BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
LeanRoles – User Tags & Role Performance Audit icon
Actively maintained Tested with WP 7.1 #31 in capabilities

LeanRoles – User Tags & Role Performance Audit

Audits what your user roles cost on every request, and adds user tags: label users without creating roles that grant nothing and weigh nothing.

Active installs<10New
Downloads · 30d85▼ -59.9% vs prev. 30d
Rating—0 reviews
Health score64/100Good
All-time downloads251Since Aug 2026
Support resolved—No recent threads
RequiresWP 5.9PHP 7.4+
Downloads · 7d29▲ +52.6% week over week
Our verdict

Solid choice

LeanRoles is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 6 hours ago, and scores 64/100 on our health check.

  • Actively developed — last update 6 hours ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

142842Aug 25Sep 15Oct 6
Yesterday2
Daily average (1y)6
Peak day56Aug 25, 2026
Last 12 months258

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where LeanRoles stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
capabilities >100 7,895 Best capabilities plugins →
multisite >100 5,597 Best multisite plugins →
user management >100 8,006 Best user management plugins →
user roles >100 5,784 Best user roles plugins →
user tags >100 10,000 Best user tags plugins →

About LeanRoles

From the official readme · v0.6.3

Description

WordPress keeps every role in one autoloaded option, with each role’s capabilities copied out in full, because core has no inheritance. On a membership or commerce site with forty roles that option is read, unserialized and held in memory by every PHP worker on every request — and those are exactly the sites whose traffic is mostly logged in, so page caching never gets a look in.

LeanRoles does two things about it.

It measures. The auditor is strictly read-only. It takes the size of your role option with LENGTH() in the database rather than re-serializing it in PHP, times a real unserialize() of it on your machine after a warm-up pass, measures the resident footprint with the result kept alive, and works out what that costs in concurrent workers. It identifies roles that grant no effective permission, roles nobody holds, roles with identical capability sets, and capabilities it cannot account for — while being explicit that “unrecognised” is not “orphaned”, because custom code checks capabilities no scanner can see.

It offers the missing primitive. There is no way in WordPress to say “this user is a wholesale customer” without granting them permissions. There are only roles. That is why membership plugins keep inventing them: they have no alternative. A LeanRoles tag is that alternative. It appears in $user->roles, answers current_user_can(), and can be filtered on in WP_User_Query — and it is never written to the autoloaded option. Third-party code cannot tell the difference.

What it does

  • The auditor, with real measurements and wp leanroles audit --format=json
  • User tags: create, assign individually or in bulk, filter, a users-list column, CSV import and export
  • The tag engine as a standalone library, libraries/user-tags/, that any plugin can bundle so tags cost them nothing to adopt
  • WP-CLI: create a tag, assign it in bulk by role, edit or delete a role with reassignment, move a role configuration between sites, take and restore role-option backups

Licensing, and the one external service

LeanRoles uses Freemius for licensing, payment and automatic updates on its paid plan. Freemius is a third-party service, and this is the only thing in the plugin that talks to anything outside your site.

Nothing is sent anywhere unless you say so. The plugin asks once, on activation, and skipping is a real option: skip it and the plugin works exactly as it does otherwise. Nothing about the auditor or user tags depends on it.

If you do opt in, what is shared is:

  • your WordPress user’s name and email address;
  • the site’s homepage URL and title, its language, and the WordPress and PHP versions;
  • which version of LeanRoles is running, its SDK version, and whether it is active or has been uninstalled.

Two further items are optional and stay off unless you tick them: the list of other plugins and themes installed on the site, and the newsletter.

Activating a licence key sends the key and the site URL, so the licence can be checked and updates delivered to you.

Freemius’ terms and privacy policy cover what they do with it.

What the paid plans cost, and what they add

What it does not do

It does not convert roles into tags for you. What it gives you are three independent primitives — create a tag, assign it in bulk, delete a role with reassignment — which compose into a conversion done by hand, by someone who has read the audit and accepts the risk.

Before deleting a role it tells you how many capabilities that role grants and how many users hold it. It does not tell you which of those users will actually notice the difference: answering that means computing effective capabilities per user, before and after, and the plugin does not do it. Take a backup and check for yourself.

