{"id":360820,"date":"2026-09-29T13:09:21","date_gmt":"2026-09-29T13:09:21","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/dreamfox-client-edit-mode\/"},"modified":"2026-09-29T13:28:41","modified_gmt":"2026-09-29T13:28:41","slug":"dreamfox-client-edit-mode","status":"publish","type":"plugin","link":"https:\/\/en-za.wordpress.org\/plugins\/dreamfox-client-edit-mode\/","author":12721565,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.3","stable_tag":"1.0.3","tested":"7.1.2","requires":"6.5","requires_php":"8.1","requires_plugins":null,"header_name":"Dreamfox Client Edit Mode","header_author":"Dreamfox","header_description":"Give clients a safe, limited \"Client Editor\" role: they can change text, images and links on the pages you assign, while layout, styling and structure stay locked \u2014 enforced server-side, not just hidden in the UI. Supports the block editor (Gutenberg) and Elementor.","assets_banners_color":"095bca","last_updated":"2026-09-29 13:28:41","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/dreamfoxmedia.com\/","header_author_uri":"https:\/\/dreamfoxmedia.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":66,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"dreamfox","date":"2026-09-29 12:21:29","revision":3719010},"1.0.3":{"tag":"1.0.3","author":"dreamfox","date":"2026-09-29 13:28:41","revision":3719137}},"upgrade_notice":{"1.0.1":"<p>Maintenance release: wp.org readme compliance and hardened activity log queries.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3719137,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3719137,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3719137,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3719137,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2","1.0.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3719137,"resolution":"1","location":"assets","locale":"","width":1440,"height":660},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3719137,"resolution":"2","location":"assets","locale":"","width":1440,"height":440},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3719137,"resolution":"3","location":"assets","locale":"","width":1440,"height":740},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3719137,"resolution":"4","location":"assets","locale":"","width":1440,"height":360},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3719137,"resolution":"5","location":"assets","locale":"","width":1440,"height":900}},"screenshots":{"1":"Overview: protection status, Client Editors and recent activity.","2":"Protected Pages: protect pages and jump to their permissions.","3":"Page permissions: text\/image\/link defaults and per-user overrides.","4":"My Pages: the simplified dashboard a Client Editor sees.","5":"Settings with the Information tab."}},"plugin_section":[],"plugin_tags":[283411,19875,148076,163503,1915],"plugin_category":[58],"plugin_contributors":[82375],"plugin_business_model":[],"class_list":["post-360820","plugin","type-plugin","status-publish","hentry","plugin_tags-client-editor","plugin_tags-content-lock","plugin_tags-gutenberg","plugin_tags-restrict-editing","plugin_tags-roles","plugin_category-user-management","plugin_contributors-dreamfox","plugin_committers-dreamfox"],"banners":{"banner":"https:\/\/ps.w.org\/dreamfox-client-edit-mode\/assets\/banner-772x250.png?rev=3719137","banner_2x":"https:\/\/ps.w.org\/dreamfox-client-edit-mode\/assets\/banner-1544x500.png?rev=3719137","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/dreamfox-client-edit-mode\/assets\/icon-128x128.png?rev=3719137","icon_2x":"https:\/\/ps.w.org\/dreamfox-client-edit-mode\/assets\/icon-256x256.png?rev=3719137","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/dreamfox-client-edit-mode\/assets\/screenshot-1.png?rev=3719137","caption":"Overview: protection status, Client Editors and recent activity."},{"src":"https:\/\/ps.w.org\/dreamfox-client-edit-mode\/assets\/screenshot-2.png?rev=3719137","caption":"Protected Pages: protect pages and jump to their permissions."},{"src":"https:\/\/ps.w.org\/dreamfox-client-edit-mode\/assets\/screenshot-3.png?rev=3719137","caption":"Page permissions: text\/image\/link defaults and per-user overrides."},{"src":"https:\/\/ps.w.org\/dreamfox-client-edit-mode\/assets\/screenshot-4.png?rev=3719137","caption":"My Pages: the simplified dashboard a Client Editor sees."},{"src":"https:\/\/ps.w.org\/dreamfox-client-edit-mode\/assets\/screenshot-5.png?rev=3719137","caption":"Settings with the Information tab."}],"raw_content":"<!--section=description-->\n<p><strong>Dreamfox Client Edit Mode<\/strong> is built for agencies and freelancers who deliver WordPress sites and then hand them over. Your client gets a restricted <strong>Client Editor<\/strong> role: they can update text, swap images and change links on exactly the pages you assign \u2014 and nothing else. Layout, styling and page structure are locked, and the lock is enforced <strong>on the server<\/strong>, not just hidden in the editor UI.