Advanced Access Manager – Access Governance for WordPress icon

Advanced Access Manager – Access Governance for WordPress

by AAM Plugin

View on WordPress.org
82 Quality Score
Active Installs
23/30

With 100,000 active installs it is a mid-tier plugin, well known in the access control niche but far behind the top security plugins that clear 1 million installs.

Update Freshness
25/25

Last updated on 2026-05-25, the maintenance score is perfect, signalling an actively developed plugin that keeps pace with WordPress core releases.

User Rating
13/15

A rating of 84 out of 100 from 420 reviewers is solid and indicates most users feel the plugin delivers on its promises, though the smaller review pool means feedback is less battle-tested than category leaders.

Support Health
8/15

Only 3 total support threads with 0 resolved is a real weakness; the sample size is small but the 0.0 percent resolution rate suggests either low community engagement or that users self-support through documentation.

WP Compatibility
15/15

Tested with WordPress 7.0.0 and requiring PHP 5.6.0 with a WordPress minimum of 5.8.0, compatibility is excellent and the plugin runs on virtually every modern WordPress environment.

Scores higher than 89% of indexed plugins

About

Access Governance for WordPress. Control roles, users, content, admin areas, and APIs to prevent broken access controls and excessive privileges.

Active Installs 100k+
Rating ★★★★ 4.2/5
Last Updated 2026-09-08 10:26am GMT
Requires WordPress 5.8.0+
Tested Up To 7.1.0
Requires PHP 5.6.0+

Security History

12 known vulnerabilities, all patched
1 Critical 3 High 8 Medium

Most recent: May 14, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

Advanced Access Manager is an access governance plugin that lets administrators define granular permissions for roles, individual users, content, admin screens, and WordPress REST API endpoints. It goes beyond simple role editors by enforcing restrictions on backend menus, pages, posts, and custom post types based on user, role, or capability. In practice, you can lock down sensitive admin areas, hide content from specific roles, and restrict which API routes different user types can call.

Who It's For

This plugin is built for organizations running WordPress in regulated, multi-user, or client-facing environments where access control is a compliance or security requirement. Healthcare portals, legal document management systems, membership sites with tiered content, education LMS platforms, and agencies juggling multiple client sites will get the most value. It suits teams that need to enforce least-privilege access without writing custom code.

Who Should Skip It

If you run a personal blog, small business brochure site, or simple WooCommerce store with one or two staff, this plugin is overkill and adds administrative complexity you do not need. Sites already covered by a security suite like Wordfence or Jetpack plus a basic role editor like User Role Editor will rarely benefit from layering AAM on top.

The Bottom Line

Advanced Access Manager delivers exactly what its name promises: detailed control over who can see and do what inside WordPress, and its 82.49/100 overall score reflects a well-maintained, broadly compatible plugin with strong user satisfaction. The 0 percent resolved support thread rate is the one notable concern, so buyers should not rely on fast forum help and should test changes on staging first. For sites with real access governance needs, it is a strong choice; for everyone else, a lighter solution will do.

Tags

access governance api security restricted content security user roles