Restrict WordPress Content to Logged-In Users: 4 Ways

4.5/5 - (6 votes)

Want to show a WordPress post or page only to registered users? You usually do not need a paid membership plugin. WordPress has built-in password protection for shared-password access; the free Kadence Memberships plugin (formerly Restrict Content) can limit posts or part of a page to logged-in users; and Members controls content by role and capability. Buy a paid membership system only if you also need billing, renewals, coupons or more complex access rules.

Choose your access rule

One shared password: WordPress’s built-in Password Protected visibility. Any registered account: Kadence Memberships’ free restriction settings. Editors versus subscribers or custom roles: Members. Charge recurring fees: compare Kadence Memberships’ free Stripe features with its paid gateways and specialist membership platforms.

Compare four approaches · Set up a registered-users page · Decide whether to charge · Avoid access leaks

Registered users, password holders and paying members are different audiences

A user who knows a shared post password does not need a WordPress account. A registered subscriber may have a free account without an active paid membership. An administrator or editor has elevated publishing permissions, not necessarily a customer subscription. Make the access rule explicit before installing anything.

WordPress core’s Private visibility is not a normal subscriber paywall: the official documentation says private posts are available to users with the appropriate editing permissions, typically administrators and editors. Use a membership or access-control plugin when ordinary subscribers must read protected posts.

Four ways to restrict WordPress content

Pick the access rule before selecting software
MethodWho gets access?PriceMain trade-off
WordPress Password ProtectedAnyone with the shared passwordBuilt inNo individual member identity or billing
Kadence MembershipsLogged-in users, specific roles or membership plansFree core; Pro upgradesCheck gateway and plan-specific features
MembersWordPress roles or capabilitiesFree pluginNot a billing system
WP-MembersRegistered users, including approval workflowsFree core; paid support/extensionsMore registration workflow to configure

Option 1: protect one page with a WordPress password

In the block editor, open the post or page settings, select Visibility → Password protected, enter the password and update the page. Visitors get a password prompt instead of the content. This is quick for sharing a draft with a small group or making a temporary resource available.

Not suitable for members: everybody shares the same password, so you cannot revoke access for one person without changing it for everyone. WordPress’s documentation also warns that custom fields may need their own protection if the theme prints them separately. A password-protected homepage or posts page may have additional template-specific behavior. Read WordPress’s official visibility documentation.

Option 2: restrict content to any logged-in user for free

The plugin previously called Restrict Content is now listed in the WordPress directory as Kadence Memberships. Its current listing supports free membership levels, login and registration forms, content restriction and Stripe payments. The longstanding [restrict], [login_form] and [register_form] shortcodes are still documented. This is the route for a members-only article that does not need payment.

  1. Install the correct plugin. Go to Plugins → Add New, search for Kadence Memberships and confirm that the WordPress.org listing is the one at /plugins/restrict-content/. Do not confuse it with the different plugin simply called Restrict by Tickera.
  2. Choose who can register. Configure registration and account pages in the plugin, with an email-verification or moderation process appropriate to the site’s risk. Avoid turning on unrestricted registration when the protected content is intended for an invited audience only.
  3. Create a test user. Use a normal subscriber account rather than your administrator account: administrators often bypass content restrictions, which makes logged-in admin testing misleading.
  4. Protect a specific post or page. In the editor’s restriction settings, require logged-in access or a selected membership level. For just part of an article, use the documented shortcode in a Shortcode block:
[restrict]Members-only text goes here.[/restrict]

Publish the page and confirm that anonymous users see an appropriate login or registration prompt. Keep the publicly visible introduction useful: explain what is inside without putting private details into the teaser, title, SEO description or social preview.

Install Kadence Memberships free →

Option 3: give WordPress roles different content permissions

Members is a separate free plugin for role and capability management. Its public listing documents content permissions, shortcodes and multiple roles. Choose it when a team needs different views for subscribers, contributors, editors or a custom role, but no customer checkout.

