Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsTo stop an administrator deactivating a particular WordPress plugin, deny the deactivate_plugin capability for that plugin’s basename with a small must-use (MU) plugin. WordPress checks that capability on the Plugins screen before it runs deactivation. Add DISALLOW_FILE_MODS as optional defense in depth, but it is not documented as a dedicated deactivation lock.
Use a targeted capability denial
WordPress’s Plugins screen checks current_user_can( 'deactivate_plugin', $plugin ) before offering the deactivation action. The check is visible in WordPress core’s plugins.php. A must-use plugin can deny that capability only for the plugin basenames you specify.
1. Create the must-use plugin
- Using SFTP, SSH, or your hosting file manager, create
wp-content/mu-pluginsif it does not exist. - Create
wp-content/mu-plugins/protect-plugin-deactivation.php. - Paste this code, replacing the example basename with the plugin or plugins you need to protect:
<?php
add_filter( 'map_meta_cap', function ( $caps, $cap, $user_id, $args ) {
if (
'deactivate_plugin' === $cap &&
! empty( $args[0] ) &&
in_array( $args[0], array( 'akismet/akismet.php' ), true )
) {
return array( 'do_not_allow' );
}
return $caps;
}, 10, 4 );
The basename is the plugin path relative to wp-content/plugins. For example, a plugin stored at wp-content/plugins/example-plugin/example.php uses example-plugin/example.php. Add more basenames to the array when necessary:
array(
'akismet/akismet.php',
'example-plugin/example.php',
)
Because an MU plugin loads automatically and cannot be deactivated from the normal Plugins screen, the rule applies before the protected plugin’s row is processed. Keep the list narrow so authorized maintenance remains possible.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
2. Verify the result
- Sign in with the administrator role you want to restrict.
- Open Plugins → Installed Plugins.
- Confirm that the protected plugin has no usable Deactivate action, or that an attempted action is rejected.
- Test an unprotected plugin to ensure ordinary administration still works.
Test on the WordPress version and role configuration used by the site. A capability mapping rule is an wp-admin control, not an absolute guarantee that the plugin can never be turned off.
What this control does—and does not—cover
| Control | Scope | Enforcement layer | Maintenance impact |
|---|---|---|---|
Targeted map_meta_cap denial |
Selected plugin basenames | WordPress capability check in wp-admin | Other plugins remain manageable; edit or remove the MU file for emergency access |
DISALLOW_FILE_MODS |
All dashboard plugin/theme installation and updates, plus file editing | WordPress admin feature restriction | Legitimate dashboard updates and the Theme/Plugin File Editor are unavailable |
| Deployment or server controls | Potentially the whole installation | Filesystem, hosting, CI/CD, or server policy | Strongest operational lock, but emergency changes require an out-of-band process |
The targeted rule is usually the least disruptive option when one or a few plugins must remain active. A deployment-level control can complement it where the threat model includes people who can write to the server.
Rank #2
Should you add DISALLOW_FILE_MODS?
In wp-config.php, you can add:
define( 'DISALLOW_FILE_MODS', true );
WordPress documents this constant as blocking “the plugin and theme installation/update functionality from the WordPress admin area” and explains that it also disables the Plugin and Theme File Editor. See the official wp-config.php documentation.
That documented scope does not say that the constant specifically prevents the Deactivate action. Use it for hardening against dashboard changes, not as a substitute for the targeted capability denial. Plan updates through SFTP, WP-CLI, a deployment pipeline, or another controlled process if you enable it.
Rank #3
Why deactivation hooks cannot lock a plugin
WordPress’s deactivate_plugins() function removes plugins from the active list and accepts a $network_wide argument for multisite, as described in the function reference and its core implementation.
During an ordinary deactivation, WordPress fires the dynamic deactivate_{$plugin} hook and the deactivated_plugin action. The references for deactivated_plugin and deactivate_{$plugin} note that silent deactivation suppresses these hooks. They can clean up data, log an event, or trigger a response after a normal action, but they are not a prevention mechanism.
Rank #4
- Laminated, durable tabs designed specifically for the Plain Language Big Book: A Tool for Reading Alcoholics Anonymous (Book not Included): These tabs are specially crafted for the Alcoholics Anonymous Plain Language Big Book, featuring 3 mil film lamination for exceptional durability. They are suitable for regular use with the PL book of Alcoholics Anonymous, ensuring they withstand frequent page turns
- Easy and precise placement with our alignment card: Each set comes with an alignment card to simplify organizing your Plain Language AA Big Book. Pre-numbered tabs with page numbers and locations save time and ensure consistent positioning, making navigating the big book for AA effortless
- Repositionable adhesive for damage-free use: Unlike traditional sticky tabs, these repositionable tabs let you adjust their placement without tearing pages. They're a clean, reliable solution for customizing the AA book, staying secure once folded
- Customizable blank tabs for personalized sections: Add unique categories or highlight important notes in your Alcoholics Anonymous book with the included blank tabs. This allows you to personalize the plain language big book to suit your recovery journey
- Color-coded tabs for easy navigation: Includes bright, color-coded tabs with large, clear fonts, simplifying the process of locating chapters and key sections in the Plain Language AA Big Book. Save time while enhancing your focus on Alcoholics Anonymous Big Book recovery insights
Multisite: protect both site and network state
Multisite maintains site-level and network-wide plugin state. Network administrators can manage plugins in Network Admin → Plugins, while individual site administrators may have a separate Plugins screen depending on the network’s settings.
- Use the same basename rules for every protected plugin.
- Test both Network Admin → Plugins and a site’s Plugins → Installed Plugins screen.
- Confirm behavior for network activation and for a site-level activation; the function reference documents the separate states and the
$network_wideparameter. - Do not assume hiding a link in one screen protects the other.
If only network administrators should control a plugin, combine the MU-plugin rule with a clearly documented network maintenance procedure rather than relying on the visual absence of a link.
Recommended Free Tools
Best Value
Bypasses and recovery planning
Anyone with sufficient server, filesystem, database, hosting-panel, recovery, or WP-CLI access can bypass a wp-admin capability rule. A deployment process can also replace the MU plugin or alter the active-plugin data directly. Describe this measure accurately as wp-admin enforcement, not immutability.
Keep an emergency path before deploying the lock:
- Retain SFTP or SSH access for trusted operators.
- Document the exact MU-plugin filename and the protected basenames.
- Store a known-good copy of the file outside the web root or in your deployment repository.
- Define how to rename or remove the MU file if the protected plugin causes a fatal error.
- For multisite, document who can recover a network-wide failure and how a single site is isolated for testing.
After deployment, check the site’s logs and test normal plugin updates through the approved maintenance channel. A lock that cannot be safely reversed can turn a routine plugin failure into an outage.
The Bottom Line
A narrow map_meta_cap denial in a must-use plugin is the direct WordPress-admin method for preventing deactivation of selected plugins. Use DISALLOW_FILE_MODS only for its broader installation, update, and file-editor restrictions, and maintain a server-level recovery route for multisite and emergency maintenance.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.




