Most WordPress site owners do not think about their user roles until something goes wrong. A client calls to say their site is showing strange content. You log into the dashboard and find an administrator account you did not create. The attacker has been inside for weeks — quietly, because no plugin caught them getting in.
This is the scenario that Ethwebs Role Auditor was built to prevent. It catches privilege escalation attacks that most well-known WordPress security plugins simply cannot — because of a fundamental gap in how standard security logging works.
The Gap in Standard WordPress Security Plugins
Most WordPress security and activity log plugins — even popular paid options — work strictly by listening to WordPress action hooks. When someone logs in, wp_login fires. When a new user is created through the WordPress dashboard, user_register fires. The plugin catches these events and logs or alerts accordingly.
This works well for normal admin activity, but it has a critical blind spot: SQL injection attacks.
When an attacker exploits a database vulnerability in an outdated plugin, theme, or configuration, they do not create an admin account through the standard WordPress dashboard. They insert rows directly into the wp_users and wp_usermeta database tables using raw SQL. WordPress action hooks never fire, standard activity loggers see nothing, and the attacker quietly gains full administrative control.
If you have ever cleaned a compromised WordPress site, you have likely found rogue administrator accounts that appeared with zero audit trail in traditional security plugins.
How Ethwebs Role Auditor Works Differently
Instead of relying solely on runtime hooks, Ethwebs Role Auditor runs direct, prefix-aware SQL queries against your database during scheduled and on-demand audits. It inspects table capabilities directly to count and identify every user holding administrator privileges — regardless of how that account got there.
If an attacker injects an admin record directly into your database, the next audit flags it immediately. You receive an email alert, while our Attacker Exclusion Safeguard automatically strips the rogue email from the notification list so the attacker never knows they were detected.
Key Features
Direct Database SQL Audit
Queries the database directly using prefix-aware SQL to count and identify every user account holding administrator capabilities. Catches silent database modifications from SQL injection attacks that bypass the WordPress hook layer entirely.
Instant Dashboard Status
Open the settings page and view a live database audit table immediately — real-time user counts per role and active admin user IDs pulled directly from the database on page load.
Smart Email Subject Line Previews
The email subject line itself shows current admin and editor counts (e.g. [Ethwebs Audit] Site Name — Status Clean (Admins: 1 | Editors: 2)), allowing you to verify role integrity directly from your inbox without opening the email.
Multiple Recipient Notifications
Enter comma-separated email addresses to notify your entire team. Ideal for web designers and agencies managing multiple client sites alongside site owners.
Attacker Exclusion Safeguard
When an instant role elevation alert fires, the plugin automatically strips the newly promoted user’s email address from the recipient list, ensuring attackers never receive alerts about their own detection.
Manual “Run Check Now” Trigger
Trigger an on-demand database scan and email dispatch directly from the admin panel to verify baseline security and test email routing immediately after activation.
Instant Role Elevation Alerts
Dispatches immediate email notifications whenever an existing user is elevated or assigned to the Administrator or Editor role inside WordPress.
Persistent Admin IP Access Detection
Maintains a persistent whitelist of recognized admin IP addresses. When an administrator accesses the dashboard from an unfamiliar IP or new network, an alert is dispatched to flag potential credential leaks.
Zero Database Bloat
Creates zero custom tables. Unlike heavy activity log plugins that write thousands of rows to your database on every visit, Ethwebs Role Auditor uses standard background crons and native user metadata. Your database stays lean and fast.
Who Should Install This?
Low-traffic and small business websites are frequently targeted specifically because they are less actively monitored. Attackers use compromised access to inject spam links, host phishing pages, or pivot to other sites on shared servers.
- WordPress Site Owners: Get automated peace of mind without configuring complex firewall rules.
- Web Designers & Agencies: Add your monitoring email across client sites to spot unauthorized changes instantly.
- WooCommerce Stores: Protect customer records, order details, and payment configurations from hidden admin takeovers.
- Blogs & Content Sites: Prevent stealth takeovers that cause Google search deindexing and malware blacklisting.
- Sites with Legacy Plugins: Catch vulnerabilities exploited in older, unmaintained codebases.
A note for web designers in Kerala and Wayanad: Many small business WordPress sites in our region are launched and left unattended without ongoing security maintenance. Installing Ethwebs Role Auditor takes two minutes, adds zero database overhead, and provides an essential safety net.
Installation & Setup
- Log in to your WordPress Dashboard and go to Plugins → Add New.
- Search for Ethwebs Role Auditor.
- Click Install Now, then click Activate.
- Navigate to Settings → Ethwebs Role Auditor.
- Configure your notification email addresses and set your baseline Maximum Expected Admins (usually 1 or 2).
- Click Run Check Now & Send Email to test your setup and verify your live database table.
Note: The live database audit table displays directly inside your WordPress dashboard at all times, even without an active SMTP email configuration.
Plugin Specifications
- Version: 1.0.1
- WordPress Compatibility: 5.8 to 7.1
- PHP Requirement: 7.4 or higher
- Custom Database Tables: Zero
- Performance Impact: Negligible (zero frontend page-load overhead)
- Developer: Sanmatiraj, Ethweb Datacomm, Muttil, Wayanad, Kerala
Download Free on WordPress.org Chat on WhatsApp for Setup Help
Support Open Source Development
Ethwebs Role Auditor is completely free open-source software with no paid paywalls or upsells. If this tool helps protect your websites or client projects, contributions help support ongoing updates and compatibility testing:
- PayPal: paypal.me/ethwebs
- UPI:
srpj@jio(Google Pay, PhonePe, Paytm, BHIM)
Explore all Ethwebs tools and donation options at wayanad.co.in/wordpress-plugins.
For professional web development and hosting inquiries, visit ethwebs.net.
Ethwebs Role Auditor is open-source software hosted on the official WordPress.org plugin directory. Support is provided via the official WordPress.org support forums.
