Plugin Pulse
← Pulse

Advanced Access Manager – Access Governance for WordPress

by AAM Plugin · Security

Also makes 4 other plugins · 100.7K+ installs across the portfolio →

Access Governance for WordPress. Control roles, users, content, admin areas, and APIs to prevent broken access controls and excessive privileges.

How scoring works →
86 Health · A
Maintenance 100/100
Rating quality 80/100
Support 70/100

86 health vs 64 average across 997 Security plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

82 / 100

Well optimized

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 84/100
Listing tuning 100/100
Support resolution 0/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-30% vs prior 30d
450Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

13.7K

now · peak 204.3K

13.8K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Advanced Access Mana · #386 you Wordfence Security · #11 Hostinger Tools · #20 Really Simple Securi · #17

Rating trend

Star average over time · dips mark rough releases

4.2Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

138per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

6

releases in the last 12 months

3mo ago

latest release · v7.1.2

207

tagged releases on record

Recent releases

7.1.2 · 3mo ago7.1.1 · 4mo ago7.1.0 · 6mo ago7.0.11 · 7mo ago7.0.10 · 10mo ago7.0.9 · 11mo ago7.0.8 · 1.1y ago7.0.7 · 1.1y ago7.0.6 · 1.2y ago7.0.5 · 1.2y ago7.0.4 · 1.2y ago7.0.3 · 1.3y ago7.0.2 · 1.3y ago7.0.1 · 1.3y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 50% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v7.1 50%
v6.9 22%
v7.0 16%
Older / other versions 12%

Estimated active installs

The public count shows “100K+”. Our estimate pins where the real number sits.

modeled estimate
100K–200K ≈140K

Modeled within the band wp.org reports; tightens as we track daily.

Install history · since 2015-03-16 · 1,495 observations

100KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.

Details

Version
7.1.2
Last updated
3mo ago
Added
2011-07-30 · 15 yrs old
Requires WP
5.8.0
Tested up to
7.0.0
Requires PHP
5.6.0

Recent review vibe

read from the latest 12 reviews to 2025-09-23
Positive PraiseSupport gone quietCompatibility

Reviewers keep calling it the best access control plugin they've found and praise the support, though one recent reviewer hit conflicts with other plugins and got locked out of their own admin.

Recent reviews

All reviews on wp.org ↗
  1. Sepi
    11mo ago

    very good plugin.

    Read on wp.org ↗
  2. yungcyang
    1.6y ago

    I have been looking for a plugin to manage user access and AAM is by far the best of all. Highly recommended.

    Read on wp.org ↗
  3. Vassos Hadjivassiliou
    2.0y ago

    This plugin is the best out there. I use it every time I have a client that needs to have access to the backend. I can easily make changes to permissions for every user role. 10 stars guys

    Read on wp.org ↗
  4. tomo55555
    2.2y ago

    When we started using this plugin a year or so ago it was good. But now it conflicts with many other plugins and misses out plugins like WPCode. It actually locked me out of the plugin as an administrator, so I had to uninstall AAM.It is a shame because it was once a great plugin.

    Read on wp.org ↗
  5. superwpml
    2.4y ago

    I am looking to hide “metaboxes” in Gutenberg editors, but as far as I understand in the “Metaboxes and Widgets”, in the “Articles” section, when I click hide (Comments, Slug…) .it does nothing.Does it only work in classic editor ?

    Read on wp.org ↗
  6. adamr001
    2.5y ago

    Very comprehensive plugin that was able to do a lot of the things that I needed (especially in comparison to other ones out there when it comes to access management). Support was prompt, professional and very helpful and actually went above and beyond to help me out even after I had misunderstood some of the terms and conditions. They really know their stuff when it comes to WP so you are in good hands!

    Read on wp.org ↗
  7. rosalvoalc
    2.6y ago

    Olá Equipe do Advance Access Manager, Gostaria de expressar minha imensa satisfação com o AAM! Minha experiência com este plugin tem sido excelente, proporcionando um gerenciamento detalhado de usuários e acessos de forma intuitiva e fácil de compreender. O AAM se destaca como o melhor plugin que já encontrei até hoje para lidar com as nuances do controle de usuários e permissões. A interface é amigável, facilitando a configuração e administração das permissões de acesso, tornando todo o processo extremamente eficiente. Agradeço à equipe do Advance Access Manager pelo desenvolvimento de uma ferramenta tão poderosa e eficaz. Continuem o excelente trabalho!

