WP Tip: don't blog as Administrator

do not blog as administrator

The default user when you install WordPress is called “Administrator” and many people don’t change it which unfortunately leads to anonymous looking posts made by Administrator instead of by Matt, Mark, Lloyd, Joseph, Alex or your own name of course.

I would venture to say it’s a new user problem but I remember seeing Administrator posts by old hands at the blogging game so it might be worth double checking, just in case. Your template might not show Administrator, but your RSS feed isn’t as clever.

It’s simple to check and fix. Log in to your WordPress blog, go to Users, and then Your Profile. If you haven’t changed your first and last names, do it now. Click “Update Profile” and then change your “Display name” to a friendlier name.

One final tip, it’s probably much safer to blog as a non-admin user. If you’re logged in all the time, consider creating an editor or author user. If you leave your laptop unattended in a busy area for a moment it’s much less likely that someone will do real harm to your blog. (Presuming they don’t rob the laptop first!)

If you’re a WordPress.com user, then don’t worry about Administrator showing up on your blog posts, it won’t happen as your login name is your author name. Isn’t that nice?


41 Comments

Jonathan (5 comments.) on July 25, 2007 at 7:21 pm.

It’s a great tip!

I personally like to blog as Matt, then on occasion I’ll blog as Fred, or maybe even through in a Frank or a Ralph, but then sometimes I’ll blog as myself…

who knows! :)

Reply

Alex (1 comments.) on July 25, 2007 at 7:22 pm.

Thanks for the tip. My theme doesn’t show it but at least now I know that my feed does!

Reply

Disier (1 comments.) on July 25, 2007 at 7:25 pm.

Excelent tips, thats the first thing the i do when i install wordpress for a friend or a customer.

I have made more than 45 wordpress installation and i always recomend then to create another user to do it.

Thanks for spread the voice and help others user to be more pro in the blogging world.

Reply

Phil (1 comments.) on July 25, 2007 at 7:52 pm.

Thanks for the tip, although since I have my own computer, and I rarely use it at coffee shops and public hotspots and such, I think I’ll stick to the admin account for blogging. Plus Macs are pretty much invulnerable anyways :-D

Reply

Jonathan the 2nd (2 comments.) on July 25, 2007 at 8:38 pm.

It took me a while to convince a customer that he should blog under a lower-authority user.

Reply

Patrick Havens (1 comments.) on July 25, 2007 at 8:41 pm.

I have a tendency to blog as Admin, because I’m always having to check on plugins, or do a quick tweak to my theme. But one of the first things I’ve always done, is change the name, and set the display name.

Good suggestion, Though when I wandered off during WordCamp I always either had someone watching the lappy, or I locked it. :)

Reply

GnomeyNewt (1 comments.) on July 25, 2007 at 8:44 pm.

Good tip for other bloggers. Good idea to change that to your name or nickname. Makes your blog more personal. I like to know how is writing the posts, Administrator sounds like your hosts tech support is blogging.

Reply

Jonathan (5 comments.) on July 25, 2007 at 8:56 pm.

Patrick,

Why not just make your publisher user an administrator? That’s what I do. I actually never use the Admin account after I install WordPress.

Reply

James McKay (2 comments.) on July 25, 2007 at 10:15 pm.

There is another good reason why you should avoid logging in as administrator as much as possible. When you are changing your password, WordPress does not ask for your old one. This means that if you are logged in as an administrator, anyone with physical access to your computer could change the admin password to anything they like and totally hijack your blog. I always blog from an account that has restricted rights for this reason, and only use the admin account when I absolutely, fundamentally, really have to.

Reply

Neil (1 comments.) on July 25, 2007 at 10:50 pm.

“If you leave your laptop unattended in a busy area for a moment it’s much less likely that someone will do real harm to your blog. (Presuming they don’t rob the laptop first!)”

I love that, sod my blog, bring my MacBook back!

Reply

Ulysses Ronquillo (2 comments.) on July 25, 2007 at 11:17 pm.

My theme doesn’t show the author’s name since I’m the only writer for my blog. I do login as Adminstrator to post articles, but I created a Nickname. I tell WordPress to display my Nickname instead of ‘admin.’ You’ll find this feature under ‘Users’ and ‘Your Profile” in the Admin Panel.

Reply

Jonathan (5 comments.) on July 25, 2007 at 11:22 pm.

James,

If someone had physical access to my machine, the least of my worries would be that they would take over my blog ;)

I’d be more worried about the thousands of dollars worth of hardware and even more costly software on my computer, not even including the priceless financial data on my systems.

But then there is, of course, my blog…

Reply

Emz (1 comments.) on July 25, 2007 at 11:35 pm.

Ooh I would never blog as Administrator! I would expect myself to be a four-eyed tech geek, let alone what my readers would expect!

Although I admit I’m always logged in as my admin user – I had never thought not to, due to having no reason for computer hijack etc.

But I might start thinking about changing this now.

Reply

Amy (1 comments.) on July 26, 2007 at 12:10 am.

Seems pretty much like common sense, but I have noticed a few people blog under Administrator. I personally prefer to use a name.

