BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Mandate App Security icon
Maintained Tested up to 7.0.7 #97 in access-control

Mandate App Security

WordPress Application Passwords carry the full access of their user. Mandate App Security adds per-credential policies to limit what each one may do.

Active installs<10New
Downloads · 30d67▲ +63.4% vs prev. 30d
Rating—0 reviews
Health score49/100Fair
All-time downloads339Since May 2026
Support resolved—No recent threads
RequiresWP 7.0PHP 8.2+
Downloads · 7d17▲ +6.3% week over week
Our verdict

Use with caution

Mandate App Security works, but test it on a staging site before relying on it in 2026. Was last updated 4 months ago, and scores 49/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far
  • Needs PHP 8.2 or newer

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

134Jul 9Aug 22Oct 6
Yesterday1
Daily average (1y)3
Peak day34May 29, 2026
Last 12 months347

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Mandate App Security stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
access-control >100 7,026 Best access-control plugins →
application-passwords >100 1,414 Best application-passwords plugins →
capabilities >100 7,883 Best capabilities plugins →
rest-api >100 7,658 Best rest-api plugins →
security >100 10,000 Best security plugins →

About Mandate App Security

From the official readme · v0.5.1

Description

WordPress Application Passwords prove identity. They do not limit what an authenticated request can do. If the user behind a password is an admin, every tool that authenticates as that user has admin-level access — with no native way to narrow it.

Today, REST clients, automation platforms, AI agents, management tools, and MCP connectors all authenticate with Application Passwords. Any of them, if misconfigured or compromised, can do anything that user can do.

Mandate App Security adds the missing layer: a capability policy per Application Password. You define what each credential is allowed to do. Mandate App Security enforces it on every request. Normal wp-admin sessions and user roles are unaffected.

Instead of treating every Application Password as equally trusted, Mandate App Security lets administrators and password owners save a capability allowlist per password.

An administrator can choose:

  • a WordPress user
  • one of that user’s Application Passwords
  • the capabilities that password should be allowed to use
  • an optional expiration date for that password
  • whether the scope is locked so the password owner can view it but not edit it

Users can scope their own Application Passwords when WordPress allows Application Passwords for their account. Only administrators can edit another user’s scope or lock a scope against owner edits.

When a request is authenticated with that Application Password, Mandate App Security checks the saved allowlist and removes capabilities that are not allowed for that password.

Mandate App Security never grants new permissions. It only narrows an Application Password to capabilities the selected user already receives from assigned roles. If the selected Application Password is past its saved expiration date, Mandate App Security removes all capabilities for that request. Normal browser and wp-admin sessions for the same user are not changed.

Example scopes

A reporting dashboard that only needs to read posts and media should never be able to edit settings or manage users. A content automation tool that publishes posts has no reason to access WooCommerce orders. An AI writing assistant does not need plugin management access.

With Mandate App Security, each of those tools gets a dedicated Application Password scoped to exactly what it needs. Nothing more.

Source Code

Mandate App Security is available at https://wpmandate.com.

The public development repository, release packages, and build documentation are at https://github.com/FernleafSystems/Mandate-for-WordPress.

Installation

  1. Upload the plugin files to the /wp-content/plugins/mandate-app-security directory, or install the plugin through the WordPress plugins screen.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Open Tools > Mandate App Security to select an application password and save its allowed capabilities.

Frequently asked questions

Does this create or manage Application Passwords?

No. Mandate App Security scopes existing Application Passwords. You create and manage Application Passwords from the WordPress user profile screen.

What integrations does this work with?

Any tool that authenticates using a WordPress Application Password: REST API clients, automation platforms, AI agents, management tools, and MCP connectors. If it uses an Application Password to authenticate, Mandate App Security can scope its access.

Does this change the user’s normal role capabilities?

No. Scope enforcement only applies to requests authenticated by a scoped application password.

What happens when no scope is saved for an application password?

The application password keeps its normal WordPress behavior until an administrator or the password owner saves a scope or expiration date for it.

Can users scope their own application passwords?

Yes. Users can scope their own Application Passwords when WordPress allows Application Passwords for their account, unless an administrator has locked that scope. Administrators can edit any user’s scope.

How do expiration dates work?

Expiration dates use the site’s calendar date. A password remains valid through the selected date, expires on the following day, and is then revoked by a daily WordPress cron task.

Can this grant new permissions to an application password?

No. Mandate App Security can only remove capabilities from an authenticated application-password request. It does not grant capabilities the selected user does not already receive from assigned roles.

Does this replace careful roles and integration security?

No. It is an extra layer for reducing the blast radius of broad Application Password access. You should still use appropriate user roles, secure integrations, and normal operational controls.

Does this scope multisite super-admin passwords?

No. Scopes for multisite super admins are not supported.

Changelog

0.5.1

  • Fixes an admin page crash that could happen when a role or integration registered malformed capability data.
  • Keeps capability lists safe by ignoring invalid capability names before they are shown or saved.

0.5.0

  • Improves WordPress.org compatibility for plugin storage, hooks, nonces, admin selectors, and runtime identifiers.
  • Hardens admin request handling, profile shortcuts, nonce generation, and template rendering.
  • Uses the new mdpsc_options storage key; earlier pre-0.5.0 internal option data is not migrated.

