Disable WP Plugin & Theme Install is a simple, lightweight security and maintenance plugin for WordPress. Once activated, it completely locks down the ability for users (including Administrators) to install, update, or edit plugins and themes directly from the WordPress dashboard.
This is especially useful for client handoffs, enterprise environments, or managed hosting setups where you need to prevent accidental or unauthorized code changes that could break the site.
- Locks Plugin/Theme Installation: Removes the "Add New" buttons for both plugins and themes.
- Disables File Editors: Prevents access to the built-in WordPress Theme Editor and Plugin Editor, stopping users from injecting malicious code or accidentally breaking PHP files.
- Prevents Unintended Updates: Stops users from running direct updates from the dashboard, ensuring all updates can be managed safely via a staging environment, version control, or SFTP.
- Lightweight: Uses native WordPress constants (
DISALLOW_FILE_MODSandDISALLOW_FILE_EDIT) to enforce these rules without any database overhead.
- Download the plugin files from this repository.
- Upload the
Disable-WP-Plugin-Theme-Installdirectory to your/wp-content/plugins/directory.- Alternatively, compress the folder into a
.zipfile and upload it directly via your WordPress Admin under Plugins > Add New.
- Alternatively, compress the folder into a
- Navigate to the Plugins screen in your WordPress dashboard.
- Locate Disable WP Plugin & Theme Install and click Activate.
Note: Once activated, the ability to add or edit plugins and themes will instantly disappear for all users. To regain access to these features, simply deactivate this plugin via the database, WP-CLI, or by renaming the plugin folder via SFTP/File Manager.
This plugin acts as a convenient wrapper for setting specific WordPress security constants. It is the equivalent of adding the following lines directly to your wp-config.php file:
define( 'DISALLOW_FILE_EDIT', true );
define( 'DISALLOW_FILE_MODS', true );Using this plugin allows you to toggle this protection on and off from the dashboard without needing direct server/FTP access to edit the wp-config.php file.
- Developer: Erick Villeta
- Website: https://ericksonvilleta.com
This project is licensed under GPLv2 or later. See the GNU General Public License v2.0 for more details.