[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fuFaxP6XtcdJpfUSu1Sudtzl4A9CHACEwamcox7NogQk":3,"$fVcsX-5XmWp76bWdodem3uSDbB0vxLhMgE1JvkauII9Q":134,"$frCPtg3KPCRkAeyEJNusuO2sKoUhYwThIdq07q0_SMMg":139},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"discovery_status":30,"vulnerabilities":31,"developer":32,"crawl_stats":28,"alternatives":37,"analysis":28,"fingerprints":28},"qrauth-passwordless-social-login","QRAuth – Passwordless & Social Login","0.1.23","QRAuth","https:\u002F\u002Fprofiles.wordpress.org\u002Faristech\u002F","\u003Cp>QRAuth replaces the password field on your WordPress login page with a drop-in QR widget. Users sign in by scanning with the QRAuth mobile app; a cryptographic signature is verified server-to-server before WordPress sets the auth cookie. Social login (Google, GitHub, Microsoft, Apple) is brokered by QRAuth’s hosted approval page, so you never have to register an OAuth app or hold a client secret.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One Client ID is the only configuration.\u003C\u002Fstrong> Paste it into Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> QRAuth and the widget appears on wp-login.php. Everything else — the approval flow, the signing, the token refresh — lives in the QRAuth platform.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Account safety is the default.\u003C\u002Fstrong> Auto-provisioning is off out of the box: only WordPress users who already exist (matched on email) can sign in via QRAuth. Flip on auto-provisioning and new users are created as Subscriber — that’s the only role available, intentionally and at every layer (settings UI, sanitiser, runtime). Operators who need a different role for an individual user can change it manually via Users \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> All Users after their first sign-in. The plugin never stores the signing material, never issues a redirect outside your site, and never touches your user table on uninstall.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Self-hosted, no third-party scripts on wp-login.php.\u003C\u002Fstrong> The QRAuth web component ships vendored inside the plugin — the only outbound call is from your server to QRAuth’s verification endpoint during a sign-in attempt.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Open source build.\u003C\u002Fstrong> The compressed JavaScript at \u003Ccode>assets\u002Fjs\u002Fqrauth-components.js\u003C\u002Fcode> is built from publicly available TypeScript source at https:\u002F\u002Fgithub.com\u002Fqrauth-io\u002Fqrauth\u002Ftree\u002Fmain\u002Fpackages\u002Fweb-components. The unminified source files are also vendored alongside the minified bundle inside this plugin (\u003Ccode>assets\u002Fjs\u002Fsource\u002F\u003C\u002Fcode>) for offline review. See the \u003Cstrong>Source\u003C\u002Fstrong> section below for build instructions.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to QRAuth (https:\u002F\u002Fqrauth.io) — the identity verification service that performs the actual passwordless \u002F social sign-in. QRAuth is operated by ProgressNet, the publisher of this plugin. Without QRAuth there is no widget and no sign-in.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What the service is and what it is used for\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>QRAuth verifies that the user who scanned the QR code (or completed a social-provider flow on the hosted approval page) is the same person who initiated the sign-in on your WordPress site, then returns a signed assertion that the plugin uses to set the WordPress auth cookie.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What data is sent and when\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Auth-session creation\u003C\u002Fstrong> — when a visitor opens a page that hosts the widget (wp-login.php, the registration form, a shortcode-enabled page, or a WooCommerce sign-in form), the plugin’s same-origin REST proxy sends your Client ID, Client Secret (server-side only — never exposed to the browser), and the host page URL to \u003Ccode>https:\u002F\u002Fqrauth.io\u002Fapi\u002Fv1\u002Fauth-sessions\u003C\u002Fcode>. No visitor data is included in this request.