{"id":364140,"date":"2026-09-10T18:04:18","date_gmt":"2026-09-10T18:04:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/temporary-admin-access\/"},"modified":"2026-09-10T18:04:09","modified_gmt":"2026-09-10T18:04:09","slug":"tempaccessly","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/tempaccessly\/","author":23467212,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1","requires":"6.2","requires_php":"7.2","requires_plugins":null,"header_name":"TempAccessly \u2013 Temporary Admin Access","header_author":"Akshar Makwana","header_description":"Create secure, time-limited WordPress access for developers, support teams, freelancers, and clients without sharing permanent passwords.","assets_banners_color":"b0befc","last_updated":"2026-09-10 18:04:09","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/gravatar.com\/aksharmakwana6\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":50,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"aksharmakwana6","date":"2026-09-10 18:04:09","revision":3690311}},"upgrade_notice":{"1.0.0":"<p>Initial public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3690311,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3690311,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3690311,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3690311,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3690311,"resolution":"1","location":"assets","locale":"","width":1919,"height":944},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3690322,"resolution":"2","location":"assets","locale":"","width":1919,"height":944},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3690322,"resolution":"3","location":"assets","locale":"","width":1919,"height":944},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3690322,"resolution":"4","location":"assets","locale":"","width":1919,"height":944},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3690311,"resolution":"5","location":"assets","locale":"","width":1919,"height":944}},"screenshots":{"1":"TempAccessly dashboard and access list.","2":"Create temporary access form.","3":"One-time login URL screen.","4":"TempAccessly settings.","5":"TempAccessly audit logs."}},"plugin_section":[],"plugin_tags":[245949,279831,35316,140155,140222],"plugin_category":[],"plugin_contributors":[278687],"plugin_business_model":[],"class_list":["post-364140","plugin","type-plugin","status-publish","hentry","plugin_tags-admin-access","plugin_tags-developer-access","plugin_tags-passwordless-login","plugin_tags-temporary-access","plugin_tags-temporary-login","plugin_contributors-aksharmakwana6","plugin_committers-aksharmakwana6"],"banners":{"banner":"https:\/\/ps.w.org\/tempaccessly\/assets\/banner-772x250.png?rev=3690311","banner_2x":"https:\/\/ps.w.org\/tempaccessly\/assets\/banner-1544x500.png?rev=3690311","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/tempaccessly\/assets\/icon-128x128.png?rev=3690311","icon_2x":"https:\/\/ps.w.org\/tempaccessly\/assets\/icon-256x256.png?rev=3690311","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/tempaccessly\/assets\/screenshot-1.png?rev=3690311","caption":"TempAccessly dashboard and access list."},{"src":"https:\/\/ps.w.org\/tempaccessly\/assets\/screenshot-2.png?rev=3690322","caption":"Create temporary access form."},{"src":"https:\/\/ps.w.org\/tempaccessly\/assets\/screenshot-3.png?rev=3690322","caption":"One-time login URL screen."},{"src":"https:\/\/ps.w.org\/tempaccessly\/assets\/screenshot-4.png?rev=3690322","caption":"TempAccessly settings."},{"src":"https:\/\/ps.w.org\/tempaccessly\/assets\/screenshot-5.png?rev=3690311","caption":"TempAccessly audit logs."}],"raw_content":"<!--section=description-->\n<p>TempAccessly lets a site administrator create a dedicated temporary WordPress user and generate a secure login URL. The account is automatically controlled by the configured expiration time and can be revoked, extended, or given a newly generated login link at any time.<\/p>\n\n<p>The login token is a 256-bit random value. Only a salted SHA-256 token hash is stored in the access table; the raw token is shown once to the administrator and is not stored in the plugin database or audit log.<\/p>\n\n<p>The plugin adds these pages under <strong>Users<\/strong>:<\/p>\n\n<ul>\n<li><strong>TempAccessly \u2013 Temporary Admin Access<\/strong> \u2014 create and manage temporary access records.<\/li>\n<li><strong>TempAccessly Settings<\/strong> \u2014 configure default role, duration, maximum duration, and account cleanup.<\/li>\n<li><strong>TempAccessly Audit Logs<\/strong> \u2014 review access lifecycle events.<\/li>\n<\/ul>\n\n<h3>Key Features<\/h3>\n\n<ul>\n<li>Dedicated temporary WordPress accounts that do not modify permanent users.