Sudo for WordPress! Risky actions -- activating plugins, deleting users, changing key settings -- are gated by a required reauthentication step, regardless of user role. Time-bounded sessions, 2FA support, rate limiting, and configurable policies for REST, WP-CLI, Cron, WPGraphQL, & XML-RPC. No role escalation, no new permissions -- just a gate.
wp-cli sudo wordpress-security wordpress-plugins access-control wordpress-xmlrpc zero-trust wpgraphql wordpress-rest-api wordpress-admin-panel wordpress-cron wordpress-auth wordpress-admin-backend wordpress-multisite-compatible wordpress-security-plugin wordpress-users principle-of-least-privilege wordpress-administrators
-
Updated
Mar 15, 2026 - PHP