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sign-in verification\u003C\u002Fstrong> — when the visitor approves the sign-in (by scanning with the QRAuth mobile app or completing a social-provider flow on QRAuth’s hosted approval page), the plugin’s REST proxy fetches the verified result from \u003Ccode>https:\u002F\u002Fqrauth.io\u002Fapi\u002Fv1\u002Fauth-sessions\u002Fverify-result\u003C\u002Fcode>. The response carries the QRAuth user identifier and, when the \u003Ccode>email\u003C\u002Fcode> scope is allowed in Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> QRAuth, the user’s email address. The plugin uses this only to locate or create the matching WordPress user; nothing beyond a hashed link reference is retained.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hosted approval page\u003C\u002Fstrong> — when a visitor on a phone taps “Continue with QRAuth”, the browser navigates to \u003Ccode>https:\u002F\u002Fqrauth.io\u002Fa\u002F\u003Ctoken>\u003C\u002Fcode> to complete the social-provider flow. This is a standard cross-domain navigation initiated by the visitor.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The vendored web component (\u003Ccode>assets\u002Fjs\u002Fqrauth-components.js\u003C\u002Fcode>) is served from your own WordPress site — there is no third-party JavaScript on wp-login.php, and the component does not contact qrauth.io directly from the browser; all server-to-server calls are proxied via your site’s REST API.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Service terms and policies\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Terms of Service: https:\u002F\u002Fqrauth.io\u002Fterms\u003C\u002Fli>\n\u003Cli>Privacy Policy: https:\u002F\u002Fqrauth.io\u002Fprivacy\u003C\u002Fli>\n\u003Cli>Data Processing Addendum: https:\u002F\u002Fqrauth.io\u002Fdpa\u003C\u002Fli>\n\u003Cli>List of Sub-processors: https:\u002F\u002Fqrauth.io\u002Fsubprocessors\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Source\u003C\u002Fh3>\n\u003Cp>\u003C!-- Keep the banner code block below in sync with the first lines of assets\u002Fjs\u002Fqrauth-components.js after every web-components version bump. -->\u003C\u002Fp>\n\u003Cp>The compiled bundle at \u003Ccode>assets\u002Fjs\u002Fqrauth-components.js\u003C\u002Fcode> carries the following banner header at the top of the file:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>`\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u002F*!\u003Cbr \u002F>\n * @qrauth\u002Fweb-components v0.4.1\u003Cbr \u002F>\n * Vendored by qrauth-passwordless-social-login. Do not edit by hand.\u003Cbr \u002F>\n *\u003Cbr \u002F>\n * Source:  https:\u002F\u002Fgithub.com\u002Fqrauth-io\u002Fqrauth\u002Ftree\u002Fmain\u002Fpackages\u002Fweb-components\u003Cbr \u002F>\n * License: MIT\u003Cbr \u002F>\n * npm:     https:\u002F\u002Fwww.npmjs.com\u002Fpackage\u002F@qrauth\u002Fweb-components\u003Cbr \u002F>\n * Build:   \u003Ccode>npm install && npm run build:assets\u003C\u002Fcode> (see bin\u002Ffetch-web-components.mjs)\u003Cbr \u002F>\n *\u003Cbr \u002F>\n * The unminified TypeScript source for this bundle is also vendored at\u003Cbr \u002F>\n * assets\u002Fjs\u002Fsource\u002F — see assets\u002Fjs\u002Fsource\u002FREADME.md for provenance.\u003Cbr \u002F>\n *\u002F\u003Cbr \u002F>\n    `\u003C\u002Fp>\n\u003Cp>The unminified TypeScript source files are also vendored alongside the compiled bundle inside this plugin (\u003Ccode>assets\u002Fjs\u002Fsource\u002F\u003C\u002Fcode>) for offline review.\u003C\u002Fp>\n\u003Cp>The plugin’s own source — PHP, the small browser adapter (\u003Ccode>assets\u002Fjs\u002Fqrauth-adapter.js\u003C\u002Fcode>), build scripts, tests, and CI — is publicly maintained under GPL-2.0-or-later at:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Plugin source repository: https:\u002F\u002Fgithub.com\u002Fqrauth-io\u002Fqrauth-passwordless-social-login\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The PHP and \u003Ccode>assets\u002Fjs\u002Fqrauth-adapter.js\u003C\u002Fcode> shipped in the plugin ZIP are non-minified — read them directly without checking out the repo.