<\/p>\n\n<h4>How it works<\/h4>\n\n<ol>\n<li>Protect the pages the client may edit.<\/li>\n<li>Assign one or more Client Editor users to those pages.<\/li>\n<li>Choose per page (and optionally per user) whether text, images and links may be changed.<\/li>\n<\/ol>\n\n<p>Every save by a Client Editor is compared against the stored page by a permission diff engine: only allowed changes go through. Adding, removing, moving or restyling elements is rejected with a clear message \u2014 the layout you delivered cannot be broken.<\/p>\n\n<h4>Server-side enforcement<\/h4>\n\n<p>The editor UI is locked down for the role (content-only editing, no style panels, no block inserter), but that is comfort, not the security. The real protection runs on the server on <strong>every<\/strong> save route:<\/p>\n\n<ul>\n<li>The block editor's REST save \u2014 rejected with a clear per-violation error in the editor.<\/li>\n<li>Classic admin saves and XML-RPC \u2014 a late <code>wp_insert_post_data<\/code> guard.<\/li>\n<li>Page-level access \u2014 <code>map_meta_cap<\/code> pins Client Editors to their assigned protected pages; everything else (including deleting and creating posts) is denied.<\/li>\n<li>Elementor-built pages \u2014 Client Editors can open the Elementor editor, and saving plus direct <code>_elementor_data<\/code> writes are validated the same way as everywhere else.<\/li>\n<\/ul>\n\n<h4>What the client sees<\/h4>\n\n<ul>\n<li>A simplified admin: a <strong>My Pages<\/strong> screen with an Edit button per assigned page, irrelevant menus and toolbar items hidden.<\/li>\n<li>An optional \"Edit this page\" toolbar link on their assigned pages.<\/li>\n<li>Clear error messages when a change is not allowed, instead of a broken layout.<\/li>\n<\/ul>\n\n<h4>What you keep<\/h4>\n\n<ul>\n<li>Every allowed change creates a normal WordPress revision \u2014 nothing is ever overwritten without a trace.<\/li>\n<li>An activity log of allowed and blocked saves (summaries only: element IDs and attribute names, never full content, never IP addresses), with configurable retention.<\/li>\n<li>Text \/ image \/ link permissions per page, with per-user overrides.<\/li>\n<\/ul>\n\n<p>Built by <a href=\"https:\/\/dreamfoxmedia.com\">Dreamfox Media<\/a>. Guides and frequently asked questions are in the <a href=\"https:\/\/help.dreamfoxmedia.com\/dreamfox-client-edit-mode\">knowledge base<\/a>; need help? <a href=\"https:\/\/dreamfoxmedia.com\/support\/\">Contact support<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to <code>\/wp-content\/plugins\/dreamfox-client-edit-mode<\/code>, or install through the WordPress plugins screen.<\/li>\n<li>Activate the plugin through the 'Plugins' screen.<\/li>\n<li>Open <strong>Client Edit<\/strong> in the admin menu, protect a page and assign a Client Editor.<\/li>\n<li>Create client users under Users \u2192 Add New with the \"Client Editor\" role.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20the%20protection%20just%20hidden%20editor%20buttons%3F\"><h3>Is the protection just hidden editor buttons?<\/h3><\/dt>\n<dd><p>No. The editor UI is locked for the role, but every save is additionally validated on the server against the stored page. Even a hand-crafted REST API request with a Client Editor's credentials cannot add, remove, move or restyle elements \u2014 the whole save is rejected with a 403 and a list of violations.<\/p><\/dd>\n<dt id=\"what%20exactly%20can%20a%20client%20editor%20change%3F\"><h3>What exactly can a Client Editor change?<\/h3><\/dt>\n<dd><p>Only what you allow per page, in three categories: <strong>text<\/strong> (headings, paragraphs, button labels \u2026), <strong>images<\/strong> (replace an image, its alt text or caption) and <strong>links<\/strong> (URLs and link targets). Layout, styling, element structure and everything else is always locked. You can override the three categories per user.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20a%20client%20editor%20tries%20something%20that%20is%20not%20allowed%3F\"><h3>What happens when a Client Editor tries something that is not allowed?<\/h3><\/dt>\n<dd><p>The save is rejected as a whole \u2014 no partial merge \u2014 and the editor shows a clear message explaining what was not allowed. The attempt is recorded in the activity log.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20elementor%3F\"><h3>Does it work with Elementor?<\/h3><\/dt>\n<dd><p>Yes. Client Editors can open the Elementor editor on their assigned pages, and every save (plus direct <code>_elementor_data<\/code> writes) is validated against the same text\/image\/link rules as the block editor.<\/p><\/dd>\n<dt id=\"how%20many%20pages%20can%20i%20protect%3F\"><h3>How many pages can I protect?