Title: JM Admin Role Lock
Author: Jose Mortellaro
Published: <strong>October 8, 2026</strong>
Last modified: October 8, 2026

---

Search plugins

![](https://ps.w.org/jm-admin-role-lock/assets/banner-772x250.jpg?rev=3734633)

![](https://ps.w.org/jm-admin-role-lock/assets/icon-256x256.jpg?rev=3734626)

# JM Admin Role Lock

 By [Jose Mortellaro](https://profiles.wordpress.org/giuse/)

[Download](https://downloads.wordpress.org/plugin/jm-admin-role-lock.1.1.0.zip)

 * [Details](https://wordpress.org/plugins/jm-admin-role-lock/#description)
 * [Reviews](https://wordpress.org/plugins/jm-admin-role-lock/#reviews)
 *  [Installation](https://wordpress.org/plugins/jm-admin-role-lock/#installation)
 * [Development](https://wordpress.org/plugins/jm-admin-role-lock/#developers)

 [Support](https://wordpress.org/support/plugin/jm-admin-role-lock/)

## Description

JM Admin Role Lock stops new Administrator accounts. Users who are already Administrators
stay Administrators. Nobody else can be given that role.

The plugin blocks the role when WordPress saves it:

 * The Users screens and the users REST API no longer offer Administrator, except
   while editing a user who already has it.
 * A new user cannot be created as an Administrator. If other code requests that
   role anyway, the account is created as Subscriber.
 * An existing user who is not an Administrator cannot be promoted, from the admin
   screens, the REST API, or code that assigns the role.
 * The default role for new users cannot be Administrator. If it already was, activation
   changes it to Subscriber.
 * An Administrator can still be demoted. After that, the role cannot be given back.

On activation the plugin writes the current Administrator user IDs to `administrators.
json` in a `jm-admin-role-lock` folder inside the uploads directory. On every request
it compares that file with the database. A user who has the Administrator role in
the database but is not listed in the file loses the role before the request continues.
When an allowed Administrator is demoted, their ID is removed from the file.

There is no settings screen.

Multisite Super Admin is a network privilege, separate from the Administrator role
on a site. This plugin does not change Super Admin.

#### What a direct database edit can still do

A SQL query can write the role into the database. The next WordPress request removes
it again, as long as `administrators.json` is still the list created by the plugin.

Deleting that file makes the plugin take a new snapshot from whoever is an Administrator
in the database at that moment. Anyone who can edit files on the server can edit
the JSON and add an ID.

## Installation

 1. Upload the `jm-admin-role-lock` folder to `/wp-content/plugins/`.
 2. Activate the plugin through the Plugins screen. On Multisite you can network-activate
    it.
 3. Leave `administrators.json` in the `jm-admin-role-lock` folder of the uploads directory.

## FAQ

### Can I add another Administrator while this plugin is active?

No. The role can only be kept by users who already have it. Deactivate the plugin
before creating or promoting an Administrator, then activate it again so the file
lists the new set of Administrators.

### What happens to an existing Administrator?

They keep the role. Their user profile still shows Administrator, so saving the 
profile does not demote them. You can change them to another role. They cannot be
made an Administrator again after that.

### What if the default role for new users was Administrator?

Activation stores Subscriber instead. While the plugin is active, WordPress will
not save Administrator as the default role.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“JM Admin Role Lock” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ Jose Mortellaro ](https://profiles.wordpress.org/giuse/)

[Translate “JM Admin Role Lock” into your language.](https://translate.wordpress.org/projects/wp-plugins/jm-admin-role-lock)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/jm-admin-role-lock/),
check out the [SVN repository](https://plugins.svn.wordpress.org/jm-admin-role-lock/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/jm-admin-role-lock/)
by [RSS](https://plugins.trac.wordpress.org/log/jm-admin-role-lock/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.1.0

 * Revert an Administrator role written directly in the database, using `administrators.
   json` in the uploads directory.

#### 1.0.0

 * Block granting the Administrator role to users who do not already have it.

## Meta

 *  Version **1.1.0**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.0 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.2 or higher **
 * Tags
 * [administrator](https://wordpress.org/plugins/tags/administrator/)[roles](https://wordpress.org/plugins/tags/roles/)
   [security](https://wordpress.org/plugins/tags/security/)[users](https://wordpress.org/plugins/tags/users/)
 *  [Advanced View](https://wordpress.org/plugins/jm-admin-role-lock/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/jm-admin-role-lock/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/jm-admin-role-lock/reviews/)

## Contributors

 *   [ Jose Mortellaro ](https://profiles.wordpress.org/giuse/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/jm-admin-role-lock/)