Development

The distributed plugin has no dependencies and no build step: what is in src/ and assets/ is what runs. Composer is used only for the test suite, and .distignore keeps all of it out of the release.

composer install
./tests/bin/start-db.sh      # throwaway MariaDB on 127.0.0.1:3307
./tests/bin/install.sh       # WordPress + the test library
composer test                # single site
composer test:multisite      # network
composer test:matrix         # WordPress 5.9, 6.5 and latest
composer lint                # standards + PHP 7.4 compatibility

Every test runs against a real WordPress install and a real database, because the risky parts of this plugin are all seams it does not own — the short-circuit contract of the metadata filters, what WP_User::set_role() does on its way past, how WP_User_Query builds a role clause. See tests/README.md.

Installation

  1. Upload the plugin to wp-content/plugins/leanroles and activate it.
  2. Open LeanRoles → Audit. Nothing on that screen writes anything.

Frequently asked questions

Is the auditor safe to run on a production site?

Yes, and that is the point of it. It reads. The only things it writes are a twelve-hour cache of count_users() and, on activation, a restore point of your role option.

What happens to my tags if I deactivate the plugin?

They stop being injected. Because they grant no capabilities, nothing about what your users can do changes. The assignments stay in the database and come back when you reactivate.

Can my plugin use user tags without depending on LeanRoles?

Yes, and that is the point. The tag engine is a self-contained library that ships inside this plugin and can be copied into yours: one require_once and you have user_tags_add(), user_tags_get() and the rest. If several plugins bundle it, the newest copy wins and they all share one set of tags. Removing LeanRoles does not remove them. See libraries/user-tags/readme.md.

Will `current_user_can(‘my_tag’)` work?

Yes. So will in_array( 'my_tag', $user->roles ), get_users( array( 'role' => 'my_tag' ) ) and WP_Roles::is_role().

Does it work on multisite?

The auditor understands it: role options are per site and it reads the right one. Tags are per site too, since term relationships live in each site’s own tables. Network-wide operations are not in this version.

Does an object cache solve the underlying problem?

It helps with query time and nothing else. Memory, unserialization and — with Redis — bandwidth all get worse, not better, because alloptions lives under a single key and crosses the wire whole on every request. The audit detects your drop-in and tones its findings down if that drop-in already compresses or splits the blob.

Changelog

Security update of the bundled Freemius SDK. Nothing in LeanRoles itself changes.

0.6.3

The 0.6.2 package delivered to paid sites carried a stray directory, a copy of this plugin’s own public files left over from publishing it, which did nothing but take up space. 0.6.3 is 0.6.2 without it, and the build now refuses to package any file the source does not track. The plugin directory never received 0.6.2, so here this is simply the Freemius SDK security update below.

0.6.2

The bundled Freemius SDK goes from 2.13.4 to 2.13.5, a security release: error messages, emails and URLs in its admin notices are escaped, a notice that built HTML out of the address bar is gone, only an administrator can opt a site in, and the pricing page no longer lets the query string override the plugin’s own data. Nothing in LeanRoles itself changes.

0.6.1

The report screen named the filter that puts an agency’s own name on a report and left it at that, which makes a feature only its author can use. It now carries the whole recipe — the call to paste into a mu-plugin, and a table of where each of the three keys comes out. Writing that table down turned up a key that was carried everywhere and rendered nowhere; it is rendered now, and the one output that cannot show an image says so instead of pretending.

This affects the paid plans only. Nothing in this build changes.

0.6.0

Five screens in wp-admin for what the paid plans do: converting a role to a tag, giving a role a parent, bulk tagging, the report with its thirty-day drift, and drift alerts. All of it already existed and all of it was reachable only from WP-CLI — a reasonable interface for somebody who lives in a terminal, and no interface at all for everybody else.

The screens decide nothing themselves. They call what the commands call, so a screen and a terminal cannot disagree about the same site. Two things they do differently on purpose: the code scan that reads every PHP file under wp-content runs when it is asked for rather than on page load, and a bulk run advances one batch per click rather than pretending a web request can walk fifty thousand users.

This affects the paid plans only. Nothing in this build changes.

0.5.6

The Author URI header pointed at a wordpress.org profile page. It points at davefx.com, which is where the other plugins under this name already point.

0.5.5

A link, in the description, to the page that says what the paid plans cost. 0.5.4 pointed the Plugin URI header there, which was the right value for that header and does not put a link on this page — the directory does not render it. A line in the description does.

