Skip to content
GPLWP Guides

How to protect member-only downloads in WordPress

Membership & LMS Time About 30–60 minutes 7 steps Updated 30 Sep 2026

MEMBERSHIP & LMS
The short answer

WordPress does not protect files just because the download link is on a members-only page. Store files in a protected location and check membership on every download request, either with custom code or a membership-and-download integration such as Paid Memberships Pro with Download Monitor.

The route
  1. 01Choose the access rule
  2. 02Avoid the page-only shortcut
  3. 03Set up the manual route
  4. 04Create managed downloads
  5. 05Add the no-access response
  6. 06Test the file itself
  7. 07Use the faster integration

What you need

  • Administrator access to WordPress
  • An active membership system with at least one membership level
  • The files you want to restrict
  • A staging site or recent backup

Choose the access rule

Decide which membership levels can download each file. You may give every active member access, or reserve files for higher levels. Also decide whether people without access should see a locked download, a sign-up message, or nothing at all.

Do not treat a hidden button as protection. A normal Media Library URL can still be opened directly if somebody has copied it, so the file request itself needs an access check.

Avoid the page-only shortcut

You can restrict the page containing your download links with a membership plugin, but that only hides the links. It does not automatically protect files already stored at public URLs in wp-content/uploads. This shortcut is acceptable only for non-sensitive files where link hiding is enough.

For paid course material, client documents, software, PDFs, or anything members should not share publicly, use protected file delivery rather than relying on page restriction alone.

Set up the manual route

For a small site, the manual route can be fine if your membership plugin provides protected files and you are comfortable adding a small customisation. In Paid Memberships Pro, go to Memberships > Settings > Security, find the restricted files directory, create a subfolder such as premium-downloads, and upload the files there rather than to a normal public media URL.

Then add a custom plugin or Code Snippets entry that uses the confirmed pmpro_can_access_restricted_file filter and checks the member with pmpro_hasMembershipLevel(). Replace the example level IDs with your own. This route keeps the source file in the protected directory, but you must maintain the code and access rules yourself.

Create managed downloads

For a larger library, add each file as a download in Download Monitor instead of linking to the Media Library file. Create the download from Downloads > Add New, add the file under its downloadable files or versions area, and publish it.

On the download’s rules area, select the membership-level group supplied by the integration, choose the permitted level, and set Can Download to yes. Add a final rule denying access to anyone else. Download-specific rules take priority over global rules, so check both if a file behaves unexpectedly.

Add the no-access response

Create a page for visitors who do not meet the rule. If you are using Download Monitor’s access-management workflow, add its confirmed [dlm_no_access] shortcode to that page, then choose the page under Downloads > Settings > Advanced. Set a clear message explaining whether the visitor should log in, join, or upgrade.

Do not leave the fallback response vague. Members often reach it because they are logged out in another browser, their subscription has expired, or a rule was assigned to the wrong level.

Test the file itself

Test every protected download in four states: logged out, logged in with the wrong level, logged in with the correct level, and a member whose access has expired. In each case, open the download URL directly, not only the page containing the button.

Also test a copied old URL, a private browser window, and any cache or CDN layer. The common Friday failure is that the page is restricted but the original upload URL still works, or a cache serves a previously authorised response to somebody else. If direct access succeeds for an unauthorised visitor, move the file into the protected delivery system and purge the relevant caches.

Use the faster integration

If you already use Paid Memberships Pro and Download Monitor, the Paid Memberships Pro – Download Monitor Integration Add On is the faster route. It connects Download Monitor’s file rules with PMPro membership levels, so you can assign access from the download settings instead of maintaining custom file-delivery code.

Use the manual route for a small number of files and a simple rule set. Choose the integration when you need many downloads, different membership tiers, download tracking, or a no-access flow that administrators can manage from WordPress.

The fast route

Let Paid Memberships Pro do it

Connects Paid Memberships Pro with Download Monitor to restrict files by membership level instead of using basic password protection.

Get Paid Memberships Pro

Sources

  1. paidmembershipspro.com /add-ons/pmpro-downloads/?utm_source=openai
  2. paidmembershipspro.com /locking-down-protecting-files-with-pmpro/?utm_source=openai
  3. download-monitor.com /limit-downloads-membership-levels/?utm_source=openai
  4. download-monitor.com /enhance-downloads-with-paid-membership-pro/?utm_source=open…

Questions

Does restricting the download page protect the file itself?
No. Restricting the page hides the link, but a file uploaded to the normal WordPress uploads directory may still be reachable through its direct URL. Use protected file storage or a download handler that checks the visitor’s membership on every request. Always test the direct file URL in a private browser window, not just the page containing the link.
Can I protect downloads without a plugin?
Not reliably with WordPress alone. You can use server-level authentication or write custom code that checks membership before serving each file, but that requires development work and careful handling of public uploads, caching, and expired memberships. For a small library, a membership plugin’s protected-file feature can be enough; for a managed download library, use a download integration.
Why can a non-member still download a protected file?
The file is usually still stored at a public Media Library URL, the rule allows logged-in users rather than the intended membership level, or a cache is serving an old response. Check the download rule, test while fully logged out, open the direct URL, and confirm that the source file is in the protected delivery location rather than the ordinary uploads folder.
Can different membership levels access different files?
Yes. Create a rule for each download and assign the permitted membership level or levels. With Download Monitor and a compatible membership integration, the rule can use the membership-level group and deny access to everyone else. With a custom protected-files setup, your access check must return permission only for the relevant level IDs.