We all know sharing your WordPress password with a developer or support person is one of the riskiest habits a site owner can pick up, even when it feels like the fastest option in the moment. That’s exactly why we built a way to give temporary WordPress access without sharing a password, using a self-expiring login link that automatically stops working when the expiry time is reached. This guide walks through how Ultimate Security Pro’s Temporary Access feature works, from setting your defaults to creating and revoking individual links.
Table of Contents
Why Sharing Your Password Is a Bad Idea
Your admin password opens every door on your site. A developer with your login can see billing details, delete plugins, or export your database, whether they meant to or not. Most people forget to revoke access once the work is done. The account stays active long after anyone needs it, sometimes for months.
This applies to more than just developers. Guest authors, support agents, and freelancers doing a quick fix all end up in the same situation. An account created for a two-day job often still exists a year later, with the same permissions it started with. Once a password is shared, you also lose track of it. You do not know where it gets saved or who else might see it. Resetting it later feels unnecessary if nothing has gone wrong, so most people simply never do it.
If login security is already on your mind, our guide on login security features that stop brute force attacks is worth reading alongside this one.
Why WordPress Doesn’t Handle This on Its Own
WordPress gives you exactly two options. You either share your existing login, or you create a brand new user account by hand. Neither option expires. Neither option limits itself to a single task. If you create a new user for a one-day job, that account exists forever unless you remember to go back and delete it yourself.
There’s no built-in concept of a login that works today and stops working next Tuesday. That gap is exactly why a dedicated feature for this makes sense, instead of just working around WordPress’s default user system every time someone needs short-term access.
Give Temporary WordPress Access Without Password
Ultimate Security’s Temporary Access feature solves this by creating a login link that works once to get someone in. Once it’s clicked and used, that same link stops working, so it cannot be shared around or reused by someone else later. But using the link is not the same as access ending there. Once logged in, the person has a normal WordPress session, just like any other login. They can close the tab, come back later, and go straight to wp-admin without needing the link again, and they will still be logged in.
What actually ends their access is the expiry date you set when you created the link. Once that date passes, the session is destroyed and the account stops working, whether they are actively logged in at that moment or not. Nobody has to remember to delete anything. The expiry date does that automatically.
At some point, almost anyone running a WordPress site needs temporary access to a WordPress site without password sharing, and that’s exactly the gap this feature fills. You can find every option in our documentation if you want the full picture, but here’s the breakdown of what matters for actually using it.
Set Up Your Default Temporary Access Settings First
Before you create your first temporary access, it helps to set your defaults inside the Temporary Access settings tab. This step saves time if you have to give temporary access to your WordPress site more than once, which most people end up doing sooner or later. Here’s what you can configure and why each one matters:

- Visible Roles: Choose which WordPress roles show up as options when you create a new temporary login. Select All or Remove All make quick work of this list.
- Default Role: Set the role that gets applied automatically, such as Editor or Subscriber, so you’re not picking it every single time.
- Default Redirect: Decide where the temporary user lands right after they log in. The Dashboard is the default, but you can point it anywhere, which is handy if you always want guest authors dropped straight into the post editor instead.
- Default Expiry Time: Pick how long access lasts by default. Shorter times are usually the safer habit, since it’s always easy to create a fresh link if a job runs long.
Once you adjust these settings to match how your team actually works, a click on Save Changes locks them in. Discard Changes reverts everything back if something looks off before you save.
Create a Temporary Access Link
Once your defaults are set, creating an actual access link takes less than a minute. The Temporary Access settings in your dashboard have a Create Access Link page. You’ll fill in a short form:

