[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feg9eF9MScFOg5sFKDQK-JGjsV_G9Esu4l5kitEh3FBg":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":8,"trust_score":10,"computed_at":11,"plugins":12},"twestford","Talisa @ Page Authority","https:\u002F\u002Fprofiles.wordpress.org\u002Ftwestford\u002F",1,30,100,94,"2026-08-24T13:39:41.063Z",[13],{"slug":14,"name":15,"version":16,"author":5,"author_profile":6,"description":17,"short_description":18,"active_installs":8,"downloaded":19,"rating":20,"num_ratings":20,"last_updated":21,"tested_up_to":22,"requires_at_least":23,"requires_php":24,"tags":25,"homepage":31,"download_link":32,"security_score":9,"vuln_count":20,"unpatched_count":20,"last_vuln_date":33,"fetched_at":34},"page-authority-allowed-domains","Page Authority – Allowed Domains","2.0.2","\u003Cp>Restrict WordPress user accounts to administrator-approved email domains.\u003C\u002Fp>\n\u003Cp>Page Authority – Allowed Domains gives administrators a simple way to control which email domains are permitted when WordPress user accounts are created. When the allowlist is set, any attempt to create a user with an email outside the approved domains is blocked across the standard registration form, the REST API, and WooCommerce registration.\u003C\u002Fp>\n\u003Cp>It is designed for sites where only users from specific organizations, companies, clients, or teams should be added as WordPress users. Typical use cases include internal company portals where only staff email addresses should ever become accounts, agency-managed client sites that should reject public signups, membership or B2B sites that vet users by their email domain, and multisite networks that need consistent domain rules across sites.\u003C\u002Fp>\n\u003Cp>Existing users are never modified automatically. Instead, the Existing User Audit highlights accounts whose email domains are not on the allowlist so an administrator can review and act on them individually, including removing an account and reassigning its content.\u003C\u002Fp>\n\u003Cp>Features include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Admin-managed allowed domain list\u003C\u002Fli>\n\u003Cli>Standard WordPress registration enforcement\u003C\u002Fli>\n\u003Cli>REST API user creation\u002Fupdate enforcement\u003C\u002Fli>\n\u003Cli>WooCommerce registration enforcement\u003C\u002Fli>\n\u003Cli>Existing User Audit tools\u003C\u002Fli>\n\u003Cli>Optional login enforcement\u003C\u002Fli>\n\u003Cli>Per-user unauthorized account removal with content reassignment\u003C\u002Fli>\n\u003Cli>Multisite-aware protections\u003C\u002Fli>\n\u003Cli>Lightweight architecture with no custom database tables\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Security Notes\u003C\u002Fh3>\n\u003Cp>The plugin includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Capability checks\u003C\u002Fli>\n\u003Cli>Nonce verification (verified before any state-changing logic runs)\u003C\u002Fli>\n\u003Cli>Sanitization and escaping\u003C\u002Fli>\n\u003Cli>Live revalidation before destructive actions\u003C\u002Fli>\n\u003Cli>Current-admin protection\u003C\u002Fli>\n\u003Cli>Multisite Super Admin protection\u003C\u002Fli>\n\u003Cli>Explicit content reassignment or delete confirmation before user removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Recommended operational practices:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Review the Existing User Audit before enabling login blocking\u003C\u002Fli>\n\u003Cli>Test custom registration and SSO flows before production rollout\u003C\u002Fli>\n\u003Cli>Maintain regular database backups before deleting users\u003C\u002Fli>\n\u003Cli>Restrict plugin management access to trusted administrators only\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Uninstall\u003C\u002Fh3>\n\u003Cp>Deleting the plugin removes its current options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>pageauth_allowed_domains\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>pageauth_audit_log\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>pageauth_block_unauthorized_logins\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>It also cleans up internal flags, transients, user meta, and any leftover keys from prior plugin versions that used the \u003Ccode>paad_\u003C\u002Fcode> or \u003Ccode>aed_\u003C\u002Fcode> prefixes. On multisite, the matching network options are removed as well.\u003C\u002Fp>\n","Restrict WordPress user accounts to administrator-approved email domains.",279,0,"2026-06-28T19:23:00.000Z","7.0.2","6.0","7.4",[26,27,28,29,30],"domains","email","registration","security","users","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fpage-authority-allowed-domains\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpage-authority-allowed-domains.2.0.2.zip",null,"2026-07-22T17:31:50.256Z"]