<\/h3><\/dt>\n<dd><p>As many as you like \u2014 there is no limit.<\/p><\/dd>\n<dt id=\"are%20changes%20traceable%3F\"><h3>Are changes traceable?<\/h3><\/dt>\n<dd><p>Yes, twice over: every allowed save creates a regular WordPress revision (so you can compare and restore), and the activity log records who changed what, when, linked to that revision \u2014 plus every blocked attempt.<\/p><\/dd>\n<dt id=\"a%20block%20i%20added%20later%20is%20not%20editable%20for%20the%20client.%20why%3F\"><h3>A block I added later is not editable for the client. Why?<\/h3><\/dt>\n<dd><p>Blocks get a persistent internal ID when a page is protected. Blocks added afterwards do not have one yet and are read-only for Client Editors until you press <strong>Re-sync IDs<\/strong> on the Protected Pages screen.<\/p><\/dd>\n<dt id=\"which%20hooks%20can%20developers%20use%3F\"><h3>Which hooks can developers use?<\/h3><\/dt>\n<dd><ul>\n<li><code>dreamfox_client_edit_permissions<\/code> \u2014 filter the permission set used for a protected page.<\/li>\n<li><code>dreamfox_client_edit_can_modify<\/code> \u2014 filter a single per-element\/attribute permission decision (structural changes never reach this filter; they are always denied).<\/li>\n<li><code>dreamfox_client_edit_allowed_attributes<\/code> \u2014 classify attributes of custom blocks\/widgets into the text \/ image \/ link \/ layout \/ style \/ advanced categories.<\/li>\n<li><code>dfce_protected_post_types<\/code> \u2014 post types guarded by the block editor save guard (default: page, post).<\/li>\n<li><code>dfce_save_blocked<\/code> (action) \u2014 fires whenever an enforcement path blocks a save.<\/li>\n<\/ul><\/dd>\n<dt id=\"where%20can%20i%20find%20documentation%20and%20support%3F\"><h3>Where can I find documentation and support?<\/h3><\/dt>\n<dd><ul>\n<li><a href=\"https:\/\/help.dreamfoxmedia.com\/dreamfox-client-edit-mode\">Knowledge base<\/a>: setup guides, permissions, Elementor and troubleshooting.<\/li>\n<li><a href=\"https:\/\/dreamfoxmedia.com\/support\/\">Support<\/a>: submit a request to the Dreamfox Media team.<\/li>\n<li><a href=\"https:\/\/dreamfoxmedia.com\">Dreamfox Media<\/a>: more plugins and services.<\/li>\n<\/ul><\/dd>\n<dt id=\"does%20it%20delete%20my%20data%20on%20uninstall%3F\"><h3>Does it delete my data on uninstall?<\/h3><\/dt>\n<dd><p>Not by default. Enable <em>\"Delete all plugin data when the plugin is uninstalled\"<\/em> under Client Edit \u2192 Settings \u2192 Advanced first if you want a clean removal. The Client Editor role itself is always removed on uninstall.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Added the plugin icon, banner and screenshots for the WordPress.org plugin page.<\/li>\n<li>Readme: added links to dreamfoxmedia.com and the knowledge base.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Remove all Pro feature gating: unlimited protected pages, Elementor editing and per-element permission rules are now standard, unrestricted functionality.<\/li>\n<li>Move the \"My Pages\" admin menu item to the default (lower) position instead of a prominent top position.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Bump \"Tested up to\" to WordPress 7.1.<\/li>\n<li>Trim short description to meet the wp.org 150 character limit.<\/li>\n<li>Harden activity log queries with esc_sql() on the table name.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Client Editor role restricted to assigned protected pages (map_meta_cap).<\/li>\n<li>Permission diff engine: server-side validation of every save (block editor REST, classic admin, XML-RPC, Elementor) with all-or-nothing rejection and per-violation messages.<\/li>\n<li>Text \/ image \/ link permissions per page and per user; layout, styling and structure always locked.<\/li>\n<li>Content-only block editor experience for the role; persistent block IDs with re-sync.<\/li>\n<li>Simplified client dashboard (My Pages), pruned admin menus\/toolbar, login redirect, frontend edit link.<\/li>\n<li>Activity log with revision linking, configurable retention and daily cleanup.<\/li>\n<\/ul>","raw_excerpt":"Give clients a safe, limited editing role: text, images and links only \u2014 layout and styling stay locked, enforced server-side.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/360820","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=360820"}],"author":[{"embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dreamfox"}],"wp:attachment":[{"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=360820"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=360820"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=360820"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=360820"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=360820"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=360820"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}