What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To stop an administrator from deactivating a specific WordPress plugin, deny the deactivate_plugin capability for that plugin’s basename with a small must-use plugin (MU-plugin). WordPress checks this capability on the Plugins screen before running deactivation, so the control applies at the wp-admin layer. Add DISALLOW_FILE_MODS as additional hardening, but do not treat it as a dedicated deactivation lock.

Protect a specific plugin with a must-use plugin

MU-plugins load automatically and cannot be deactivated from the normal Plugins screen. Create the directory wp-content/mu-plugins if it does not exist, then create protect-plugin-deactivation.php inside it.

  1. Open your site’s files with your deployment process, hosting file manager, SFTP, or SSH.
  2. Create wp-content/mu-plugins/protect-plugin-deactivation.php.
  3. Add this code, replacing the example basename with the path of each plugin you want to protect:
<?php
add_filter( 'map_meta_cap', function ( $caps, $cap, $user_id, $args ) {
    if (
        'deactivate_plugin' === $cap &&
        ! empty( $args[0] ) &&
        in_array( $args[0], array( 'akismet/akismet.php' ), true )
    ) {
        return array( 'do_not_allow' );
    }
    return $caps;
}, 10, 4 );

The basename is the plugin file path relative to wp-content/plugins. For example, a plugin stored at wp-content/plugins/example-plugin/example-plugin.php uses example-plugin/example-plugin.php. Add additional basenames to the array when needed, but keep the list narrow so authorized maintenance remains possible.

Verify the result

  1. Log in with the administrator role you intend to restrict.
  2. Go to Plugins in wp-admin.
  3. Confirm the protected plugin no longer offers a usable Deactivate action.
  4. Test activation, updates, and ordinary site operation separately; this filter is intended to deny deactivation, not all plugin administration.

The implementation follows the capability check in WordPress core’s Plugins screen: core checks current_user_can( 'deactivate_plugin', $plugin ) before invoking the deactivation routine. Because capability mapping can vary with WordPress versions and role setups, test on the version and environment you operate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What this control does—and does not—protect

Option Scope Enforcement layer Multisite coverage Maintenance impact
Targeted map_meta_cap denial Selected plugin basenames wp-admin capability and UI check Test in both site admin and Network Admin Legitimate administrators retain other maintenance paths, but the protected plugin needs an emergency override
DISALLOW_FILE_MODS All dashboard plugin/theme installation and updates, plus the file editor WordPress configuration Applies according to the site’s configuration Blocks routine dashboard installs and updates, so deployments must handle them elsewhere
Server, deployment, or hosting controls Potentially all users and processes Filesystem, hosting, database, or release pipeline Can cover network and site files when configured accordingly Strongest boundary, but emergency changes require operational access

Using DISALLOW_FILE_MODS for defense in depth

Add this line to wp-config.php before the line that says WordPress is finished loading:

define( 'DISALLOW_FILE_MODS', true );

WordPress documents that this “will block users being able to use the plugin and theme installation/update functionality from the WordPress admin area.” The same documentation says it disables the Plugin and Theme File Editor: WordPress wp-config.php documentation.

This setting is useful hardening, but its documented scope is installation, updates, and editing—not the Deactivate action itself. Keep the targeted capability denial when deactivation must be blocked, and plan a deployment method for updates after enabling this constant.

Why deactivation hooks cannot prevent the action

WordPress performs deactivation through deactivate_plugins(), which removes active plugins and accepts a $network_wide argument for multisite: function reference and core implementation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

During ordinary deactivation, WordPress fires the plugin-specific deactivate_{$plugin} hook and the general deactivated_plugin hook. Documentation for those hooks is available at deactivated_plugin and deactivate_{$plugin}. These hooks can clean up, log, or react after the request, but they are not a prevention mechanism: silent deactivation suppresses them. Use the capability denial for enforcement.

Multisite considerations

Multisite keeps site-level and network-wide plugin state separately, and deactivate_plugins() distinguishes them through its $network_wide parameter. Protect the plugin basename in both contexts and test each path:

Rank #4
Book Tabs for The Plain Language Big Book: Alcoholics Anonymous
  • Laminated, durable tabs designed specifically for the Plain Language Big Book: A Tool for Reading Alcoholics Anonymous (Book not Included): These tabs are specially crafted for the Alcoholics Anonymous Plain Language Big Book, featuring 3 mil film lamination for exceptional durability. They are suitable for regular use with the PL book of Alcoholics Anonymous, ensuring they withstand frequent page turns
  • Easy and precise placement with our alignment card: Each set comes with an alignment card to simplify organizing your Plain Language AA Big Book. Pre-numbered tabs with page numbers and locations save time and ensure consistent positioning, making navigating the big book for AA effortless
  • Repositionable adhesive for damage-free use: Unlike traditional sticky tabs, these repositionable tabs let you adjust their placement without tearing pages. They're a clean, reliable solution for customizing the AA book, staying secure once folded
  • Customizable blank tabs for personalized sections: Add unique categories or highlight important notes in your Alcoholics Anonymous book with the included blank tabs. This allows you to personalize the plain language big book to suit your recovery journey
  • Color-coded tabs for easy navigation: Includes bright, color-coded tabs with large, clear fonts, simplifying the process of locating chapters and key sections in the Plain Language AA Big Book. Save time while enhancing your focus on Alcoholics Anonymous Big Book recovery insights
  • In a site dashboard, check the plugin’s site-level status.
  • In Network Admin → Plugins, check the network-active state and network deactivation action.
  • Confirm the role model you use cannot bypass the filter through a different administrative context.

The exact behavior should be verified on the WordPress version and multisite configuration you run; a rule that only appears to work in one dashboard is not sufficient network protection.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Understand the bypasses and keep a recovery path

This is wp-admin enforcement, not absolute immutability. Anyone or anything with server, WP-CLI, database, hosting-panel, recovery, or filesystem access can change the active-plugin list or remove the MU-plugin. A deployment pipeline or host administrator may therefore still deactivate the plugin deliberately or accidentally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep an emergency procedure before enabling the lock. At minimum, maintain a tested filesystem or deployment route that can disable or edit the MU-plugin, restore a known-good plugin version, and recover the site if the protected plugin causes a fatal error. Avoid hiding only the link with CSS or custom markup: removing a visual control does not enforce the capability check.