Reply

Lloyd Budd (22 comments.) on July 26, 2007 at 12:24 am.

Great tip! Particularly what can be overlooked in themes that don’t include the author on each post, because it is still very important for the feed.

The additional suggestion about using an account with editor or author role is where things can get a bit tricky, as only an admin role gets to include rich content like YouTube, Viddler videos, or other Flash, JavaScript, or other code in posts for similar security reasons.

Locking your computer when walking a way from it is essential.

Thanks for the Lloyd bait ;-)

Reply

Michael Visser (1 comments.) on July 26, 2007 at 1:27 am.

> The additional suggestion about using an account with editor or author role is where things can get a bit tricky…

Surely a flexible user-permission model has been released for users to overcome this issue. I know it used to be a pain in the early days of embedded posts.

Reply

adam (6 comments.) on July 26, 2007 at 2:28 am.

security wise, even if you can’t convince a client to not blog as an admin, wouldn’t it at least be good to create a new admin user with a new username, and delete the original (thinking back to the security flaw in 2.1.3)?

Reply

Lloyd Budd (22 comments.) on July 26, 2007 at 4:48 am.

Michael Visser, what does the experience around that look like? The reality is that you give people the ability to upload this type of content on your server, you are giving them FULL trust.

Adam, I can’t see you going wrong with that advice, but I sort of look at like putting a lock on the ventilation system when many people barely have the time or focus to put locks on the front door (staying up to date with releases) — I think there is another interesting reason of user experience that could be improved by including setting the account name in the first run.

Reply

klisiu (1 comments.) on July 26, 2007 at 7:07 am.

I made it first time after installing WordPress. Now you can see my nickname under posts, and it looks much better than “administrator”.

Reply

Reyn (1 comments.) on July 26, 2007 at 7:37 am.

Interesting point. I’ll go tell my bunch of “admin” blog friends about this :D

Reply

Administrator on July 26, 2007 at 2:06 pm.

Wish someone had told me that!

:)

Reply

Jared Schwager (2 comments.) on July 26, 2007 at 4:19 pm.

I like this idea but it would be too much of a hassle for me. I’m always doing little tweaks and whatnot to my blog, so I’d have to log in and log out quite frequently which would be a big pain in the butt.

Reply

Moey (3 comments.) on July 26, 2007 at 5:02 pm.

that’s a good tip for noobs.

Reply

Jonathan the 2nd (2 comments.) on July 26, 2007 at 8:19 pm.

Ha ha! I was wondering when someone was going to say something here under the name “Administrator”. :-)

Reply

alex_t (1 comments.) on July 26, 2007 at 10:26 pm.

It would be nice if WordPress would allow to customize administrators’s name during the installation!

Reply

Dave Zan (1 comments.) on July 27, 2007 at 10:25 am.

Just read this bit from my blog’s dashboard. Another security tip that I haven’t considered, thanks for blogging about it. :)

Reply

Jasmine (1 comments.) on July 27, 2007 at 12:01 pm.

I am very new to blogging, so it is great to be able to get some great tips. Thank very much for the great help.

Reply

Daniel (1 comments.) on July 27, 2007 at 12:32 pm.

Good point. writing under the namn admin is never good :)

Reply

Matt Keegan (1 comments.) on July 27, 2007 at 11:13 pm.

Thanks for the head’s up. I would have never thought to check the RSS feed and I am sure that it still says Administrator. Off I go to give it a look.

Reply

Glen (1 comments.) on July 28, 2007 at 2:41 pm.

Thanks for the tip what a difference it can make to someone new to blogging.

Reply

oleszka (1 comments.) on July 29, 2007 at 5:17 am.

You know it’s mistake of beginner. I remember when I opened my first blog I liked to use “Admin” (how it sounded! ADMIN)… but later I got that name is the best choice, it helps to be with readers of your blog more close. /sorry for my English, I hope you know what I mean/

Reply

Rafal on July 30, 2007 at 1:37 pm.

Pass could be changed directly in mysql database for example with phpmyadmin, so even if anybody change admin pass, blog could be still lived. /Sorry for my english too/

Reply

WP-Design (forever) (1 comments.) on August 9, 2007 at 6:08 pm.

I just use a nickname for admin, it seems to show the nickname on the feed as well – that’s easy to see in Google blog search, for instance.

About what ‘James McKay’ said – I did not know that or even think of that. But luckily there’s nobody going in my room and onto my computer.

Reply

новини (1 comments.) on September 9, 2007 at 12:21 am.

In fact my first name is Adm , second is “ini Strator” which means “from Strator”. Adm is popular name in my country. I live in MAURITANIA ;-]

Reply

mlankton (1 comments.) on September 17, 2007 at 2:23 pm.

Generally good advice.
On unix systems I administer, I always log in as a user for anything but system administration tasks. I am less picky on my site because A) I am the only writer on the site, B) I never stay logged in when I am not writing or tweaking the site, and C) I never leave a computer that I am logged into. Honestly I could care less what my feed says in the author spot, because I’m not advertising myself but the site.

Reply

Leave Your Comment

Your email will not be published or shared. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>


Holy Shmoly! is Stephen Fry proof thanks to caching by WP Super Cache