After installing, configure Settings → Members and select the role or capability that may view a test post. Assign an ordinary test account that role and verify access in a private browser window. Do not change administrator capabilities casually: the plugin can alter powerful site permissions, and a mistake can lock administrators out. Back up before changing roles and check WordPress Multisite’s super-administrator restrictions when operating a network.

Explore Members’ role controls →

Option 4: require registration approval or custom profile fields

WP-Members includes login, registration, custom form fields, restricted posts and administrator approval of new accounts. It fits a professional association, private resource library or client community where accepting an email address alone should not grant immediate access. The trade-off is an extra registration and approval workflow; test account creation, rejection and password recovery before announcing the site.

Review WP-Members’ registration features →

When do you actually need a paid membership plugin?

Charging for access adds payment failures, refunds, renewals, taxes and customer support to what started as a login rule. The free Kadence Memberships listing documents Stripe support and manual payments; PayPal, Authorize.net and Braintree are listed as Pro gateways. If you need only Stripe and a simple subscription, inspect the free features and payment fees before buying an expensive suite.

Consider a premium membership product when you require several gateways, group accounts, advanced reporting or bundled course and community products. WPNeon’s Restrict Content Pro review covers the membership product itself, while the payment gateway guide addresses payment-provider fees. Do not buy a membership product solely to make one free article require login.

Buyer checkpoint: a paid gate is only useful if it works

Before taking payments, run a test purchase, a failed payment and a cancelled subscription. Confirm that access starts and ends at the correct times, receipts reach the right address, and a customer cannot open another member’s content through an unrestricted file URL.

Five places a WordPress content restriction can leak

  1. Direct media URLs. Hiding an image or PDF embedded in a protected post does not necessarily protect the original upload URL; Kadence Memberships’ own project documentation distinguishes embedded-media restrictions from server-file protection. Use a documented protected-download system when file secrecy matters.
  2. REST API and feeds. Test anonymous REST API requests, RSS excerpts, site search and third-party integrations. A plugin’s restriction may apply only to the normal template rather than every data endpoint.
  3. Page caching. Ensure your cache and CDN do not serve one authenticated user’s protected HTML to anonymous visitors. Exclude personalized pages from shared caching as your host recommends.
  4. SEO and social snippets. Titles, excerpts, structured data and Open Graph images can be publicly accessible even when the main content is gated. Do not include confidential information in those fields.
  5. Privileged account tests. Verify logged-out, free-member, paid-member and expired-member states separately. Testing only as an administrator proves almost nothing about the visitor experience.

Frequently asked questions

Can I restrict WordPress content to logged-in users without paying?

Yes. Kadence Memberships’ free version can restrict posts or content sections to logged-in users. Members provides free role-based permissions, and WP-Members provides a registration-led alternative. WordPress’s own Password Protected visibility works without accounts but is not a true members-only system.

Will a Private WordPress post be visible to subscribers?

Not by default. WordPress’s native Private visibility is for users with the relevant editing permissions, typically editors and administrators. Use a membership plugin when ordinary subscribers need access.

Is Restrict Content Pro the same plugin as Kadence Memberships?

The free plugin formerly named Restrict Content is currently listed as Kadence Memberships at the existing WordPress.org plugin URL; the commercial product and its premium features have their own licensing. Verify the plugin name and vendor in your dashboard before following an older tutorial’s screenshots.

Can I protect only half of a WordPress article?

Yes. Kadence Memberships documents the [restrict]...[/restrict] shortcode for a protected section. Leave a helpful public introduction and test both anonymous and eligible-user views.

Does a members-only page automatically protect its PDF downloads?

No. Hiding a download link or embedded document can leave the original upload URL accessible. Test the direct file address while logged out and choose a dedicated protected-download mechanism if the file must remain private.

Start with your actual access rule: try free Kadence Memberships for ordinary registered readers, or Members if roles and capabilities—not billing—are the central requirement.