What is a Profile in WordPress?
A profile in WordPress is the personal settings screen every logged-in user has, reached via Users > Profile or by clicking your name at the top of the admin screen. It holds identity details like your username, display name, email address, biography, and avatar, personal preferences like the admin color scheme, and security controls for changing your password.
More About WordPress Profiles
To open your profile, go to Users > Profile in the dashboard menu, or click your name at the top of the admin screen. The screen holds your username, first and last names, nickname, display name, email address, website, a biography, and an avatar (WordPress pulls the avatar from Gravatar; the Profile screen links to gravatar.com to change it). Only 2 fields are required: your email address and a nickname. Everything else is optional.
Your own Profile screen looks the same whatever your WordPress user role is. Its Personal Options let any user pick an admin color scheme, show or hide the toolbar while viewing the site, and turn on keyboard shortcuts for comment moderation. What changes with your role is whose profile you can edit. On a single-site installation, Administrators can open other users’ profiles and change their details and roles. On a multisite network, that’s reserved for the Super Admin. Our guide to WordPress user roles breaks down what each role can do.
Profile pictures come from Gravatar
Core WordPress has no avatar upload field. The Profile screen displays whatever image Gravatar has on file for your email address, so changing your picture means setting a new image for that address at gravatar.com. If you’d rather keep avatars on your own site, the free Simple Local Avatars plugin adds an upload field to every profile and stores the images in your uploads folder with the rest of your media.
Where your profile appears publicly
Visitors see more of your profile than you might expect. Most themes print your “Display name publicly as” choice on every post you publish, and your username appears by default in your author archive URL, like example.com/author/username/. Themes that support author boxes can also display your biography. Your email address is never shown by default; WordPress uses it for notifications and account recovery. Choosing a display name that differs from your username keeps your login name out of bylines, but treat that as presentation, not protection: the author archive URL still contains your username. Protect the account itself with a strong, unique password and multifactor authentication, which a security plugin can add.
Account management: passwords, sessions, and app access
The Account Management section at the bottom of the screen is the security half of your profile. The Set New Password button fills in a strong generated password, which you can keep or replace before saving. The Log Out Everywhere Else button ends every session except your current one; use it if you stayed logged in on a shared or public computer, or you think your password has leaked. Application Passwords, added in WordPress 5.6 in December 2020, generate revocable per-app credentials so external tools can connect through the REST API without your main password. Each one is shown only once and can’t be used to log in to wp-admin.
Extending profiles with plugins
WordPress plugins can push profiles well past the core screen. Ultimate Member, for example, adds front-end profile pages, registration and login forms, custom profile fields, and member directories, which turns bare profiles into the foundation of a membership or community site. If you only need the built-in screen, just keep it current: password resets and comment notifications all depend on the email address stored here.
Frequently Asked Questions
Powerful WordPress Hosting
Reliable, lightning-fast hosting solutions specifically optimized for WordPress. Find the perfect plan for you by clicking below.
WordPress Hosting Plans