\u003C\u002Fp>\n\u003Cp>The vendored file \u003Ccode>assets\u002Fjs\u002Fqrauth-components.js\u003C\u002Fcode> is a pinned production build of the public \u003Ccode>@qrauth\u002Fweb-components\u003C\u002Fcode> library. The non-compiled source for that library is openly available:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Source repository: https:\u002F\u002Fgithub.com\u002Fqrauth-io\u002Fqrauth\u002Ftree\u002Fmain\u002Fpackages\u002Fweb-components (MIT-licensed)\u003C\u002Fli>\n\u003Cli>npm release: https:\u002F\u002Fwww.npmjs.com\u002Fpackage\u002F@qrauth\u002Fweb-components — pinned to v0.4.1, sha512 in \u003Ccode>package.json\u003C\u002Fcode> under the \u003Ccode>qrauth.webComponentsIntegrity\u003C\u002Fcode> key\u003C\u002Fli>\n\u003Cli>Build instructions for the upstream library: https:\u002F\u002Fgithub.com\u002Fqrauth-io\u002Fqrauth\u002Fblob\u002Fmain\u002FBUILDING.md\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>To regenerate the vendored bundle from the pinned npm release, clone the plugin source repository linked above and run from its root:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>npm install\nnpm run build:assets\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The build script \u003Ccode>bin\u002Ffetch-web-components.mjs\u003C\u002Fcode> (kept in the plugin source repository, not in the WordPress.org plugin ZIP) downloads the npm tarball, verifies its sha512 SRI hash against \u003Ccode>package.json#qrauth.webComponentsIntegrity\u003C\u002Fcode>, extracts the IIFE build, and writes it to \u003Ccode>assets\u002Fjs\u002Fqrauth-components.js\u003C\u002Fcode>. CI runs the same script before the WordPress.org plugin-check job, so the bundle distributed on the directory always matches the published npm release. To rebuild from upstream source instead of the pinned tarball, follow \u003Ccode>BUILDING.md\u003C\u002Fcode> in the upstream library repository above.\u003C\u002Fp>\n","Passwordless sign-in for WordPress. Users scan a QR code with the QRAuth mobile app — no passwords, no forms, no OAuth apps to register.",20,211,100,1,"2026-06-03T09:29:00.000Z","7.0.2","6.4","8.2",[20,21,22,23,24],"authentication","login","passwordless","qr-code","social-login","https:\u002F\u002Fgithub.com\u002Fqrauth-io\u002Fqrauth-passwordless-social-login","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fqrauth-passwordless-social-login.0.1.23.zip",0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":33,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":11,"avg_security_score":13,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"aristech",30,94,"2026-08-29T05:21:05.270Z",[38,59,76,96,115],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":13,"downloaded":46,"rating":13,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":57,"download_link":58,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"memberstack","Memberstack – Member Management & Content Protection","1.3.1","Josh","https:\u002F\u002Fprofiles.wordpress.org\u002Fmsjoshlopez\u002F","\u003Cp>Since 2019, we’ve helped thousands of businesses to generate $125,000,000 in revenue through premium content and membership sites. Our customers range from high school seniors to teams at Slack, Reddit, American Airlines, Webflow, IDEO, etc.\u003C\u002Fp>\n\u003Cp>Whether you’re creating a custom SaaS application, online course, subscription service, premium content site, or member community, we’re ready to help!\u003C\u002Fp>\n\u003Cp>Our WordPress integration makes it simple to protect content, manage members, and process payments without any coding knowledge. Perfect for content creators, course developers, and businesses looking to monetize their WordPress sites through memberships.\u003C\u002Fp>\n\u003Ch4>Getting Started Guide\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Quick Start Video Tutorial\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Check out our installation and setup guide video: \u003Ca href=\"https:\u002F\u002Fyoutu.be\u002FN-S2CJjomK8?si=nGboxSIPbjHHbCoO\" rel=\"nofollow ugc\">Watch Getting Started with Memberstack + WordPress\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>In this video, you’ll learn how you can add gated content, social auth, and more to your WordPress site using the Memberstack plugin with WordPress!