<\/li>\n<li>Passwordless, token-protected login URLs with automatic expiration.<\/li>\n<li>Role selection with an explicit confirmation requirement for Administrator access.<\/li>\n<li>Duration presets from 15 minutes through 7 days, limited by the configured maximum.<\/li>\n<li>Real-time checks that block expired, revoked, disabled, or orphaned temporary accounts.<\/li>\n<li>Immediate revoke, active-session termination, token regeneration, and controlled extension.<\/li>\n<li>Automatic cleanup of temporary accounts and old access records.<\/li>\n<li>Audit logging for creation, login success\/failure, extension, regeneration, revocation, expiration, and deletion.<\/li>\n<li>WordPress personal-data export and erasure integration.<\/li>\n<\/ul>\n\n<h3>Security<\/h3>\n\n<p>TempAccessly uses:<\/p>\n\n<ul>\n<li>Cryptographically secure 256-bit random tokens.<\/li>\n<li>Salted SHA-256 token hashes instead of storing raw login tokens.<\/li>\n<li>WordPress nonces for state-changing admin and AJAX requests.<\/li>\n<li><code>manage_options<\/code> capability checks for plugin administration.<\/li>\n<li>Server-side allow-list validation for roles, durations, access IDs, and administrator confirmation.<\/li>\n<li>Sanitization on request data and escaping on admin output.<\/li>\n<li>Prepared SQL statements for variable database values and allow-listed SQL identifiers.<\/li>\n<li>Immediate session destruction and authentication blocking for revoked, expired, and disabled accounts.<\/li>\n<li>Strict safeguards before a temporary user can be deleted or disabled, including a plugin-owned user marker, username prefix, and protection for user ID 1.<\/li>\n<\/ul>\n\n<p><strong>Important:<\/strong> A login URL is a bearer credential. Anyone who has an active URL can use the linked temporary account. Share URLs only with the intended recipient through a secure channel. Regenerating or revoking access invalidates the previous URL.<\/p>\n\n<h3>How It Works<\/h3>\n\n<ol>\n<li>Go to <strong>Users &gt; TempAccessly \u2013 Temporary Admin Access<\/strong>.<\/li>\n<li>Click <strong>+ Create Temporary Access<\/strong>.<\/li>\n<li>Enter the recipient name, optional email, role, duration, and optional notes.<\/li>\n<li>Confirm the warning when assigning the Administrator role.<\/li>\n<li>Copy the generated login URL and share it securely.<\/li>\n<li>Manage the record with <strong>Extend<\/strong>, <strong>Regenerate<\/strong>, <strong>Revoke<\/strong>, or <strong>Delete<\/strong>.<\/li>\n<\/ol>\n\n<p>JavaScript is used for the normal creation interface. A server-side form handler remains available for the creation, revoke, and delete operations.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>TempAccessly processes data required to create, authenticate, manage, expire, and audit temporary access.<\/p>\n\n<h4>Data stored<\/h4>\n\n<p>Depending on the fields used and activity recorded, the plugin may store:<\/p>\n\n<ul>\n<li>Recipient name and optional recipient email address.<\/li>\n<li>Optional purpose or notes.<\/li>\n<li>Temporary WordPress username and user ID, assigned role, creator user ID, status, and lifecycle timestamps.<\/li>\n<li>Audit actions and timestamps.<\/li>\n<li>IP address and browser user-agent for audit events when provided by the web server.<\/li>\n<li>Temporary-user session data managed by WordPress while the recipient is signed in.<\/li>\n<\/ul>\n\n<p>Raw login tokens and passwords are not stored in the plugin access records or audit logs.<\/p>\n\n<h4>Why is the data used?<\/h4>\n\n<p>The data is used to provision temporary users, validate login links, enforce expiration and revocation, terminate temporary sessions, display access records, and provide an audit trail.<\/p>\n\n<h4>Who can access the data?<\/h4>\n\n<p>Plugin administration and access records are available only to users with the <code>manage_options<\/code> capability.<\/p>\n\n<h4>Data sharing<\/h4>\n\n<p>The plugin does not transmit this data to external services, APIs, or third parties.<\/p>\n\n<h4>Retention<\/h4>\n\n<ul>\n<li>Active records remain while access is active.<\/li>\n<li>Expired and revoked access records are eligible for removal after 30 days through the scheduled cleanup task.<\/li>\n<li>Temporary accounts are deleted by default after expiration or revocation; when automatic deletion is disabled, they are retained in a disabled state.<\/li>\n<li>Related audit events are removed when the corresponding access record is removed by retention cleanup or personal-data erasure. A manual access deletion may record a final deletion event before retention removes it.