{"id":341177,"date":"2026-07-28T05:47:17","date_gmt":"2026-07-28T05:47:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/access-policy-manager\/"},"modified":"2026-07-28T05:47:09","modified_gmt":"2026-07-28T05:47:09","slug":"ncdlabs-site-access-policies","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/ncdlabs-site-access-policies\/","author":23533509,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.0.2","requires":"6.8","requires_php":"8.3","requires_plugins":null,"header_name":"ncdLabs Site Access Policies","header_author":"Lou Grossi","header_description":"Modern Identity and Access Management for WordPress \u2014 policy-based site, hostname, and path protection with passwords, passkeys, and WordPress users.","assets_banners_color":"313f62","last_updated":"2026-07-28 05:47:09","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/ncdlabs.com\/ncdlabs-site-access-policies\/","header_author_uri":"https:\/\/ncdlabs.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":34,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"ncdlou","date":"2026-07-28 05:47:09"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3625418,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3625418,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3625418,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3625418,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3625418,"resolution":"1","location":"assets","locale":"","width":2808,"height":1736},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3625418,"resolution":"2","location":"assets","locale":"","width":2808,"height":1736},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3625418,"resolution":"3","location":"assets","locale":"","width":2808,"height":1736}},"screenshots":{"1":"Security Dashboard \u2014 protection status, recommendations, and quick actions.","2":"Policies \u2014 ordered first-match rules for site, hostname, and path protection.","3":"Policy Simulator \u2014 try sample requests through the live decision pipeline safely."}},"plugin_section":[],"plugin_tags":[1912,710,2470,222353,19979],"plugin_category":[38],"plugin_contributors":[273565],"plugin_business_model":[],"class_list":["post-341177","plugin","type-plugin","status-publish","hentry","plugin_tags-access-control","plugin_tags-authentication","plugin_tags-authorization","plugin_tags-passkeys","plugin_tags-staging","plugin_category-authentication","plugin_contributors-ncdlou","plugin_committers-ncdlou"],"banners":{"banner":"https:\/\/ps.w.org\/ncdlabs-site-access-policies\/assets\/banner-772x250.png?rev=3625418","banner_2x":"https:\/\/ps.w.org\/ncdlabs-site-access-policies\/assets\/banner-1544x500.png?rev=3625418","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ncdlabs-site-access-policies\/assets\/icon-128x128.png?rev=3625418","icon_2x":"https:\/\/ps.w.org\/ncdlabs-site-access-policies\/assets\/icon-256x256.png?rev=3625418","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/ncdlabs-site-access-policies\/assets\/screenshot-1.png?rev=3625418","caption":"Security Dashboard \u2014 protection status, recommendations, and quick actions."},{"src":"https:\/\/ps.w.org\/ncdlabs-site-access-policies\/assets\/screenshot-2.png?rev=3625418","caption":"Policies \u2014 ordered first-match rules for site, hostname, and path protection."},{"src":"https:\/\/ps.w.org\/ncdlabs-site-access-policies\/assets\/screenshot-3.png?rev=3625418","caption":"Policy Simulator \u2014 try sample requests through the live decision pipeline safely."}],"raw_content":"<!--section=description-->\n<p>ncdLabs Site Access Policies is a policy-based access layer for WordPress. Protect entire sites, hostnames, and URL paths with passwords, passkeys, and WordPress users \u2014 without server configuration.<\/p>\n\n<h4>Included in Free<\/h4>\n\n<ul>\n<li>Unlimited policies with drag-and-drop ordering<\/li>\n<li>Exact and wildcard hostname\/path matching<\/li>\n<li>Password, passkey, and WordPress login authentication<\/li>\n<li>User, role, and capability authorization (boolean authz trees)<\/li>\n<li>Secure sessions, audit log, simulator, analyzer, and recovery<\/li>\n<\/ul>\n\n<h4>Optional Premium companion (sold separately)<\/h4>\n\n<p>Advanced capabilities (access groups, custom appearance profiles, SSO\/IdP, SCIM, agency multisite tools, and more) are provided by a <strong>separate Premium plugin<\/strong> you download from ncdLabs after purchase. The Free plugin never locks included code behind a license key.<\/p>\n\n<p>Product page: https:\/\/ncdlabs.com\/ncdlabs-site-access-policies\/<\/p>\n\n<h4>Privacy<\/h4>\n\n<p>By default this plugin does <strong>not<\/strong> contact external servers. Optional integrations you configure yourself (identity providers, SIEM webhooks, cloud backups) send only the data required for that service. Password hashes and private keys are never transmitted to cloud backups.<\/p>\n\n<p>Full notice: https:\/\/ncdlabs.com\/products\/ncdlabs-site-access-policies\/privacy\/<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/ncdlabs-site-access-policies<\/code><\/li>\n<li>Activate through the Plugins screen<\/li>\n<li>Open Access Policies in WP Admin and create your first policy<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20free%20require%20a%20license%20key%3F\"><h3>Does Free require a license key?<\/h3><\/dt>\n<dd><p>No. Every feature shipped in the Free plugin works without payment. Premium is a separate download.<\/p><\/dd>\n<dt id=\"where%20is%20the%20source%20for%20the%20admin%20javascript%3F\"><h3>Where is the source for the admin JavaScript?<\/h3><\/dt>\n<dd><p>Unminified sources live in <code>resources\/js\/<\/code>. Build with <code>npm install &amp;&amp; npm run build<\/code>. Development repository: https:\/\/git.ncdlabs.com\/ncdlabs\/ncdlabs-site-access-policies<\/p><\/dd>\n<dt id=\"is%20this%20plugin%20gplv2%20compatible%3F\"><h3>Is this plugin GPLv2 compatible?<\/h3><\/dt>\n<dd><p>Yes. The plugin is licensed GPLv2 or later. Bundled production libraries are GPL-compatible (MIT\/BSD). Self-hosted IBM Plex fonts use the SIL Open Font License.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>WordPress.org review follow-up: dbDelta via require_once + immediate call helper; no wholesale $_GET\/$_SERVER\/$_COOKIE assignment in request context factory<\/li>\n<li>Removed RequestVars get\/request helpers; recovery\/email-verify use registered query_vars; admin screen detection via get_current_screen; AJAX allowlist uses heartbeat nonce \/ caps<\/li>\n<li>Custom-table services\/migrations declare justified DirectDatabaseQuery phpcs:disable (TableNames allowlist; prepared queries \/ %i)<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>WordPress.org review remediations: dbDelta upgrade.php guard, prepared DDL migrations (%i), challenge assets enqueue static fallbacks (no inline CSS\/JS)<\/li>\n<li>Clarified read-only request adapters (RequestVars \/ RequestContextFactory); mutations remain REST + caps + wp_rest nonce<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial WordPress.org Free release with Premium companion model<\/li>\n<li>Production Decision Engine pipeline (Conditions, Authentication, Authorization, Challenge)<\/li>\n<li>Authorization uses boolean AuthzTree (legacy flat OR migrates on read\/write)<\/li>\n<li>Password vault: policies reference vault credentials via <code>password_id<\/code> (one password, many policies)<\/li>\n<li>Policy Simulator and Evaluation Trace; Support Mode live-trace auto-expires after 1 hour<\/li>\n<li>PePper contextual guidance; design-system admin SPA<\/li>\n<li>Idempotent DB migrations; no required wipe on upgrade<\/li>\n<\/ul>","raw_excerpt":"Modern Identity and Access Management for WordPress \u2014 policy-based site, hostname, and path protection.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/341177","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=341177"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/ncdlou"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=341177"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=341177"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=341177"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=341177"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=341177"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=341177"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}