How to prevent content copying on WordPress
WordPress cannot completely stop visitors from copying public content. You can deter casual theft with CSS, JavaScript, watermarks and restricted downloads, but determined users can still disable browser scripts or access files directly, so use a plugin when you need several controls together.
- 01Decide what needs protection
- 02Add a visible image watermark
- 03Add the manual browser deterrent
- 04Limit the protection scope
- 05Test and monitor the result
- 06Use the fast plugin route
What you need
- Administrator access to WordPress
- A current backup or staging site
- A child theme or code-snippets tool if adding custom code
- Original image files if you plan to add watermarks
Decide what needs protection
Separate public content from content that must be private. A right-click block can discourage casual copying of articles and images, but it cannot secure information that your page already sends to the visitor’s browser.
For paid downloads, client files or private documents, use login checks, membership rules or protected file delivery instead of relying on browser tricks. Public files in the Media Library may still have a reachable file URL.
Add a visible image watermark
Apply a semi-transparent logo, site name or copyright notice to images before uploading them, or use an image-watermarking tool that can process new and existing Media Library images. Keep an unwatermarked original outside the public uploads folder.
Watermarks deter reuse and make attribution easier, but they do not stop someone cropping, blurring or recreating an image. Test the watermark on mobile and at the image sizes your theme actually displays.
Add the manual browser deterrent
For a small site, you can add front-end CSS that limits text selection and JavaScript that intercepts the context menu, drag events and common copy shortcuts. Load that JavaScript through WordPress’s front-end script system rather than hard-coding a script tag in the theme header. WordPress documents wp_enqueue_script() for this purpose and wp_add_inline_script() for adding code to an enqueued script.
Put custom code in a child theme or a maintained snippets tool, not directly in the parent theme. The manual route is fine when you only want a light deterrent, but it is easy to over-block buttons, galleries, embedded players or accessibility features. Users can also disable JavaScript, use browser tools or copy text from page source.
Limit the protection scope
Do not apply copy blocking blindly to every element. Leave form fields, search boxes, checkout controls, navigation, code samples and any area where users need to select text working normally.
Check pages with page builders, sliders, video players, translation tools and keyboard navigation. A common Friday failure is that a global right-click handler stops a gallery menu or media player from working; if that happens, narrow the selector or exclude that component instead of disabling the whole site.
Test and monitor the result
Test in an incognito window on desktop and mobile. Try selecting text, copying with the keyboard, dragging an image, opening the context menu, using forms and operating the site with a keyboard. Then temporarily disable JavaScript to understand what remains accessible.
Also check performance, cache behaviour and consent or security tools. Browser blocking is a deterrent, not access control, so keep backups, retain evidence of original publication and report substantial infringement through the relevant platform or legal process.
Use the fast plugin route
If you want one settings screen for right-click blocking, shortcut blocking, selection and dragging controls, plus image watermarks, install and activate UnGrabber from the WordPress dashboard. Configure only the protections you need, then exclude forms, checkout fields, galleries or other interactive areas if the plugin provides exclusions.
This is the faster route when you do not want to maintain custom JavaScript or combine separate tools. It still cannot make public web content impossible to copy, so use proper access control for private files and test the site after activation and after theme or page-builder changes.
Let UnGrabber do it
Blocks right-clicks, shortcuts, selection, dragging, and adds image watermarks for sites focused on deterring casual content theft.
Sources
- developer.wordpress.org /reference/functions/wp_enqueue_script/?utm_source=openai
Questions
- Can WordPress completely prevent visitors from copying content?
- No, WordPress cannot completely prevent copying of public content. Once a browser receives text, images or other page data, a determined visitor can use browser tools, disable JavaScript, take a screenshot or retrieve a public file URL. Copy blocking is useful for discouraging casual theft, while private material needs authentication and controlled file delivery.
- Does disabling right-click stop content theft?
- No, disabling right-click only removes one convenient browser action. Visitors may still use keyboard shortcuts, browser extensions, page source, developer tools, screenshots or direct media URLs. Treat it as a minor deterrent and test it carefully because a global context-menu handler can interfere with galleries, video players, forms and accessibility features.
- Can I add copy protection without a plugin?
- Yes, you can add CSS and front-end JavaScript through a child theme or maintained snippets tool. WordPress recommends loading front-end scripts with <code>wp_enqueue_script()</code>, and inline code can be attached with <code>wp_add_inline_script()</code>. The drawback is that you must maintain exclusions, compatibility and accessibility yourself.
- How do I protect images better than blocking downloads?
- Add a visible watermark before publishing and keep the original file private. Watermarking does not stop copying, but it makes unauthorised reuse less attractive and preserves your branding when an image is shared. For confidential images or customer files, do not expose the original public URL; require an authenticated request and use controlled delivery instead.