- Email: Where the link and any notifications get sent.
- First Name / Last Name: Something identifiable so you know whose access this is later, especially useful once you’ve handed out a few of these and they start to blur together.
- Username: A unique username tied just to this temporary session.
- Role: The WordPress role this person gets.
- Redirect after login: Where they land after clicking the link.
- Expiry: How long this specific link stays active, whether that’s one hour or one week.
- Language: The dashboard language for this user, handy if you’re working with a developer overseas who isn’t comfortable navigating an English-only admin panel.
Clicking the Create temporary Login button generates a new user account immediately. A copy icon appears next to the link inside the Action section, ready whenever you need it. That link can go out through email, Slack, or any project tool your team already uses.
Managing and Revoking Access
Temporary access doesn’t always mean waiting for the expiry date to end things. Sometimes a project wraps up early, or a developer asks for access they never end up using. The Actions column next to each temporary login has a delete option for exactly this kind of situation. When revoking any access, a message will popup for the final confirmation of deleting the access URL.

Deleting the account ends everything right away, not just the link. Even if the person is actively logged in through a session at that moment, deleting shuts that session down too. There’s no waiting period involved.
This matters more than it looks. A developer who finished the job three weeks ago shouldn’t still have working access sitting in your site, expiry date or not. Checking your Temporary Access list every so often, the same way you’d check your regular Users page, is a habit worth building into your routine.
Choosing the Right Role and Expiry
The two decisions you’ll make most often are which role to assign and how long access should last, and it’s worth slowing down on both instead of defaulting to Administrator and One Week out of habit.
Ask what the person actually needs to do. Fixing a broken template usually needs Editor access at most, not full Administrator rights. Writing a guest post needs Author or Contributor, nothing more. Save Administrator for situations that genuinely require plugin installs or settings changes, and even then, treat it as the exception rather than the default.
Expiry deserves the same thought, since it decides how long the whole session lasts, not just how long the link stays clickable. Once someone logs in, they stay logged in through a normal session until either they log out or the expiry date arrives, at which point access ends automatically no matter what they’re doing. A quick bug fix rarely needs more than a day or two. A longer project, like a redesign an agency is handling over several weeks, justifies a longer window, but it’s still worth checking in on it rather than assuming a long expiry means you never have to think about it again.
Two-factor authentication is another layer worth stacking on top of this. If you haven’t set it up yet, our walkthrough on setting up two-factor authentication for your WordPress site login covers Email OTP and the Authenticator App step by step.
Frequently Asked Questions
How long can temporary access last?
That depends on what you pick when you create the link. Presets like one day or one week are available, and a custom expiry works too if the job needs more or less time than that.
Can I give a temporary user admin permissions?
Yes, Administrator is one of the roles you can assign, though it’s worth thinking twice before you use it. Giving someone a lower role, like Editor, is often enough for most tasks and keeps your risk smaller.
What happens if I forget to revoke access?
The account expires automatically once the expiry date passes, so a forgotten login doesn’t turn into a permanent security hole the way a regular WordPress user account would.
Can I create more than one temporary link at a time?
Yes. Every temporary login is its own separate account, so several can go out at once, each with its own role, expiry, and redirect settings.
Does the temporary user need their own password?
No password is required at all. The whole point of this feature is to let someone log in through a unique link instead of a username and password combination.
Will a temporary user show up in my regular Users list?
Yes, they show up as a regular WordPress user with whatever role you assigned, which is exactly why deleting expired or unneeded accounts from time to time matters.
Is Temporary Access available on the free version of Ultimate Security?
No. This feature is part of Ultimate Security Pro. The free plugin covers a wide range of security basics, but creating temporary logins is a Pro-only capability.
Conclusion
Sharing your password with anyone outside your team creates a loose end you’ll probably forget about. Getting temporary access to a WordPress site without password sharing closes that gap, since the link expires on its own with no manual cleanup required.
A few small habits go a long way here: setting your defaults once, choosing the lowest role that gets the job done, creating a link whenever you need one, and checking back occasionally to delete anything that’s outlived its purpose. That’s the whole system, and it saves you from a much bigger headache down the line.

Comments are moderated. Stay on topic: spam and link drops are removed.