\u003C\u002Fp>\n\u003Ch4>Why Choose Memberstack?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>No Coding Required\u003C\u002Fstrong> – Easy setup with visual builders and pre-built components for WordPress\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Professional Features\u003C\u002Fstrong> – Enterprise-grade security and functionality at a fraction of the cost\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexible Pricing\u003C\u002Fstrong> – Start building in test mode for free with no credit card required\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Modern Authentication\u003C\u002Fstrong> – Social login, passwordless options, and traditional email\u002Fpassword\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Page Builder Ready\u003C\u002Fstrong> – Works seamlessly with popular builders like Bricks, Elementor, Gutenberg, and more\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Perfect For\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Online Courses & Educational Content\u003C\u002Fli>\n\u003Cli>Premium News & Media Sites\u003C\u002Fli>\n\u003Cli>Subscription Services\u003C\u002Fli>\n\u003Cli>Member Communities\u003C\u002Fli>\n\u003Cli>Digital Downloads\u003C\u002Fli>\n\u003Cli>Professional Services\u003C\u002Fli>\n\u003Cli>Content Creators\u003C\u002Fli>\n\u003Cli>Online Coaches\u003C\u002Fli>\n\u003Cli>Digital Products\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Essential Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Smart Content Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Protect entire pages or specific sections\u003C\u002Fli>\n\u003Cli>Create multiple membership plans, paid or free\u003C\u002Fli>\n\u003Cli>Set up trial periods for paid plans\u003C\u002Fli>\n\u003Cli>Custom access rules\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Modern Authentication\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Social login (Google, GitHub, LinkedIn, etc.)\u003C\u002Fli>\n\u003Cli>Passwordless email login\u003C\u002Fli>\n\u003Cli>Traditional email\u002Fpassword\u003C\u002Fli>\n\u003Cli>Custom registration fields, we call them “custom fields”\u003C\u002Fli>\n\u003Cli>Profile management\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Payment & Subscriptions\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Stripe integration – Memberstack exclusively uses Stripe\u003C\u002Fli>\n\u003Cli>Multiple pricing tiers\u003C\u002Fli>\n\u003Cli>Free and paid plans\u003C\u002Fli>\n\u003Cli>Trial periods\u003C\u002Fli>\n\u003Cli>Payment management\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pricing\u003C\u002Fh4>\n\u003Cp>Start in test mode for free – no credit card required. When you’re ready to launch, choose the plan that fits your member count. As your business grows, unlock lower transaction fees. We added this section because we want to be transparent about our pricing and help you make an informed decision.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Basic – $29\u002Fmo\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Perfect for up to 1,000 members\u003C\u002Fli>\n\u003Cli>4% transaction fee – great for testing the waters\u003C\u002Fli>\n\u003Cli>All core features included\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Professional – $49\u002Fmo\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Scale up to 5,000 members\u003C\u002Fli>\n\u003Cli>Reduced 2% transaction fee\u003C\u002Fli>\n\u003Cli>All core features included\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Business – $99\u002Fmo\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Support up to 10,000 members\u003C\u002Fli>\n\u003Cli>Ultra-low 0.9% transaction fee\u003C\u002Fli>\n\u003Cli>All core features included\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Established – $499\u002Fmo\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>10,000+ members\u003C\u002Fli>\n\u003Cli>ZERO transaction fees – maximize your revenue\u003C\u002Fli>\n\u003Cli>All core features included\u003C\u002Fli>\n\u003Cli>Priority support included\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Every Plan Includes:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress integration\u003C\u002Fli>\n\u003Cli>Social login options\u003C\u002Fli>\n\u003Cli>Stripe payment processing\u003C\u002Fli>\n\u003Cli>Custom SSO\u003C\u002Fli>\n\u003Cli>Branded emails\u003C\u002Fli>\n\u003Cli>Member management dashboard\u003C\u002Fli>\n\u003Cli>Save 20% with annual billing\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Start for free in test mode and upgrade when you’re ready to launch. No hidden fees or surprises – just straightforward pricing that scales with your success.