ncdLabs Site Access Policies
Control who can access your WordPress site, domain names, and URL paths with passwords, logins, roles, and reusable policies.
Solid choice
ncdLabs Site Access Policies is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 6 days ago, and scores 64/100 on our health check.
- Actively developed — last update 6 days ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
- Needs PHP 8.2 or newer
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where ncdLabs Site Access Policies stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| access-control | >100 |
| content restriction | >100 |
| password protection | >100 |
| private site | >100 |
| staging | >100 |
About ncdLabs Site Access Policies
From the official readme · v1.0.14Description
Developed by ncdLabs.
Control access to a whole WordPress site or only the parts that need protection. Create ordered policies for domain names and URL paths, then decide whether visitors can enter with a shared password, a WordPress login, or both. Everything is managed in WordPress — no web-server rules required.
A practical fit for
- Staging sites and client previews
- Private company or team sites
- Protected sections within an otherwise public site
- Different access requirements for different domain names or URL paths
How policies work
Each request is checked against your enabled policies in order. The first matching policy decides what access is required, so broad rules and narrow exceptions can live together without custom code.
- Choose what to protect: the entire site, an exact or wildcard domain name, or a URL path.
- Choose how visitors enter: a shared password, their WordPress login, or both.
- For WordPress users, optionally allow only selected accounts, roles, or capabilities.
- Use the simulator and analyzer to check which policy will apply, then review activity in the audit log.
Included in Free
- Unlimited policies with drag-and-drop ordering and revision history
- Whole-site, exact domain name, wildcard domain name, and URL path matching
- Shared passwords kept in a reusable password vault
- WordPress login access for selected users, roles, and capabilities
- “Any” or “all” authentication requirements
- Scheduled start and end times, plus observe-only policies
- Secure access sessions, recovery codes, an audit log, a policy simulator, and an analyzer
Premium is optional
Premium is a separate companion plugin for organizations that need passkeys, access groups, custom sign-in screens, SSO/identity providers, SCIM, agency multisite tools, and other advanced controls. The Free plugin is fully usable on its own and does not lock included features behind a license key.
Privacy and external services
By default, the plugin does not contact external services. WordPress handles its normal translation updates. Optional integrations that you configure, such as identity providers, SIEM webhooks, and cloud backups, send only the data needed for that service. Password hashes and private keys are never sent to cloud backups.
Optional deactivation feedback: if an administrator chooses to submit the optional survey when deactivating, the plugin emails the selected reason and comments to ncdLabs via the site’s WordPress mail. A separate unchecked checkbox can include plugin, WordPress, and PHP versions only — never the site URL or admin email. You can skip the survey and deactivate without sending anything.
The plugin supports WordPress’s personal-data export and erasure tools. Audit events are anonymized rather than deleted so the security record remains useful. Shared policies and credentials belonging to other users are not erased.
Installation
- In WordPress, go to Plugins → Add New.
- Search for “ncdLabs Site Access Policies”, then select Install Now and Activate.
- Open Access Policies in WP Admin and follow the setup guide.
- Create a policy and use the simulator to confirm which requests it will match.
For a manual installation, upload the ncdlabs-site-access-policies folder to /wp-content/plugins/, then activate the plugin.
Frequently asked questions
Does Free require a license key?
No. Every feature included in the Free plugin works without payment or a license key. Premium is a separate download.
What happens when more than one policy matches?
The first enabled policy that matches the request is used. You can drag policies into the order you want, place specific exceptions above broader rules, and use the simulator to confirm the result.
Can I use the same password for several policies?
Yes. Save a named password once in the password vault and assign it to as many policies as needed. If you rotate that password, every assigned policy uses the replacement.
Does the plugin protect images, downloads, and other files?
The plugin protects requests processed by WordPress. A web server or storage service may deliver static files, including files in the uploads directory, without loading WordPress. Protect sensitive files separately at the server or storage layer.
Does full-page caching affect access policies?
It can. A cached page may be served before WordPress runs the access check. Exclude protected domain names and paths from full-page caching, then clear any existing cached copies. Object caching does not bypass the request check.
How do I unlock Premium after purchase?
Install the Premium companion zip, then add define('WPAPM_PREMIUM_SKU', 'pro'); (or agency / enterprise) to wp-config.php. The plugin does not contact a licensing server. Your purchase confirmation email includes the exact line for your edition.
Does the plugin contact external servers?
Not by default. WordPress handles its normal translation updates. Optional Premium features that you configure, such as identity providers, SIEM webhooks, and cloud backups, send data only to the endpoints you choose. Optional deactivation feedback is sent only if an administrator submits the survey (never required to deactivate).
Where is the source for the admin JavaScript?
Unminified sources live in resources/js/. Build with npm install && npm run build. Development repository: https://git.ncdlabs.com/ncdlabs/ncdlabs-site-access-policies
Is this plugin GPLv2 compatible?
Yes. The plugin is licensed GPLv2 or later. Bundled production libraries are GPL-compatible (MIT/BSD). Self-hosted IBM Plex fonts use the SIL Open Font License.
Changelog
1.0.14
- Feature: in-app WordPress.org review prompt after several admin visits and a successful setup apply or policy create (snooze / dismiss; never blocks plugin use).
1.0.13
- Fix: shared ncdLabs admin-menu created hook uses the wpapm_ prefix (wpapm_admin_menu_created).
- Maintenance: remove unused challenge presentation dependency; tighten timed re-enable status handling.
- Build: update @wordpress/i18n to v6 (admin SPA external).
1.0.12
- Fix: Premium companion IdP/SIEM classes no longer fatal under PHP 8.2+ (constructor property visibility/types aligned with Free stubs). Free version aligned for companion installs.
1.0.11
- Feature: optional shared ncdLabs WordPress admin menu folder (Settings + setup Confirm; nest under peer folder when present; admin reloads so the menu updates immediately).
1.0.10
- Feature: optional timed policy deactivation with automatic re-enable after N minutes (or permanent with confirmation).
- Feature: optional deactivation feedback survey on Plugins → Deactivate (skip anytime; diagnostics opt-in only).
- Privacy: product privacy notice documents optional deactivation feedback.
1.0.9
- Compatibility: support PHP 8.2 and newer.
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best ncdLabs Site Access Policies alternatives
All access-control plugins →FAQ
ncdLabs Site Access Policies: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 8, 2026
Is ncdLabs Site Access Policies free?
Yes. ncdLabs Site Access Policies is free to download and use from the official WordPress.org plugin directory.
Is ncdLabs Site Access Policies safe to use in 2026?
ncdLabs Site Access Policies is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 6 days ago, and scores 64/100 on our health check.
How many websites use ncdLabs Site Access Policies?
ncdLabs Site Access Policies is active on <10 WordPress websites and has been downloaded 626 times since it launched in July 2026. It was downloaded 302 times in the last 30 days.
Does ncdLabs Site Access Policies work with WordPress 7.1?
Yes. The developer has tested ncdLabs Site Access Policies up to WordPress 7.1.3, the latest release. It requires WordPress 6.8 or newer.
What PHP version does ncdLabs Site Access Policies need?
ncdLabs Site Access Policies requires PHP 8.2 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was ncdLabs Site Access Policies last updated?
The latest version, 1.0.14, was released on October 3, 2026 (6 days ago).
Who makes ncdLabs Site Access Policies?
ncdLabs Site Access Policies is developed and maintained by ncdLabs.
What are the best alternatives to ncdLabs Site Access Policies?
The most popular alternatives to ncdLabs Site Access Policies are PublishPress Capabilities:… (100K+ installs), Restrict User Access (10K+ installs) and PublishPress Permissions: A… (10K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card