{"id":342353,"date":"2026-08-06T05:27:17","date_gmt":"2026-08-06T05:27:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/arabdown-permissions\/"},"modified":"2026-08-06T05:27:09","modified_gmt":"2026-08-06T05:27:09","slug":"arabdown-permissions","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/arabdown-permissions\/","author":23527731,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.16","stable_tag":"1.1.16","tested":"7.0.3","requires":"6.5","requires_php":"8.1","requires_plugins":null,"header_name":"Arabdown Permissions","header_author":"Asem Alkamel","header_description":"\u0625\u062f\u0627\u0631\u0629 \u0628\u0635\u0631\u064a\u0629 \u0644\u0635\u0644\u0627\u062d\u064a\u0627\u062a \u0627\u0644\u0645\u0633\u062a\u062e\u062f\u0645\u064a\u0646 \u0641\u064a \u0648\u0648\u0631\u062f\u0628\u0631\u064a\u0633: \u0625\u062e\u0641\u0627\u0621 \u0642\u0648\u0627\u0626\u0645 admin \u0648\u0627\u0644\u0625\u0636\u0627\u0641\u0627\u062a \u0648\u0639\u0646\u0627\u0635\u0631 admin bar \u062d\u0633\u0628 \u0627\u0644\u062f\u0648\u0631\u060c \u0623\u062f\u0648\u0627\u0631 \u0645\u062e\u0635\u0651\u0635\u0629\u060c \u0642\u0648\u0627\u0639\u062f \u0632\u0645\u0646\u064a\u0629\u060c 2FA\u060c \u0648\u062d\u0645\u0627\u064a\u0629 \u0627\u0644\u062f\u062e\u0648\u0644 \u2014 \u0645\u0639 \u0633\u062c\u0644 \u062a\u062f\u0642\u064a\u0642 \u0643\u0627\u0645\u0644. \u064a\u064f\u063a\u0644\u0651\u0641 \u0646\u0648\u0627\u0629 Arabdown Core.","assets_banners_color":"567161","last_updated":"2026-08-06 05:27:09","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/arabdown.net\/","header_author_uri":"https:\/\/asemalkamel.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":31,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.16":{"tag":"1.1.16","author":"asemalkamel","date":"2026-08-06 05:27:09"}},"upgrade_notice":{"1.1.8":"<p>Clearer upgrade experience. Recommended for all users.<\/p>","1.1.7":"<p>Hardening and WordPress.org compliance. Recommended for all users.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3636097,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3636097,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3636112,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3636112,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.16"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[83,1913,895,1915,600],"plugin_category":[54,58],"plugin_contributors":[271384],"plugin_business_model":[],"class_list":["post-342353","plugin","type-plugin","status-publish","hentry","plugin_tags-admin","plugin_tags-capabilities","plugin_tags-permissions","plugin_tags-roles","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_category-user-management","plugin_contributors-asemalkamel","plugin_committers-asemalkamel"],"banners":{"banner":"https:\/\/ps.w.org\/arabdown-permissions\/assets\/banner-772x250.png?rev=3636112","banner_2x":"https:\/\/ps.w.org\/arabdown-permissions\/assets\/banner-1544x500.png?rev=3636112","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/arabdown-permissions\/assets\/icon-128x128.png?rev=3636097","icon_2x":"https:\/\/ps.w.org\/arabdown-permissions\/assets\/icon-256x256.png?rev=3636097","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Arabdown Permissions gives you full visual control over what each user role sees inside WordPress, without editing WordPress core capabilities and without writing code. It is RTL-first (built for Arabic) and works with any theme.<\/p>\n\n<h4>Free features<\/h4>\n\n<ul>\n<li><strong>Admin menu control<\/strong> \u2014 hide any menu or submenu from the sidebar per role.<\/li>\n<li><strong>Plugins screen<\/strong> \u2014 hide specific plugins from the Plugins screen per role (visual only; the plugin stays active).<\/li>\n<li><strong>Dashboard widgets<\/strong> \u2014 control dashboard widgets per role.<\/li>\n<li><strong>Admin Bar<\/strong> \u2014 hide specific admin-bar items (WP logo, comments, updates\u2026) or the whole admin bar on the front end, per role.