Advanced Access Manager – Access Governance for WordPress
by AAM Plugin · Security
Also makes 4 other plugins · 100.7K+ installs across the portfolio →
Access Governance for WordPress. Control roles, users, content, admin areas, and APIs to prevent broken access controls and excessive privileges.
86 health vs 64 average across 997 Security plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Well optimized
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
13.7K
now · peak 204.3K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
6
releases in the last 12 months
3mo ago
latest release · v7.1.2
207
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 50% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “100K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-03-16 · 1,495 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent review vibe
read from the latest 12 reviews to 2025-09-23Reviewers keep calling it the best access control plugin they've found and praise the support, though one recent reviewer hit conflicts with other plugins and got locked out of their own admin.
Recent reviews
All reviews on wp.org ↗- ★★★★★ Sepi11mo ago
very good plugin.
Read on wp.org ↗ - ★★★★★ yungcyang1.6y ago
I have been looking for a plugin to manage user access and AAM is by far the best of all. Highly recommended.
Read on wp.org ↗ - ★★★★★ Vassos Hadjivassiliou2.0y ago
This plugin is the best out there. I use it every time I have a client that needs to have access to the backend. I can easily make changes to permissions for every user role. 10 stars guys
Read on wp.org ↗ - ★★★★★ tomo555552.2y ago
When we started using this plugin a year or so ago it was good. But now it conflicts with many other plugins and misses out plugins like WPCode. It actually locked me out of the plugin as an administrator, so I had to uninstall AAM.It is a shame because it was once a great plugin.
Read on wp.org ↗ - ★★★★★ superwpml2.4y ago
I am looking to hide “metaboxes” in Gutenberg editors, but as far as I understand in the “Metaboxes and Widgets”, in the “Articles” section, when I click hide (Comments, Slug…) .it does nothing.Does it only work in classic editor ?
Read on wp.org ↗ - ★★★★★ adamr0012.5y ago
Very comprehensive plugin that was able to do a lot of the things that I needed (especially in comparison to other ones out there when it comes to access management). Support was prompt, professional and very helpful and actually went above and beyond to help me out even after I had misunderstood some of the terms and conditions. They really know their stuff when it comes to WP so you are in good hands!
Read on wp.org ↗ - ★★★★★ rosalvoalc2.6y ago
Olá Equipe do Advance Access Manager, Gostaria de expressar minha imensa satisfação com o AAM! Minha experiência com este plugin tem sido excelente, proporcionando um gerenciamento detalhado de usuários e acessos de forma intuitiva e fácil de compreender. O AAM se destaca como o melhor plugin que já encontrei até hoje para lidar com as nuances do controle de usuários e permissões. A interface é amigável, facilitando a configuração e administração das permissões de acesso, tornando todo o processo extremamente eficiente. Agradeço à equipe do Advance Access Manager pelo desenvolvimento de uma ferramenta tão poderosa e eficaz. Continuem o excelente trabalho!
Read on wp.org ↗ - ★★★★★ dotboy2.8y ago
Really the quickest and best support I’ve had for any software, ever. Marvellous!
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 7.1.2 Fixed: “Sorry, you are not allowed to give users that role.” when Multi-Role Support is enabled and default_role is not in get_editable_roles() https://github.com/aamplugin/advanced-access-manager/issues/501 Fixed: Incor 7.1.2
- — Version 7.1.1 Fixed: Incorrectly handled URL with encoded characters https://github.com/aamplugin/advanced-access-manager/issues/500 Fixed: Deprecated: Method ReflectionProperty::setAccessible() is deprecated since 8.5, as it has no e 7.1.1
- — Version 7.1.0 Fixed: Warning: Undefined array key “effect” in /../application/Framework/Utility/Misc.php on line 483 https://github.com/aamplugin/advanced-access-manager/issues/497 Fixed: Can’t reset ConfigPress https://github.com/aam 7.1.0
- — Version 7.0.11 Fixed: Advanced Multi-Role setup fails to hide posts https://github.com/aamplugin/advanced-access-manager/issues/491 Fixed: Security Audit References are incorrectly displayed after page refresh https://github.com/aamplu 7.0.11
- — Version 7.0.10 Fixed: Permalink has empty href when post is password protected https://github.com/aamplugin/advanced-access-manager/issues/487 Fixed: Roles & Capabilities are not syncing in multisite https://github.com/aamplugin/advanc 7.0.10
- — Version 7.0.9 Fixed: PHP Parse error in php7.4 https://github.com/aamplugin/advanced-access-manager/issues/482 Fixed: Uncaught OutOfRangeException: Cannot find user by identifier 0 in /../Framework/Utility/AccessLevels.php:198 https:/ 7.0.9
Known vulnerabilities
via Wordfence Intelligence12 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2024-03-20 CVE-2024-29127 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.9.20 Patched in 6.9.21
- Medium · 5.5 Advanced Access Manager <= 6.9.20 - Authenticated (Administrator+) Stored Cross-Site Scripting ↗2024-03-16 CVE-2024-29124 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.9.20 Patched in 6.9.21
- 2023-12-27 CVE-2023-51675 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 6.9.18 Patched in 6.9.19
- Medium · 6.4 Advanced Access Manager <= 6.9.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2023-12-27 CVE-2023-51674 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.9.18 Patched in 6.9.19
- Medium · 6.4 Advanced Access Manager <= 6.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2023-12-26 CVE-2023-50881 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.9.15 Patched in 6.9.16
- 2021-10-19 CVE-2021-24830 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 6.8.0 Patched in 6.8.0
- 2020-08-20 CVE-2020-35934 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 6.6.1 Patched in 6.6.2
- High · 7.5 Advanced Access Manager <= 6.6.1 - Authenticated Authorization Bypass and Privilege Escalation ↗2020-08-14 CVE-2020-35935 Authentication Bypass by Primary Weakness Affects <= 6.6.1 Patched in 6.6.2
- 2019-09-09 CVE-2019-25213 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 5.9.9 Patched in 5.9.9
- High · 8.8 Advanced Access Manager <= 3.2.1 - Unrestricted AJAX Actions allowing Privilege Escalation ↗2016-06-21 Improper Authorization Affects < 3.2.2 Patched in 3.2.2
- 2014-08-20 CVE-2014-6059 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 2.8.3 Patched in 2.8.3
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 36 languages, 3 at 90% or more
Plus 12 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Wordfence Security – Firewall, Malware Scan, and Login Security 5M+ installs · 4.7★ · 1 shared tag A
-
Hostinger Tools 3M+ installs · 3.6★ · 1 shared tag B
-
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) 3M+ installs · 4.9★ · 1 shared tag A -
Jetpack – WP Security, Backup, Speed, & Growth 3M+ installs · 3.8★ · 1 shared tag A
-
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention 1M+ installs · 4.8★ · 1 shared tag A -
Loginizer 1M+ installs · 4.8★ · 1 shared tag A
Embed this report card
Drop a live Pulse card for Advanced Access Manager – Access Governance for WordPress into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/advanced-access-manager" width="480" height="300" style="border:0" loading="lazy" title="Advanced Access Manager – Access Governance for WordPress — Plugin Pulse"></iframe> Advanced Access Manager – Access Governance for WordPress: 100K+ active installs, 4.2★ (420 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/advanced-access-manager