| 开发者 | paultgoodchild |
|---|---|
| 更新时间 | 2026年6月12日 21:37 |
| PHP版本: | 8.2 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
/wp-content/plugins/mandate-app-security directory, or install the plugin through the WordPress plugins screen.No. Mandate App Security scopes existing Application Passwords. You create and manage Application Passwords from the WordPress user profile screen.
Any tool that authenticates using a WordPress Application Password: REST API clients, automation platforms, AI agents, management tools, and MCP connectors. If it uses an Application Password to authenticate, Mandate App Security can scope its access.
No. Scope enforcement only applies to requests authenticated by a scoped application password.
The application password keeps its normal WordPress behavior until an administrator or the password owner saves a scope or expiration date for it.
Yes. Users can scope their own Application Passwords when WordPress allows Application Passwords for their account, unless an administrator has locked that scope. Administrators can edit any user's scope.
Expiration dates use the site's calendar date. A password remains valid through the selected date, expires on the following day, and is then revoked by a daily WordPress cron task.
No. Mandate App Security can only remove capabilities from an authenticated application-password request. It does not grant capabilities the selected user does not already receive from assigned roles.
No. It is an extra layer for reducing the blast radius of broad Application Password access. You should still use appropriate user roles, secure integrations, and normal operational controls.
No. Scopes for multisite super admins are not supported.
mdpsc_options storage key; earlier pre-0.5.0 internal option data is not migrated.