0.4.1

  • Publishes only the WordPress.org ZIP and current GitHub updater ZIP for releases.
  • Keeps GitHub release asset naming in tooling code instead of runtime plugin identity.
  • Removes plugin header author metadata for WordPress.org package compatibility.

0.4.0

  • Allows users to scope their own Application Passwords when WordPress allows Application Passwords for their account, unless an administrator locks the scope.
  • Adds administrator locks that make selected scopes read-only for password owners.
  • Adds a Restrict Scope shortcut to Application Password profile tables when the current user can manage that password.
  • Adds source tabs, area/action grouping, section select/deselect controls, and read/write/delete badges to the capability editor.
  • Splits selected password details from Mandate rule status in the admin summary.
  • Improves admin page output hardening.

0.3.1

  • Adds a Plugins page Settings link that opens the Mandate admin tool.
  • Adds favicon and sitemap metadata for the static product site.
  • Keeps legacy GitHub updater installs on built release ZIPs by publishing and verifying the legacy package asset.

0.3.0

  • Capability descriptions and tooltips explain what each WordPress capability does.
  • Cleaner admin layout: user, password, and scope summary shown as aligned columns.
  • Expiration date editing moved into the password summary.
  • Capability tabs relabelled: WordPress Capabilities and Third-Party Capabilities.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Mandate App Security alternatives

All access-control plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 PublishPress Capabilities: User Role Access Control, Admin Area Permissions PublishPress Capabilities: User Role Access Control, Admin… User role editing for WordPress. Manage user roles, control capabilities and permissions… by PublishPress 100K+ ★★★★★★★★★★ 4.7 (143) 2 weeks ago 95
2 Restrict User Access – Ultimate Membership & Content Protection Restrict User Access Create Access Levels and restrict any post, page, category, etc. Supports bbPress… by Joachim Jensen 10K+ ★★★★★★★★★★ 4.3 (94) 1 month ago 72
3 PublishPress Permissions: Access Control, Content Permissions, User Access PublishPress Permissions: Access Control, Content Permissio… The permissions plugin for posts, pages, categories, tags and more. You can control… by PublishPress 10K+ ★★★★★★★★★★ 4.3 (66) 2 weeks ago 91
4 Groups – Memberships and Access Control Groups – Memberships and Access Control Turn your site into a powerful membership solution. Manage members, teams and access to… by itthinx 10K+ ★★★★★★★★★★ 4.8 (382) 2 weeks ago 93
5 SureMembers – Membership & Content Restriction Plugin SureMembers – Membership & Content Restriction Plugin Protect your content, build memberships, and control who sees what on your WordPress site… by Brainstorm Force 2K+ ★★★★★★★★★★ 5 (2) 4 weeks ago 67
6 Quick Download Button Quick Download Button Add stylish download buttons to any post or page — 7 styles, countdown, popup modal, access… by sidocode 2K+ ★★★★★★★★★★ 4.6 (12) 5 months ago 59
7 SimpleShop SimpleShop The SimpleShop WP plugin connects your WordPress website with a SimpleShop account and… by Redbit s.r.o. 1K+ ★★★★★★★★★★ No reviews 1 month ago 66
8 Menu By User Roles Menu By User Roles Menu By User Roles allows you to control the visibility of menu items based on user roles. by kahnu044 1K+ ★★★★★★★★★★ 5 (3) 1 year ago 43
9 Groups 404 Redirect Groups 404 Redirect Redirect 404's when a visitor tries to access a page protected by Groups. by itthinx 1K+ ★★★★★★★★★★ 4.6 (10) 2 weeks ago 80
10 Geo Blocker – Control Site Access by Region and IP Geo Blocker – Control Site Access by Region and IP 🔐 Block or allow visitors by country. Track access attempts. View analytics. Stay in… by Mohamed Shili 1K+ ★★★★★★★★★★ 5 (1) 1 year ago 32

FAQ

Mandate App Security: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 7, 2026

Is Mandate App Security free?

Yes. Mandate App Security is free to download and use from the official WordPress.org plugin directory.

Is Mandate App Security safe to use in 2026?

Mandate App Security works, but test it on a staging site before relying on it in 2026. Was last updated 4 months ago, and scores 49/100 on our health check.

How many websites use Mandate App Security?

Mandate App Security is active on <10 WordPress websites and has been downloaded 339 times since it launched in May 2026. It was downloaded 67 times in the last 30 days.

Does Mandate App Security work with WordPress 7.1?

Mandate App Security is officially tested up to WordPress 7.0.7, while the latest release is 7.1.3. It may still work, but try it on a staging site first.

What PHP version does Mandate App Security need?

Mandate App Security requires PHP 8.2 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Mandate App Security last updated?

The latest version, 0.5.1, was released on June 12, 2026 (4 months ago).

Who makes Mandate App Security?

Mandate App Security is developed and maintained by Paul.

What are the best alternatives to Mandate App Security?

The most popular alternatives to Mandate App Security are PublishPress Capabilities:… (100K+ installs), Restrict User Access (10K+ installs) and PublishPress Permissions: A… (10K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.