\u003C\u002Fp>\n\u003Ch4>Page Builder Integration\u003C\u002Fh4>\n\u003Cp>Works seamlessly with your favorite page builders:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Bricks\u003C\u002Fstrong> – Native elements for forms and buttons\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Elementor\u003C\u002Fstrong> – Custom widgets for membership features\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Divi\u003C\u002Fstrong> – Built-in module support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gutenberg\u003C\u002Fstrong> – Dedicated blocks for content protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Easy Implementation\u003C\u002Fh4>\n\u003Cp>Add membership features anywhere with our shortcodes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>[memberstack_login]\u003C\u002Fcode> – Display login form\u003C\u002Fli>\n\u003Cli>\u003Ccode>[memberstack_signup]\u003C\u002Fcode> – Display signup form\u003C\u002Fli>\n\u003Cli>\u003Ccode>[memberstack_protected]\u003C\u002Fcode> – Protect content sections\u003C\u002Fli>\n\u003Cli>\u003Ccode>[memberstack_member]\u003C\u002Fcode> – Display member information\u003C\u002Fli>\n\u003Cli>\u003Ccode>[memberstack_modal]\u003C\u002Fcode> – Add modal triggers\u003C\u002Fli>\n\u003Cli>\u003Ccode>[memberstack_logout]\u003C\u002Fcode> – Add logout buttons\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Getting Started\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install the Memberstack WordPress plugin\u003C\u002Fli>\n\u003Cli>Create your free Memberstack account at \u003Ca href=\"https:\u002F\u002Fmemberstack.com\" rel=\"nofollow ugc\">memberstack.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Copy your App ID from the Memberstack dashboard\u003C\u002Fli>\n\u003Cli>Paste the App ID in WordPress under Settings > Memberstack\u003C\u002Fli>\n\u003Cli>Start protecting content and adding membership features!\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Professional Support\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Extensive \u003Ca href=\"https:\u002F\u002Fdocs.memberstack.com\u002Fhc\u002Fen-us\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Support Team – \u003Ca href=\"https:\u002F\u002Fdocs.memberstack.com\u002Fhc\u002Fen-us\u002Frequests\u002Fnew\" rel=\"nofollow ugc\">Contact Us\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Community Forum – \u003Ca href=\"https:\u002F\u002Fdocs.memberstack.com\u002Fhc\u002Fen-us\u002Fcommunity\u002Fposts\" rel=\"nofollow ugc\">Join the Discussion\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>WordPress Slack Community – \u003Ca href=\"https:\u002F\u002Fwww.memberstack.com\u002Fwpslack\" rel=\"nofollow ugc\">Join the Slack Community\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>Memberstack integrates with our cloud service to manage memberships and protect content. \u003Ca href=\"https:\u002F\u002Fdocs.memberstack.com\u002Fhc\u002Fen-us\u002Farticles\u002F11419812024347-Privacy-Policy\" rel=\"nofollow ugc\">View our Privacy Policy\u003C\u002Fa>.\u003C\u002Fp>\n","Transform your WordPress site into a premium membership platform. Create members-only content and manage subscriptions with ease.",3288,24,"2026-03-03T09:43:00.000Z","6.9.5","6.7","7.4",[53,54,24,55,56],"content-protection","membership","subscription-management","user-authentication","https:\u002F\u002Fmemberstack.com\u002Fwordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmemberstack.1.3.1.zip",{"slug":60,"name":61,"version":62,"author":63,"author_profile":64,"description":65,"short_description":66,"active_installs":13,"downloaded":67,"rating":13,"num_ratings":68,"last_updated":69,"tested_up_to":16,"requires_at_least":70,"requires_php":51,"tags":71,"homepage":74,"download_link":75,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"onecode-login","OneCode Login","1.1","oaron","https:\u002F\u002Fprofiles.wordpress.org\u002Foaron\u002F","\u003Cp>OneCode Login provides a modern, passwordless authentication experience for your WordPress site. Instead of traditional passwords, users receive a secure 6-digit verification code via email.