Full changelog on WordPress.org →

Screenshots

The audit. Everything on this page is read — the size of the role option taken with LENGTH() in the database, and what it is costing you.
The audit. Everything on this page is read — the size of the role option taken with…
Measured cost. A real unserialize() of your own option, timed on your own machine, and what that works out to in workers and object-cache bandwidth. 3. Every role, heaviest first, with what it grants, what it denies, how many deprecated level_N entries it carries, and how many users hold it. 4. Users → Tags. Create and edit tags, with CSV import and export. 5. The users list, with a Tags column, filter links, and bulk assign and remove. 6. Tags on the user profile.
Measured cost. A real unserialize() of your own option, timed on your own machine, and…
LeanRoles – User Tags & Role Performance Audit screenshot
LeanRoles – User Tags & Role Performance Audit screenshot
LeanRoles – User Tags & Role Performance Audit screenshot
LeanRoles – User Tags & Role Performance Audit screenshot

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best LeanRoles alternatives

All capabilities plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Members – Membership & User Role Editor Plugin Members – Membership & User Role Editor Plugin The best WordPress membership and user role editor plugin. User Roles & Capabilities editor… by Blair Williams 300K+ ★★★★★★★★★★ 4.9 (1.3K) 1 month ago 93
2 PublishPress Capabilities: User Role Access Control, Admin Area Permissions PublishPress Capabilities: User Role Access Control, Admin… User role editing for WordPress. Manage user roles, control capabilities and permissions… by PublishPress 100K+ ★★★★★★★★★★ 4.7 (143) 2 weeks ago 95
3 Restrict User Access – Ultimate Membership & Content Protection Restrict User Access Create Access Levels and restrict any post, page, category, etc. Supports bbPress… by Joachim Jensen 10K+ ★★★★★★★★★★ 4.3 (94) 1 month ago 72
4 Roles & Capabilities Roles & Capabilities Take full control of user roles and capabilities in WordPress with an intuitive, powerful… by Ariel 1K+ ★★★★★★★★★★ 5 (7) 10 months ago 54
5 User Role for Flamingo User Role for Flamingo Configure special user role to access the flamingo contacts and messages wihtout admin… by Yannick Zipf 700+ ★★★★★★★★★★ 3 (2) 3 years ago 28
6 RoleMaster Suite – User Role Editor for E-Commerce, Membership & Admin Panel RoleMaster Suite Create, manage, and assign WordPress user roles and capabilities with precision — ideal for… by Pixar Labs 700+ ★★★★★★★★★★ 3.7 (3) 3 weeks ago 73
7 Enable Contributor Uploads Enable Contributor Uploads Easy plugin which adds the capability for contributors to upload images to their blog posts. by Equalize Digital 300+ ★★★★★★★★★★ 5 (4) 8 months ago 48
8 Comment Moderation Role by WPBeginner Comment Moderation Role by WPBeginner Add a new comment moderator user role to your site. by WPBeginner 200+ ★★★★★★★★★★ 3.7 (3) 7 months ago 44
9 Custom Access Roles Custom Access Roles Create custom roles with editing capability for only specific pages, categories and post… by Room 34 Creative Services, LLC 200+ ★★★★★★★★★★ 5 (1) 3 months ago 67
10 Map Cap Map Cap Control who can publish, edit and delete custom post types. Silly name, useful code. by thenbrent 100+ ★★★★★★★★★★ 5 (4) 13 years ago 32

FAQ

LeanRoles: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 7, 2026

Is LeanRoles free?

Yes. LeanRoles is free to download and use from the official WordPress.org plugin directory.

Is LeanRoles safe to use in 2026?

LeanRoles is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 6 hours ago, and scores 64/100 on our health check.

How many websites use LeanRoles?

LeanRoles is active on <10 WordPress websites and has been downloaded 251 times since it launched in August 2026. It was downloaded 85 times in the last 30 days.

Does LeanRoles work with WordPress 7.1?

Yes. The developer has tested LeanRoles up to WordPress 7.1.3, the latest release. It requires WordPress 5.9 or newer.

What PHP version does LeanRoles need?

LeanRoles requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was LeanRoles last updated?

The latest version, 0.6.3, was released on October 7, 2026 (6 hours ago).

Who makes LeanRoles?

LeanRoles is developed and maintained by David Marín Carreño (DaveFX).

What are the best alternatives to LeanRoles?

The most popular alternatives to LeanRoles are Members (300K+ installs), PublishPress Capabilities:… (100K+ installs) and Restrict User Access (10K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.