Sudo for WordPress! Risky actions -- activating plugins, deleting users, changing key settings -- are gated by a required reauthentication step, regardless of user role. Time-bounded sessions, 2FA support, rate limiting, and configurable policies for REST, WP-CLI, Cron, WPGraphQL, & XML-RPC. No role escalation, no new permissions -- just a gate.
-
Updated
Mar 15, 2026 - PHP