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Passwordless Authentication\u003C\u002Fstrong> – Users log in with just their email address\u003C\u002Fli>\n\u003Cli>\u003Cstrong>6-Digit Verification Codes\u003C\u002Fstrong> – Secure, time-limited codes sent via email\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate Limiting\u003C\u002Fstrong> – Built-in protection against brute force attacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Request ID Binding\u003C\u002Fstrong> – Each code is bound to a specific login session for enhanced security\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Neutral Feedback\u003C\u002Fstrong> – Prevents user enumeration attacks by not revealing if an email exists\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable\u003C\u002Fstrong> – Configure expiry times, cooldowns, and email templates\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Accessible\u003C\u002Fstrong> – Full keyboard navigation and screen reader support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gutenberg Block\u003C\u002Fstrong> – Easy to add login forms to any page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shortcode Support\u003C\u002Fstrong> – Use [onecode_login] anywhere\u003C\u002Fli>\n\u003Cli>\u003Cstrong>wp-login.php Integration\u003C\u002Fstrong> – Optionally replace the default WordPress login\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer API\u003C\u002Fstrong> – Other plugins can use OneCode Login as an email one-time-code (OTP) service to verify a visitor’s email — see the \u003Cem>Developer information\u003C\u002Fem> section\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Cryptographically secure code generation\u003C\u002Fli>\n\u003Cli>Codes and magic-link tokens are stored HMAC-hashed, never in plain text\u003C\u002Fli>\n\u003Cli>Configurable code expiry (default: 10 minutes)\u003C\u002Fli>\n\u003Cli>Resend cooldown to prevent spam\u003C\u002Fli>\n\u003Cli>IP-based and email-based rate limiting\u003C\u002Fli>\n\u003Cli>Automatic lockout after failed attempts\u003C\u002Fli>\n\u003Cli>Codes are single-use and invalidated after successful login\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Use Cases\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Membership sites where password fatigue is an issue\u003C\u002Fli>\n\u003Cli>Customer portals requiring simple authentication\u003C\u002Fli>\n\u003Cli>Internal tools where security without complexity is needed\u003C\u002Fli>\n\u003Cli>Any site wanting to improve user experience\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Developer information\u003C\u002Fh3>\n\u003Cp>Other plugins on the same site can use OneCode Login as a generic email\u003Cbr \u002F>\none-time-code (OTP) service — for example to verify a guest’s email before\u003Cbr \u002F>\nletting them act. OneCode emails the code and verifies it; your plugin keeps\u003Cbr \u002F>\nfull control of its own login\u002Fsession (OneCode only asserts that the code is\u003Cbr \u002F>\nvalid for the email — it never logs anyone in). It works for \u003Cstrong>any\u003C\u002Fstrong> email\u003Cbr \u002F>\naddress; the address does not need a WordPress account.\u003C\u002Fp>\n\u003Cp>All entry points are plain functions (and matching filters), so you do not need\u003Cbr \u002F>\na hard dependency on any class. The API is gated by the \u003Cem>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Advanced \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003Cbr \u002F>\nEnable developer API\u003C\u002Fem> toggle.