I have two security-related questions.
1. I’m wondering which role I should assign to a freelance developer for my WP site. Before giving me a quote, he would like to gain access to my wp-admin to determine if what I am asking for is possible. He wants to have a look at the functionality and see how my ads plugin works. I want to give him access but I am conscious about security.
2. If I award him the job, which role should I then assign to him? I’m assuming I should only be the only one with an admin role for security reasons, but with any other role, will he be able to change settings and make the adjustments I have requested? Or will I need to give him admin access?
Thanks very much.
]]>But the ‘traditional’ approach is fiddly and annoying. We have to to create a guest admin account, exclude it from two-factor authentication (where used), manually activate the account and remember to deactivate it after the developer is done. And we have to log out and check it works (to make sure we didn’t forget a step), and send username, password and login URL to the developer.
With this plugin, it is soooo much easier. Easier to set up an account the first time, easier to reactivate it in future, deactivates automatically after the set time period, and it’s easier because you only need to copy and paste a single piece of information to the developer rather than three separate bits. (I wish more developers would provide a secure method of communication to share credentials instead of email, but that’s another story and not a fault of this awesome plugin!)
Brilliant!
]]>