<\/li>\n<\/ul>\n\n<h4>Export and erasure<\/h4>\n\n<p>TempAccessly registers with <strong>Tools &gt; Export Personal Data<\/strong> and <strong>Tools &gt; Erase Personal Data<\/strong>. Matching access records are located by recipient email address. Export includes the matching access information and related audit events. Erasure removes matching temporary accounts, access records, and associated audit events where the data is available.<\/p>\n\n<h4>Uninstallation<\/h4>\n\n<p>When uninstalled through WordPress, TempAccessly removes plugin-created temporary accounts, both plugin tables, plugin options, and the scheduled cleanup hook.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>tempaccessly<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or upload the ZIP from <strong>Plugins &gt; Add New &gt; Upload Plugin<\/strong>.<\/li>\n<li>Activate <strong>TempAccessly \u2013 Temporary Admin Access<\/strong>.<\/li>\n<li>Open <strong>Users &gt; TempAccessly \u2013 Temporary Admin Access<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20i%20create%20administrator%20access%3F\"><h3>Can I create Administrator access?<\/h3><\/dt>\n<dd><p>Yes. Administrator is available when the role exists on the site, but the creation form requires an explicit confirmation because it grants full site control.<\/p><\/dd>\n<dt id=\"does%20the%20recipient%20need%20a%20password%3F\"><h3>Does the recipient need a password?<\/h3><\/dt>\n<dd><p>No. The recipient uses the generated login URL while the access record is active.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20access%20expires%3F\"><h3>What happens when access expires?<\/h3><\/dt>\n<dd><p>The token stops working, active sessions are terminated, and the temporary account is deleted by default. When automatic deletion is disabled, the temporary account is disabled instead. A daily WP-Cron task also performs retention cleanup; WP-Cron execution can be delayed on low-traffic sites.<\/p><\/dd>\n<dt id=\"can%20i%20revoke%20access%20before%20it%20expires%3F\"><h3>Can I revoke access before it expires?<\/h3><\/dt>\n<dd><p>Yes. Revocation invalidates the token, terminates active sessions, and deletes or disables the temporary account according to the cleanup setting.<\/p><\/dd>\n<dt id=\"can%20i%20regenerate%20a%20login%20link%3F\"><h3>Can I regenerate a login link?<\/h3><\/dt>\n<dd><p>Yes. Regeneration creates a new token and invalidates the previous URL while retaining the same account and expiration.<\/p><\/dd>\n<dt id=\"can%20i%20extend%20access%3F\"><h3>Can I extend access?<\/h3><\/dt>\n<dd><p>Yes. Only active records can be extended, and the new expiration cannot exceed the configured maximum duration measured from the original creation time.<\/p><\/dd>\n<dt id=\"are%20permanent%20users%20affected%3F\"><h3>Are permanent users affected?<\/h3><\/dt>\n<dd><p>No. TempAccessly only deletes or disables accounts that carry its own temporary-user marker and expected username prefix. User ID 1 is always protected.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20use%20an%20external%20service%3F\"><h3>Does the plugin use an external service?<\/h3><\/dt>\n<dd><p>No. TempAccessly does not send access, account, or audit information to an external API or third-party service.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Renamed the plugin to a distinctive product name and aligned the slug, folder, main file, text domain, and translation template.<\/li>\n<li>Replaced the short TAA prefix with the unique <code>tempaccessly<\/code> prefix across plugin-owned code, options, metadata, tables, AJAX actions, CSS, and JavaScript.<\/li>\n<li>Removed plugin-owned <code>function_exists()<\/code> and <code>class_exists()<\/code> guards so the plugin no longer relies on collision-prone conditional declarations.<\/li>\n<li>Reviewed capability checks, nonce verification, input sanitization, output escaping, SQL preparation, token handling, temporary-user safeguards, and stored-data handling.<\/li>\n<li>Improved cleanup of related audit events and updated privacy documentation.<\/li>\n<\/ul>","raw_excerpt":"Create secure, time-limited WordPress access for trusted developers, support teams, freelancers, and clients without sharing a permanent password.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/364140","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=364140"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/aksharmakwana6"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=364140"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=364140"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=364140"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=364140"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=364140"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=364140"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}