• Hi All,

    So I’ve finally gone multisite and it’s got some really cool features that I’m discovering. However one part that I’ve seen has been discussed a bit is the fact that site admins can’t by default install themes on the network. While enabling this feature is certainly possible, the claim is that one had better trust all site admins because who knows what they could upload using this permission (viruses etc).

    I don’t know all my site admins but I feel like one solution would be to go into theme-install.php and comment out the ability to upload files to the server through the theme install interface. This would restrict users to searching the wordpress theme database, posing no increase of security risk as it would operate entirely within a closed network.

    Does anyone have any thoughts on this hack? Am I overlooking something?

Viewing 1 replies (of 1 total)
  • Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    🏳️‍🌈 Advisor and Activist

    My caveats are as follows

    1) Don’t edit core. It’s a terrible idea as you’ll lose your edits every time you upgrade.

    2) Do you really want to support every single theme in the repo? Because when someone has an issue, they’ll come to you, since they can’t make changes.

    Just download the themes people want on demand. It’ll keep your site smaller, and you can be comfortable knowing exactly what’s on your site 🙂

Viewing 1 replies (of 1 total)
  • The topic ‘Possible Solution for Multisite Admins to Install their own themes’ is closed to new replies.