<\/li>\n<li><strong>Custom roles<\/strong> \u2014 create new roles by cloning existing ones, edit their capabilities, and delete safely by moving users to another role.<\/li>\n<li><strong>Activity log<\/strong> \u2014 every sensitive change is logged (who, when, what), with advanced filtering and CSV export.<\/li>\n<li><strong>Preview as role<\/strong> \u2014 preview the site as another role without logging out, with a persistent banner.<\/li>\n<li><strong>Backup \/ Restore<\/strong> \u2014 export all settings and rules as JSON, then restore or move them to another site.<\/li>\n<li><strong>Default-safe<\/strong> \u2014 first activation hides nothing; every rule is added explicitly. Administrator sees everything by default, and the plugin cannot hide itself (lockout protection).<\/li>\n<\/ul>\n\n<h4>A note on the separate security add-on<\/h4>\n\n<p>Everything listed above is free and fully functional: nothing in this plugin is limited, time-boxed or locked behind a key.<\/p>\n\n<p>Advanced security features (two-factor authentication, login protection, time-based access rules, security alerts and emergency access) are developed as a <strong>separate commercial plugin<\/strong>. Its code is not part of this download and this plugin contains no licence check, no upgrade prompt and no reference to it in the admin.<\/p>\n\n<h4>\u0628\u0627\u0644\u0639\u0631\u0628\u064a\u0629<\/h4>\n\n<p><strong>\u0639\u0631\u0628 \u062f\u0627\u0648\u0646 \u0644\u0644\u0635\u0644\u0627\u062d\u064a\u0627\u062a<\/strong>: \u062a\u062d\u0643\u0651\u0645 \u0628\u0635\u0631\u064a\u0651 \u0643\u0627\u0645\u0644 \u0628\u0645\u0627 \u064a\u0631\u0627\u0647 \u0643\u0644 \u062f\u0648\u0631 \u0645\u0633\u062a\u062e\u062f\u0645 \u0641\u064a \u0648\u0648\u0631\u062f\u0628\u0631\u064a\u0633 \u2014 \u0625\u062e\u0641\u0627\u0621 \u0642\u0648\u0627\u0626\u0645 \u0644\u0648\u062d\u0629 \u0627\u0644\u062a\u062d\u0643\u0651\u0645\u060c \u0627\u0644\u0625\u0636\u0627\u0641\u0627\u062a\u060c \u0627\u0644\u0648\u062f\u062c\u062a\u060c \u0648\u0639\u0646\u0627\u0635\u0631 \u0634\u0631\u064a\u0637 \u0627\u0644\u0623\u062f\u0648\u0627\u062a \u062d\u0633\u0628 \u0627\u0644\u062f\u0648\u0631\u060c \u0639\u0628\u0631 \u0645\u0641\u0627\u062a\u064a\u062d \u062a\u0628\u062f\u064a\u0644 \u0648\u0628\u0644\u0627 \u0643\u0648\u062f. \u0639\u0631\u0628\u064a\u0651 \u0648RTL \u0623\u0648\u0651\u0644\u064b\u0627\u060c \u0648\u064a\u0639\u0645\u0644 \u0645\u0639 \u0623\u064a\u0651 \u0642\u0627\u0644\u0628. \u0644\u0627 \u064a\u0639\u062f\u0651\u0644 \u0635\u0644\u0627\u062d\u064a\u0627\u062a \u0648\u0648\u0631\u062f\u0628\u0631\u064a\u0633 \u0627\u0644\u0623\u0633\u0627\u0633\u064a\u0629\u060c \u0648\u0627\u0644\u0645\u062f\u064a\u0631 \u0645\u062d\u0645\u064a\u0651 \u0645\u0646 \u0627\u0644\u0625\u0642\u0641\u0627\u0644.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin uses no external or third-party services.<\/p>\n\n<p>It runs entirely on your own server: it makes no remote HTTP requests of any kind, sends no data anywhere, contacts no licence server, and includes no analytics or tracking. This is verifiable in the source \u2014 the package contains no call to wp_remote_* and no external endpoint.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install from the WordPress plugin directory, or upload the <code>arabdown-permissions<\/code> folder to <code>wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate it from the Plugins screen.<\/li>\n<li>Open \"Arabdown Permissions\" and start hiding menus \/ plugins \/ widgets per role with toggles.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20modify%20wordpress%20core%20capabilities%3F\"><h3>Does it modify WordPress core capabilities?<\/h3><\/dt>\n<dd><p>No. The visual hiding is applied per role without changing core capabilities, so nothing breaks if you deactivate the plugin.<\/p><\/dd>\n<dt id=\"can%20i%20lock%20myself%20out%3F\"><h3>Can I lock myself out?