WordPress

Dreamfox Client Edit Mode

Let clients edit text, images and links — without ever breaking the layout you built

Dreamfox Client Edit Mode is made for agencies and freelancers who deliver a WordPress site and then hand it over. Your client gets a restricted Client Editor role: they can update text, swap images and change links on exactly the pages you assign — and nothing else. Layout, styling and page structure are locked.

The lock is not just a hidden button. Every save is validated on the server against the stored page, so even a hand-crafted request cannot add, remove, move or restyle elements.

What problem does it solve?

Handing a finished website to a client usually means choosing between two bad options: give them full editor access and hope nothing breaks, or keep every text change as a paid support request. A moved column, a deleted button or a changed font can quietly ruin the design you delivered. Dreamfox Client Edit Mode gives clients exactly the freedom they need — updating copy, images and links — while keeping the layout and styling out of reach.

Key features

  • Dedicated Client Editor role — clients can only touch pages you assign to them
  • Choose per page what may change: text, images and links (layout and styling are always locked)
  • Per-user overrides — give one client more or less freedom than another on the same page
  • Server-side enforcement on every save route: block editor REST, classic admin saves, XML-RPC and Elementor
  • A permission diff engine compares every save with the stored page — adding, removing, moving or restyling elements is rejected with a clear message
  • Works with the block editor (Gutenberg) and Elementor
  • Simplified admin for clients: a 'My Pages' dashboard with an Edit and View button per page, irrelevant menus hidden
  • Optional 'Edit this page' toolbar link on assigned pages
  • Every allowed change creates a normal WordPress revision — nothing is ever overwritten without a trace
  • Activity log of allowed and blocked saves (summaries only — never full content, never IP addresses) with configurable retention
  • Stable block IDs instead of fragile selectors, with a one-click 'Re-sync IDs' for blocks added later
  • Developer hooks to adjust permissions: dreamfox_client_edit_permissions, dreamfox_client_edit_can_modify and more
  • Unlimited protected pages — 100% free, no in-plugin premium gating

How it works

Protect a page, assign one or more Client Editors to it and choose per page (and optionally per user) whether text, images and links may be changed. When a Client Editor saves, a permission diff engine compares the new content with the stored page and only lets allowed changes through. Anything structural — adding, removing, moving or restyling elements — is rejected as a whole with a clear message, on every save route including the block editor REST API, classic admin saves, XML-RPC and Elementor.

Server-side protection, not just a locked editor

The editor interface is locked down for the Client Editor role, but that is comfort — not the security. The real protection runs on the server on every save route.

  • The block editor's REST save is rejected with a clear per-violation error shown in the editor
  • Classic admin saves and XML-RPC are guarded by a late wp_insert_post_data check
  • Page-level access pins Client Editors to their assigned pages; creating and deleting posts is denied
  • Elementor-built pages are validated the same way, including direct _elementor_data writes

Safe by design: revisions and an activity log

Every allowed change creates a normal WordPress revision, so you can compare and restore. The activity log records allowed and blocked saves with summaries only — element IDs and attribute names, never full content and never IP addresses — with configurable retention.

Use cases

Use this plugin when you want to:

  • Hand over a finished website while letting the client keep opening hours, prices and news up to date
  • Let a marketing colleague change copy and images without risking the page layout
  • Give one client more freedom than another on the same page with per-user overrides
  • Keep an audit trail of who changed what, with a normal WordPress revision for every allowed change
  • Protect Elementor-built pages so clients can edit content but not spacing, positioning or widgets
  • Show clients a simple 'My Pages' dashboard instead of the full WordPress admin

Often paired with our Dreamfox Form Analytics.

Free vs Premium

Free
  • Unlimited protected pages
  • Client Editor role and simplified 'My Pages' dashboard
  • Text, image and link permissions per page, with per-user overrides
  • Block editor and Elementor support
  • Server-side permission diff engine on every save route
  • Revisions for every allowed change and an activity log
  • Developer hooks and filters

See it in action

A look at the admin experience and the customer-facing result.

Video walkthrough

Knowledge base

Official docs, setup walkthroughs and developer references for Dreamfox Client Edit Mode.

Browse the full documentation

Frequently asked questions

Is the protection just hidden editor buttons?+

No. The editor is locked for the Client Editor role, but every save is additionally validated on the server against the stored page. Even a hand-crafted REST API request with a Client Editor's credentials cannot add, remove, move or restyle elements — the whole save is rejected with a 403 and a list of violations.

What exactly can a Client Editor change?+

Only what you allow per page, in three categories: text (headings, paragraphs, button labels), images (replace an image, its alt text or caption) and links (URLs and link targets). Layout, styling, element structure and everything else is always locked. You can override the three categories per user.

What happens when a Client Editor tries something that is not allowed?+

The save is rejected as a whole — there is no partial merge — and the editor shows a clear message explaining what was not allowed. The attempt is recorded in the activity log.

Does it work with Elementor?+

Yes. Client Editors can open the Elementor editor on their assigned pages, and every save, including direct _elementor_data writes, is validated against the same text, image and link rules as the block editor.

How many pages can I protect?+

As many as you like. There is no limit and no in-plugin premium gating.

Are changes traceable?+

Yes, twice over. Every allowed save creates a regular WordPress revision so you can compare and restore, and the activity log records who changed what and when, plus every blocked attempt.

A block I added later is not editable for the client. Why?+

Blocks get a persistent internal ID when a page is protected. Blocks added afterwards do not have one yet and are read-only for Client Editors until you press Re-sync IDs on the Protected Pages screen.

Which hooks can developers use?+

dreamfox_client_edit_permissions filters the permission set for a protected page, dreamfox_client_edit_can_modify filters a single per-element or per-attribute decision, dreamfox_client_edit_allowed_attributes classifies attributes of custom blocks and widgets, dfce_protected_post_types sets the guarded post types, and the dfce_save_blocked action fires whenever a save is blocked.

Does it delete my data on uninstall?+

Not by default. Enable 'Delete all plugin data when the plugin is uninstalled' under Client Edit → Settings → Advanced first if you want a clean removal. The Client Editor role itself is always removed on uninstall.

Built and supported by Dreamfox Media

Author
Dreamfox Media
Version
1.0.3
Last updated
2026-09-29 1:28pm GMT
Guarantee
Free plugin — no purchase required.

Download or buy Dreamfox Client Edit Mode

Free forever on WordPress.org. Install in seconds and ship with confidence.

More Dreamfox Media plugins