Edits WordPress roles and capabilities, supports per-user permissions and multisite, with Pro controls for menus, content and admin access.
Advanced Access Manager
Table of contents
- Quick take
- Role and capability model
- Important capabilities
- Pricing and licensing
- Safe implementation
- Where it fits
- Trade-offs
- Migration and rollback
- PluginSuggest verdict
- User overrides and policy drift
- Access-denied behavior
- AAM 7 migration and access-policy changes
- Premium plans and governance scope
- Advanced Access Manager FAQs
Plugin Health & Stats
Historical overview
364-day WordPress.org historyAdvanced Access Manager approaches WordPress permissions as access governance rather than only a role checkbox editor.
Quick take
Advanced Access Manager fits complex WordPress projects that need roles, users, content access, backend controls and security-oriented access governance in one system. Its broader policy model can cover backend, frontend and content-access scenarios that would otherwise require several narrower permission plugins.
Role and capability model
Advanced Access Manager can manage role and user capabilities, backend menu access, content restrictions, redirects, login behavior and security-oriented access rules. Its current positioning focuses on preventing excessive privileges and broken access control.
Advanced Access Manager should be configured from a written permission map, not by clicking capabilities until a screen appears. Advanced Access Manager deployments should document roles, user overrides, content rules, redirects and backend restrictions as one access policy so administrators can see which layer is responsible for each decision.
Important capabilities
- role and user capability management
- backend menu access controls
- post and content restrictions
- login and access-denied redirects
- content teaser controls
- multisite support
- developer API and service hooks
- access-governance model
AAM can apply controls at multiple layers, which is powerful but means administrators should distinguish capability permissions from content visibility and user-specific overrides.
Pricing and licensing
The core Advanced Access Manager plugin is available free on WordPress.org. The AAM ecosystem also offers commercial services and extensions; verify current vendor pricing for any paid requirement.
Advanced Access Manager cost matters less than the operational risk of a poorly documented role model. Advanced Access Manager has a capable free core, but the real cost is governance complexity when a site uses several policy layers and expects administrators to understand user-specific exceptions.
Safe implementation
Create an access model on staging and test it with accounts representing every important role. AAM rules can overlap with WordPress capabilities, content restrictions and login redirects, so rollback documentation is essential.
When testing Advanced Access Manager, keep a separate administrator account untouched and verify the edited role in a private browser session. Advanced Access Manager should be tested with ordinary role accounts and a separate administrator because user-level overrides and redirects can produce a different result from what an administrator sees.
Where it fits
AAM suits complex applications, private portals, custom dashboards and sites where access policy spans more than standard editor roles.
Advanced Access Manager is easier to maintain when role names describe organizational responsibility rather than individual people. Advanced Access Manager policies are easier to audit when they attach to stable organizational roles and groups rather than a growing collection of one-off user exceptions.
Trade-offs
The same flexibility creates a steeper learning curve. For a conventional blog or store, a simpler role editor can be easier for future administrators to understand and maintain.
Advanced Access Manager already reaches backend menus, content restrictions and redirects, so overlap with membership or security plugins should be intentionally minimized. With Advanced Access Manager, define whether AAM owns the actual access decision before a second plugin is allowed to hide the same content or redirect the same request.
Migration and rollback
Document every role, user override, content restriction and redirect rule before replacing another access plugin. Recreate policies in layers and verify each layer independently.
Advanced Access Manager migrations should be verified against custom post types and plugin-defined capabilities because those permissions may not exist on a clean WordPress install. Keep an Advanced Access Manager policy inventory and rollback point until backend, frontend, API and login scenarios have all been validated.
PluginSuggest verdict
Advanced Access Manager is relevant when access governance is broader than editing WordPress roles. Simpler sites should compare lighter capability editors first.
User overrides and policy drift
AAM can apply rules beyond roles, including user-specific access. Use those exceptions sparingly. A permission that exists only because one person received a direct override is easy to forget months later, especially after that person changes job responsibilities. Prefer role-level rules for repeatable needs and record every user exception with an owner and review date.
API and REST behavior should also be checked when AAM protects custom content because an application can expose data through routes that are not visible in normal browser navigation.
Access-denied behavior
AAM can redirect or hide content when access is denied, so test the user experience as carefully as the permission itself. Private pages should not leak titles, excerpts, REST data, or cache fragments, and legitimate users should land on a useful explanation rather than a confusing loop. Document the intended denied state for each protected area.
AAM 7 migration and access-policy changes
Advanced Access Manager 7 is a major backend rewrite rather than a cosmetic upgrade. The current free release is 7.1.4. Version 7 changed how access settings are stored, reworked JSON access policies, removed legacy WordPress level_x handling, and requires the Premium add-on to be on the same major version as the free plugin.
Before upgrading a complex AAM 6 site, export the AAM settings and test the migration on staging. The automated migration does not cover every historical setting, so verify restricted posts, taxonomies, redirects, REST API rules, role governance, visitor rules, IP/geolocation controls, and any custom access policies after the upgrade.
Premium plans and governance scope
AAM’s current Premium package starts at per year for one installation, while the Freelancer plan is per year for three installations. The value of Premium is not just more role editing: it extends granular backend access, content defaults, REST API controls, IP/geolocation rules, and multi-level access governance. Treat it as an access-control framework, not merely a user-role editor.
Advanced Access Manager FAQs
Is Advanced Access Manager free?
Yes. The core AAM plugin is available free on WordPress.org.
Does AAM edit roles and capabilities?
Yes. It manages capabilities for roles and users as part of a wider access-control system.
Can it restrict specific content?
Yes. AAM includes access controls for posts, pages and other content.
Can it control backend menus?
Yes. Backend menu access is one of the supported governance areas.
Is AAM suitable for beginners?
It can be used by non-developers, but its broad access model is more complex than a basic role editor.
Who should consider AAM?
Complex sites needing user, role, content, backend and redirect policies in one access-governance layer are the clearest fit.
Compare before you install
Similar Plugins
Members is a free role and capability manager that places a practical interface on WordPress native permissions.Quick takeMembers fits WordPress…
PublishPress Capabilities extends role editing into a broader permission and interface-control system for WordPress teams.Quick takePublishPress Capabilities fits editorial, WooCommerce…