\u003C\u002Fp>\n\u003Cp>Detect support (side-effect free — never call the request hook just to probe):\u003C\u002Fp>\n\u003Cpre>\u003Ccode>if ( function_exists( 'onecode_login_request_otp' ) && onecode_login_supports( 'otp' ) ) { ... }\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Col>\n\u003Cli>\n\u003Cp>Start authentication — email a code and receive a handle:\u003C\u002Fp>\n\u003Cp>$handle = onecode_login_request_otp( $email, array( ‘consumer’ => ‘my_plugin’ ) );\u003Cbr \u002F>\n\u002F\u002F $handle = array( ‘request_id’, ‘auth_secret’, ‘expires_in’ (seconds), ‘expires_at’ (UTC), ‘sent’ )\u003Cbr \u002F>\n\u002F\u002F On failure: a WP_Error (codes: disabled, invalid_request, rate_limited, cooldown).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Keep \u003Ccode>request_id\u003C\u002Fcode> and \u003Ccode>auth_secret\u003C\u002Fcode> server-side (e.g. in a transient tied to the\u003Cbr \u002F>\nvisitor). The \u003Ccode>auth_secret\u003C\u002Fcode> is NEVER shown to the customer — it is what stops an\u003Cbr \u002F>\noutsider who only knows the email from completing verification by guessing codes.\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>Complete authentication — the customer gives your plugin the code from the email:\u003C\u002Fp>\n\u003Cp>$result = onecode_login_verify_otp( array(\u003Cbr \u002F>\n    ’email’       => $email,\u003Cbr \u002F>\n    ‘request_id’  => $handle[‘request_id’],\u003Cbr \u002F>\n    ‘code’        => $code_from_customer,\u003Cbr \u002F>\n    ‘auth_secret’ => $handle[‘auth_secret’],\u003Cbr \u002F>\n    ‘consumer’    => ‘my_plugin’,\u003Cbr \u002F>\n) );\u003Cbr \u002F>\n\u002F\u002F Success: array( ‘valid’ => true, ’email’ => … ). Failure: WP_Error.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>On failure show a generic message to the user (the API intentionally returns a\u003Cbr \u002F>\nsingle \u003Ccode>verify_failed\u003C\u002Fcode> code so it can’t be used as an oracle).\u003C\u002Fp>\n\u003Cp>Filters are also available for loose coupling: \u003Ccode>onecode_login_request_otp\u003C\u002Fcode>\u003Cbr \u002F>\n(\u003Ccode>$pre, $email, $args\u003C\u002Fcode>) and \u003Ccode>onecode_login_verify_otp\u003C\u002Fcode> (\u003Ccode>$pre, $args\u003C\u002Fcode>).\u003C\u002Fp>\n\u003Cp>Discovery and capabilities:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>onecode_login_supports( $feature )\u003C\u002Fcode> — returns true for \u003Ccode>'otp'\u003C\u002Fcode>,\u003Cbr \u002F>\n  ‘identity_assertion’ and \u003Ccode>'any_email'\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Ccode>onecode_login_api()\u003C\u002Fcode> — returns the \u003Ccode>OneCode_Login_API\u003C\u002Fcode> service instance.\u003C\u002Fli>\n\u003Cli>\u003Ccode>OneCode_Login_API::VERSION\u003C\u002Fcode> — the API contract version (independent of the\u003Cbr \u002F>\nplugin version), so you can feature-gate against the API surface.\u003C\u002Fli>\n\u003Cli>\u003Ccode>do_action( 'onecode_login_api_init', $api )\u003C\u002Fcode> — fires once the API is ready;\u003Cbr \u002F>\nbind to it if you want to wire up as soon as OneCode Login loads.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Reference: \u003Ccode>$args['consumer']\u003C\u002Fcode> (a short \u003Ccode>[a-z0-9_-]\u003C\u002Fcode> label identifying your\u003Cbr \u002F>\nintegration) is required on both calls — it isolates your codes and rate limits\u003Cbr \u002F>\nfrom the built-in login and from other consumers. Both request and verify are\u003Cbr \u002F>\nrate-limited by OneCode, returning \u003Ccode>rate_limited\u003C\u002Fcode> \u002F \u003Ccode>cooldown\u003C\u002Fcode> WP_Errors you can\u003Cbr \u002F>\nsurface to the user.\u003C\u002Fp>\n","Simple and secure passwordless login using email verification codes. No passwords to remember, just enter your email and verify with a 6-digit code.",876,2,"2026-06-03T19:15:00.000Z","5.8",[20,72,21,73,22],"email","otp","https:\u002F\u002Fgithub.com\u002Fyour-repo\u002Fonecode-login","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fonecode-login.zip",{"slug":77,"name":78,"version":79,"author":80,"author_profile":81,"description":82,"short_description":83,"active_installs":84,"downloaded":85,"rating":27,"num_ratings":27,"last_updated":86,"tested_up_to":49,"requires_at_least":87,"requires_php":88,"tags":89,"homepage":94,"download_link":95,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"wapu-auth-social-login","Wapu Auth – Inicio de sesión social para WordPress y WooCommerce","2.0.0","Victor Flores","https:\u002F\u002Fprofiles.wordpress.org\u002Fvictor88lm\u002F","\u003Cp>\u003Cstrong>Wapu Auth\u003C\u002Fstrong> adds Google and Facebook social login to WordPress and WooCommerce. Provider OAuth processing is handled by the fixed \u003Cstrong>Wapu Auth Broker\u003C\u002Fstrong> at \u003Ccode>https:\u002F\u002Fauth.wapuos.com\u003C\u002Fcode>; provider client secrets and provider tokens never enter WordPress.