<\/h3><\/dt>\n<dd><p>No. Administrator sees everything by default, and the plugin cannot hide itself.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20any%20theme%3F\"><h3>Does it work with any theme?<\/h3><\/dt>\n<dd><p>Yes \u2014 it is theme-independent and fully supports RTL.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.16<\/h4>\n\n<ul>\n<li>Hardened settings import: every imported field is now sanitized recursively (keys via sanitize_key, strings via sanitize_text_field, scalars preserved) using the same sanitizer as the AJAX importer, instead of writing uploaded JSON values after a structural check only.<\/li>\n<\/ul>\n\n<h4>1.1.15<\/h4>\n\n<ul>\n<li>Fixed: with the \"suspicious activity\" filter on, the audit-log query passed literal <code>%<\/code> patterns to $wpdb-&gt;prepare(), which read them as placeholders and broke the query. Those patterns are now bound as placeholders.<\/li>\n<li>Fixed a malformed PHP opening tag introduced while trimming the build.<\/li>\n<\/ul>\n\n<h4>1.1.14<\/h4>\n\n<ul>\n<li>This build contains no licence checks at all: every feature it ships is free and fully functional, including audit-log CSV export. The advanced security features are a separate plugin whose code is not included here.<\/li>\n<li>The bundled Arabdown framework now ships in a lean form for this plugin: the AI-provider, Google-integration and licensing layers are not included, so the package makes no outbound HTTP request of any kind.<\/li>\n<li>Sanitization: the audit export link is rebuilt from an explicit whitelist of sanitized filters, imported backup values are sanitized recursively, and the uploaded file name goes through sanitize_file_name().<\/li>\n<li>AJAX actions now use the full <code>arabdown_perm_<\/code> prefix.<\/li>\n<li>All gettext calls in the package use the plugin's own text domain.<\/li>\n<\/ul>\n\n<h4>1.1.12<\/h4>\n\n<ul>\n<li>First WordPress.org release. The free layer is complete and standalone (menu \/ plugins \/ widgets \/ admin-bar control per role, custom roles, activity log, preview-as-role, backup &amp; restore). The optional Pro security layer (2FA, login protection, time rules, alerts, emergency access, audit export) is a separate purchase and is not bundled here \u2014 its features appear as clearly-labelled locked panels with an honest upgrade path.<\/li>\n<li>Hidden tool pages register under a proper parent, fixing a PHP 8.1 deprecation notice from WordPress core's admin-header on those screens.<\/li>\n<li>Hardening pass: every remaining input read is sanitized or explicitly justified; SQL uses prepared placeholders throughout.<\/li>\n<\/ul>\n\n<h4>1.1.8<\/h4>\n\n<ul>\n<li>Unified premium upgrade experience: a central plans catalog, an upgrade popup, an honest plans-comparison table, and clearer \"you have a key \u2014 activate\" paths on the overview. No change to the free feature set or to how the plugin updates.<\/li>\n<\/ul>\n\n<h4>1.1.7<\/h4>\n\n<ul>\n<li>Hardening &amp; WordPress.org compliance: inline scripts and styles are now enqueued; inputs are sanitized and outputs escaped. The free plugin makes no remote calls (it updates via WordPress.org). Optional Pro licence activation is opt-in and documented above.<\/li>\n<\/ul>","raw_excerpt":"Visual control over what each user role sees in WordPress: hide admin menus, plugins, widgets, and admin-bar items per role \u2014 with toggles, no code.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/342353","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=342353"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/asemalkamel"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=342353"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=342353"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=342353"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=342353"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=342353"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=342353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}