How to lock the WordPress plugin and theme editor

Anyone with an administrator login can rewrite your plugins from the browser. Here is how to close that door, and what each option costs you.

A grid of code cards with a large padlock in front of them.

WordPress ships with a plugin file editor and a theme file editor under Tools and Appearance. Any administrator can open a plugin's PHP and change it, live, with no review and no record. That includes a developer you gave access to last year, and anyone who steals an administrator's password.

WordPress itself recommends turning the editors off. There are three ways to do it.

1. DISALLOW_FILE_EDIT: turn the editors off

Add one line to wp-config.php, above the line that says to stop editing:

define( 'DISALLOW_FILE_EDIT', true );

The plugin and theme file editors disappear for every user. Plugins and themes can still be installed, updated and deleted from the admin.

The catch: it is all or nothing, it lives in a file only someone with server access can change, and it does nothing about the other ways code arrives: uploading a plugin zip, or installing one that writes files itself.

2. DISALLOW_FILE_MODS: stop every change from the admin

define( 'DISALLOW_FILE_MODS', true );

This goes further. No installs, no uploads, no deletes, and no updates from the admin either, including automatic ones. Code can only change over FTP, SSH or your deployment pipeline.

The catch: you now own every update by hand, including security fixes. On a site nobody deploys to regularly, that is how plugins go stale and vulnerable.

3. A lock only a site owner can lift

The middle path: lock the editors and stop uploads, installs and deletes from the admin, but let updates run, and let a named site owner lift the lock for an hour when they genuinely need it. That is what Touchstone's Code lock does:

  • The editors are locked the moment Touchstone is activated, for everyone, administrators included.
  • One click allows code changes only over FTP: no editors, uploads, installs or deletes from the admin. Updates still run.
  • Only a site owner can loosen it, and an hour later it locks itself again. Other administrators, including developers, cannot.
  • It lists the installed plugins that could get around the lock, such as file managers and code-snippet plugins, so you can decide whether you need them.

Which should you use?

Editors offInstalls and uploads offUpdates still runOwner can lift it for an hour
DISALLOW_FILE_EDITYesNoYesNo
DISALLOW_FILE_MODSYesYesNoNo
Touchstone Code lockYesYesYesYes

What none of them can stop

Anyone with FTP or server access can still change files and even remove the plugin that guards them. A plugin can write files with PHP directly. So a lock is half the job: the other half is noticing a change. Touchstone checks every code file against WordPress.org's official fingerprints each day and names any file that changed. How a file integrity check works.

Related: WordPress file integrity check and the EssentialPlugin backdoor, replayed.