    Read on wp.org ↗
  8. dotboy
    2.8y ago

    Really the quickest and best support I’ve had for any software, ever. Marvellous!

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 7.1.2 Fixed: “Sorry, you are not allowed to give users that role.” when Multi-Role Support is enabled and default_role is not in get_editable_roles() https://github.com/aamplugin/advanced-access-manager/issues/501 Fixed: Incor 7.1.2
  2. Version 7.1.1 Fixed: Incorrectly handled URL with encoded characters https://github.com/aamplugin/advanced-access-manager/issues/500 Fixed: Deprecated: Method ReflectionProperty::setAccessible() is deprecated since 8.5, as it has no e 7.1.1
  3. Version 7.1.0 Fixed: Warning: Undefined array key “effect” in /../application/Framework/Utility/Misc.php on line 483 https://github.com/aamplugin/advanced-access-manager/issues/497 Fixed: Can’t reset ConfigPress https://github.com/aam 7.1.0
  4. Version 7.0.11 Fixed: Advanced Multi-Role setup fails to hide posts https://github.com/aamplugin/advanced-access-manager/issues/491 Fixed: Security Audit References are incorrectly displayed after page refresh https://github.com/aamplu 7.0.11
  5. Version 7.0.10 Fixed: Permalink has empty href when post is password protected https://github.com/aamplugin/advanced-access-manager/issues/487 Fixed: Roles & Capabilities are not syncing in multisite https://github.com/aamplugin/advanc 7.0.10
  6. Version 7.0.9 Fixed: PHP Parse error in php7.4 https://github.com/aamplugin/advanced-access-manager/issues/482 Fixed: Uncaught OutOfRangeException: Cannot find user by identifier 0 in /../Framework/Utility/AccessLevels.php:198 https:/ 7.0.9

Known vulnerabilities

via Wordfence Intelligence

12 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-05-14 CVE-2026-42674 Missing Authorization Affects <= 7.1.0 Patched in 7.1.1
  2. 2024-03-20 CVE-2024-29127 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.9.20 Patched in 6.9.21
  3. 2024-03-16 CVE-2024-29124 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.9.20 Patched in 6.9.21
  4. 2023-12-27 CVE-2023-51675 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 6.9.18 Patched in 6.9.19
  5. 2023-12-27 CVE-2023-51674 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.9.18 Patched in 6.9.19
  6. 2023-12-26 CVE-2023-50881 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.9.15 Patched in 6.9.16
  7. 2021-10-19 CVE-2021-24830 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 6.8.0 Patched in 6.8.0
  8. 2020-08-20 CVE-2020-35934 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 6.6.1 Patched in 6.6.2
  9. 2020-08-14 CVE-2020-35935 Authentication Bypass by Primary Weakness Affects <= 6.6.1 Patched in 6.6.2
  10. 2019-09-09 CVE-2019-25213 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 5.9.9 Patched in 5.9.9
  11. 2016-06-21 Improper Authorization Affects < 3.2.2 Patched in 3.2.2
  12. 2014-08-20 CVE-2014-6059 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 2.8.3 Patched in 2.8.3

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 36 languages, 3 at 90% or more

Dutch 100%
Dutch (Belgium) 100%
Dutch (Formal) 100%
French (France) 81%
Russian 74%
Swedish 61%
Spanish (Chile) 44%
Persian 40%
Japanese 37%
Spanish (Spain) 36%
Czech 26%
German 21%
Ukrainian 8%
Italian 4%
English (Australia) 2%
Norwegian (Bokmål) 2%
Polish 2%
Romanian 2%
Vietnamese 2%
Azerbaijani 1%
Bulgarian 1%
Catalan 1%
Cebuano 1%
Croatian 1%

Plus 12 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

No tier crossings observed yet.

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Advanced Access Manager – Access Governance for WordPress into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/advanced-access-manager" width="480" height="300" style="border:0" loading="lazy" title="Advanced Access Manager – Access Governance for WordPress — Plugin Pulse"></iframe>
Preview card ↗

Advanced Access Manager – Access Governance for WordPress: 100K+ active installs, 4.2★ (420 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/advanced-access-manager