Access
Who gets through
Three ways in, for three different people.
Roles — tick the roles that see the site as normal. Anyone who can change these settings always gets through whatever is ticked, because unticking your own role would otherwise lock you out of your own front end with no way back but the database.
A link — send it to a client and they see the finished site with no account and no password. Opening it once is enough; their browser remembers for a week and the key is taken out of the address bar straight away, so it does not end up in a referrer or a pasted URL. Treat it as a password: anyone holding it can see the site. Make a new preview link and the old one stops working immediately.
A password — a discreet box at the foot of the page, for a group who share one password. It is hashed the way WordPress hashes yours and never shown again. Five wrong guesses and that visitor waits fifteen minutes. Changing the password signs out everyone using the old one.
Which pages are shut
Everything, by default — that is what closing a site means. Two cases come up constantly and both are settings here.
Close these pages narrows it: Everywhere, The front page only, Shop and product pages, or Only what I choose below with tick lists for places, kinds of content and archives, all built from your own site.
But leave these open wins over all of it. Quick exclude ticks the places most often left out — a place already chosen on the left cannot be ruled out here, and greys out rather than cancelling itself. Never on these takes a particular page, post, product or category by name. Addresses to keep it off takes one path per line with standing for anything: /contact/ leaves everything under /contact/ open.
The admin, the login screen, cron, the REST API, WP-CLI, robots.txt and your sitemap are never closed. A maintenance mode that locks the owner out of wp-admin is the oldest support ticket in this category of plugin.
Still stuck? We answer support email from real people.
Browse the knowledge base