential mutiny. The client just created an admin account for a new marketing / SEO agency (aren’t they paying you for that?) who’ll eventually attempt to poison your client against you to then steal your business by stealth. Ok, that might be a little far fetched but has happened to others before. In all likelihood they’ll install extra stuff, like slow loading tracking scripts and make a mess of it all.
To be honest, neither situation is great. But what if you could add a couple of subtle security focused speed bumps to this process? It might make them stop and think for a moment and get in touch with you first to find out why something isn’t working.
Please stop the notification emails!
One of the common complaints with clients leaving unannounced is having your email address left behind as the site administrator.
- Your site was updated = email sent
- Critical error = email sent.
- Badly implemented form submissions? Email sent.
You get the idea.
If they are dead set on leaving it might as well be in a controlled way, making sure to correctly remove your email as the site’s administrator, followed by your admin user account.
For some reason WordPress core doesn’t enforce the site administrator email address to match a user that can log in, which to be honest is a bit of an oversight. An old trac ticket raised this question, but it was dismissed as “a process issue with site handovers”, and closed.
Not helpful for us web designers, or for good website governance in general.
Important site emails should always go to an email address of a person who can log in and take action.
Email client rules to the rescue? I don’t think so.
You could set up some rules in your email client to block them, but that’s not the point. If you aren’t responsible for the site any more then you shouldn’t be receiving these emails in the first place.
Chances are if the client left you this way they’ll ignore your request to change this email, or it might take a few months to get around to it.
Add some security “speed bumps” to the process
Thankfully there is now a way to help you out for any new sites you manage.
By installing Administrator Toolkit when starting a new site build, or when you onboard a new support plan client, you can either solve or slow down some of these critical issues with one handy package.
Here are a number of ways it can reduce some of your client induced headaches:
- Better site administrator management with a drop down list of admins
WordPress core doesn’t enforce the site admin email matching to a current user. Swapping this free text email field out with a drop down of eligible* (see no.3) admin users list makes selecting a new one a quick task. - Prevents your client from going rogue and deleting the associated admin user account
When an admin user is deleted via the UI it’ll be blocked with a white screen of death if it’s a match. To remove your user account they’ll need to change the site’s administrator to a different active admin account before deleting your account. Simple, but it works. - Site administrator email opt-out
Once a month you’ll be sent a single use link via email. When clicked it will let other admins know you no longer want to be the site’s administrator. The next time someone logs in they’ll need to select a different user, and get nagged until they change it. (*) If you saw the eligible note above, your user account won’t be listed in the drop down so they can’t re-select you. - Emergency use only notification
Your client has an admin account in case you get caught by that bus one day, but they have no need to ever log in as you manage their site. You can enable this option on their user account to receive a special alert email should they ever log in. Are they logging in to try and add a new user from a different agency, or did their credentials get leaked? It is a good excuse to get in touch with them just in case. - Block unknown domains from becoming admin users
A pre-approved list of email domains will prevent a new admin user from being created if their email domain isn’t on that list. It’ll block the manual creation of Mr Smith from Rogue Marketing LLC. This speed bump could also help reduce the chances of basic cross site scripting attacks creating a new admin user for a random domain. - Receive site administrator emails without being the associated user
Any admin user can be opted-in to receive a copy of emails sent to the site’s administrator. You can treat this like an email distribution group for a support team while everyone keeps their individual logins (you have got 2FA enabled right?). This’ll allow the client to receive important emails while you remain the primary admin. If the client leaves you’ll have your own opt-out link, with no need to log in to the site. This is also handy for holiday cover, let a trusted out-sourced agency look after your client sites while you are in the sun, when you return they can opt-out from receiving any emails (until your next trip that is). - Work towards good site governance by removing unnecessary admin accounts
While not a direct headache caused by a client, keeping track of which admin user accounts are actually required can sometimes take a little guesswork (or a crystal ball). To make it easier for you, the last login date for admin users is now provided on the Users screen (should they ever log in). The site administrator also receives a monthly summary email with these dates. When the last login was over 30 days ago it’ll be shown in red.
No automated actions are taken, however this should be another talking point with your client to check those staff are still employed.
Having a client go rogue is hopefully a rare occurrence, but taking some extra measures just in case should never hurt your reputation.
With Administrator Toolkit installed, and configured with restrictions on admin user creation, it sits nicely alongside your existing WAF solution, and with virtual patching from PatchStack, you can demonstrate to your client you are proactive on extra security measures.
In a matter of minutes your new client site can be configured, letting you get back to discussing the size of their logo, again.

