Command Center
Enterprise SEO / 7 min read

Your SEO Plugin May Have Admin Rights You Never Granted

A canonical tag changed on the highest-earning service page. The title tag lost the city name it had carried for two years. Nobody knows when. The owner asks the four people who have logins, and all four give the same honest answer: not me. The developer only touched the checkout. The office manager only publishes blog posts. The agency swears the template edit never went near that page.

All four are telling the truth. The change came from a connected tool that nobody thought of as a person, because it never appears on the user list. It appears in a plugin settings screen, or a Search Console permissions tab, or an API token created eighteen months ago for a migration that finished long ago.

The Access Surface Is Wider Than the User List

Most owners think of site access as the login page. The actual set of parties who can change what Google sees is much larger, and most of it sits outside WordPress entirely.

The full surface usually includes:

  • WordPress user accounts and roles. Administrators, editors, and any custom role a plugin created during setup.
  • Plugin-granted capabilities and vendor accounts. Some SEO and optimization plugins create a link to the vendor's own systems when you connect a free account. In August 2026, Search Engine Journal reported allegations that the Rank Math plugin silently granted the vendor administrator-level permissions on connected sites. Whether or not that specific claim holds up, the mechanism is real: a tool that can rewrite titles, schema, redirects, and indexation directives is a tool with production write access.
  • Hosting, FTP, and database access. Usually the developer, sometimes a former developer.
  • Search Console and Google Business Profile delegated users. Anyone here can submit removals, change sitemaps, or edit business hours and categories.
  • Analytics, tag managers, CDN, and DNS. A tag manager can inject canonical tags. A CDN can rewrite headers. DNS controls whether the site resolves at all.
  • API tokens and AI or agent integrations. This category is growing fastest. SEJ reported in late August 2026 that OpenAI, Shopify, and Cloudflare are shipping structured ways for AI agents to take actions inside websites through WebMCP. Write-capable, non-human access is becoming standard equipment rather than an exception.

None of these show up when you open the WordPress users page. Every one of them can change something a search engine reads.

The 45-Minute Audit You Can Run Today

This is an inventory exercise, not an investigation. You are not trying to catch anyone. You are trying to write down every party with the ability to change a live page.

  1. Export the WordPress user list with roles and last login date. Flag anything that has not logged in for 90 days.
  2. Open every plugin settings page and look for the words "connected", "account", "API key", "license", or "sync". Write down which vendor is on the other end of each connection and what that connection is allowed to write.
  3. Review the capability table for non-human roles. Plugins sometimes create roles with names like "seo_manager" or "api_user". Ask what created them and whether anything still uses them.
  4. List every user in Search Console and Google Business Profile. Note owners versus full users versus restricted users. Old agencies and former staff live here longer than anywhere else.
  5. List every API token and integration in hosting, CDN, DNS, and any AI tool that has been pointed at the site.
  6. For each entry, record one thing: what can this party change on a live page without asking anyone? Title tags. Redirects. Robots directives. Schema. Nothing.

That last column is the whole point. A tool with read-only reporting access carries no risk to your rankings. A tool that can rewrite a canonical carries all of it. Most inventories come back with two or three parties nobody remembered granting anything to.

Access Audit Checklist

Print this and work through it once per quarter. It should take under an hour after the first pass.

  • Every WordPress account maps to a named human who currently works with you. No shared "admin" or "office" logins.
  • No dormant accounts. Anything unused for 90 days is removed, not downgraded.
  • Every plugin with a vendor connection is documented with the vendor name, the permission level, and the date it was connected.
  • Every custom role created by a plugin is identified and either justified or deleted.
  • Search Console owners are limited to two people inside your business. Agencies get delegated user access, not ownership.
  • Google Business Profile has no former agency listed as a manager or owner.
  • DNS and CDN access is held by fewer than three people and none of them are contractors on expired engagements.
  • Every API token has a named owner and a stated purpose. Tokens without a purpose get revoked.
  • Every AI or agent integration is listed with its scope. Read access is acceptable by default. Write access requires a written reason.
  • Contractor access carries an expiry date recorded in a calendar, not in someone's memory.

What to Fix First

Do not try to clean everything in one sitting. Work in this order, because the risk is not evenly distributed.

First, revoke anything that can change indexation. Robots directives, canonical tags, and noindex flags can remove a page from search results entirely, and the damage compounds daily before anyone notices. Any party holding that power without an active reason loses it today.

Second, downgrade write to read. Most reporting tools, dashboards, and agency integrations only need to read your data. If a vendor requests administrator access to produce a report, the request is wrong, not your caution. Downgrade first and see if anything breaks.

Third, kill shared logins. A shared account makes every change anonymous by design. Named individual accounts cost nothing and make every future investigation solvable in minutes rather than never.

Fourth, close the Search Console and Business Profile back doors. These carry disproportionate power over how you appear in search and cost nothing to tighten.

Fifth, put an approval path around the three change types that move rankings: schema, redirects, and indexation directives. One person approves, one record is written, no exceptions for urgency. Enterprise teams already run this pattern across dozens of properties, and it works the same way on a five-page site.

The Governance Loop That Makes Rankings Repairable

Permissions and ranking repair are the same problem viewed from two ends. When a page drops and the cause cannot be identified, the fix stalls. Teams spend weeks debating whether the drop was algorithmic, competitive, or self-inflicted, and the page stays down through all of it.

The loop that closes this has three moving parts:

  • A quarterly access review using the checklist above, dated and signed off by one named person.
  • An access change log that sits beside your content change log. When permissions are granted or revoked, it gets written down in the same place you record page edits. Two logs, one timeline.
  • A standing rule that any unexplained ranking drop opens with the access question: who had write access to this page during the affected period, including tools and integrations. That question is answerable in two minutes if the inventory exists and unanswerable forever if it does not.

The pressure on this is increasing rather than easing. More than 100 organizations, including OpenAI, Google, and Microsoft, publicly urged site owners in August 2026 to prepare for escalating AI-driven attacks. Standing write access that nobody reviews is the exact thing that turns a routine incident into an outage you discover through a traffic chart.

Where This Fits in an Operating System for Discovery

SEOGOD treats permissions as production infrastructure rather than an IT afterthought. Guardian scans watch live pages for regressions in titles, canonicals, schema, and indexation directives so a silent change surfaces as an alert instead of a ranking decline six weeks later. The access inventory tells you who could have made it. The change log tells you when. Together they turn a mystery into a ticket.

Start with the export. Open your user list, open your plugin settings, open Search Console, and write down every party that can touch a live page. Most owners find at least one entry they cannot explain. That entry is where your next ranking incident is going to come from.

If you want a baseline before you begin, run a free audit to see what is currently live on your key pages, then compare it against what you believe was approved. The gap between those two numbers is your governance problem, stated in plain terms.

Ready to Stop Guessing?

Run a SEOGOD audit on your domain and see the next proof-backed SEO opportunities.

Start Free Audit
Your SEO Plugin May Have Admin Rights Y... - SEOGOD Insights