\u003C\u002Fp>\n\u003Cp>On activation or update, Wapu Auth queues an asynchronous, one-shot background connection. An eligible public HTTPS site is registered, verified and checked without requiring a normal registration button click. The worker uses an expiring lock, reuses a pending broker challenge, retries temporary failures with bounded backoff and never rotates or re-registers a verified current-origin credential. Local, private, non-HTTPS and cloned origins fail closed. A protected manual retry remains available when the host, firewall or cron system needs attention.\u003C\u002Fp>\n\u003Cp>After the connection is verified, the plugin checks local HMAC signing, broker provider availability, schema integrity, identity preflight and safe backfill before enabling new broker login starts. Existing WordPress users, roles, WooCommerce customers, orders and downloads are not recreated or deleted by this workflow.\u003C\u002Fp>\n\u003Ch4>Main Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Google and Facebook login through full-page broker redirects and a closed provider registry.\u003C\u002Fli>\n\u003Cli>Automatic background site registration and proof-of-control verification for eligible public HTTPS sites.\u003C\u002Fli>\n\u003Cli>Encrypted, non-autoloaded per-site broker credentials with exact-origin binding.\u003C\u002Fli>\n\u003Cli>HMAC-signed server requests with timestamps, fresh nonces and fixed broker paths.\u003C\u002Fli>\n\u003Cli>Independent, expiring local transactions for concurrent login attempts.\u003C\u002Fli>\n\u003Cli>Canonical provider identities with conflict-aware account linking and safe unlinking.\u003C\u002Fli>\n\u003Cli>Adaptive provider controls: one enabled provider uses a full button; multiple providers use accessible circular buttons.\u003C\u002Fli>\n\u003Cli>Shortcodes \u003Ccode>[wapu_auth_button]\u003C\u002Fcode> and \u003Ccode>[wapu_auth_login_button]\u003C\u002Fcode>, plus the \u003Ccode>wapu-auth\u002Flogin-button\u003C\u002Fcode> block.\u003C\u002Fli>\n\u003Cli>Custom login and registration forms through \u003Ccode>[wapu_auth_login_form]\u003C\u002Fcode> and \u003Ccode>[wapu_auth_register_form]\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>WooCommerce login, registration, checkout return, profile autofill and My Account integration.\u003C\u002Fli>\n\u003Cli>Active WordPress session management, including individual revocation and closing other sessions.\u003C\u002Fli>\n\u003Cli>Safe return URLs, domain rules and a local sandbox allowlist.\u003C\u002Fli>\n\u003Cli>Local multiprovider analytics for Google, Facebook and traditional WordPress access, with provider filters and sanitized exports.\u003C\u002Fli>\n\u003Cli>Optional detailed Activity Log, GeoIP enrichment and GA4 event bridge.\u003C\u002Fli>\n\u003Cli>Identity migration diagnostics, bounded safe backfill and non-destructive broker pause\u002Fresume controls.\u003C\u002Fli>\n\u003Cli>Site-scoped support conversations through the broker’s audited HMAC API.\u003C\u002Fli>\n\u003Cli>Optional private image attachments in Support, capability-gated by the broker and proxied without exposing site credentials.\u003C\u002Fli>\n\u003Cli>Native WordPress login remains available when allowed by the site’s configuration.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How Broker Login Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>A visitor selects Google or Facebook.\u003C\u002Fli>\n\u003Cli>WordPress validates the return URL and creates an expiring, provider-bound local transaction.\u003C\u002Fli>\n\u003Cli>WordPress sends a signed request to \u003Ccode>\u002Fapi\u002Fv1\u002Fgoogle\u002Fsessions\u003C\u002Fcode> or \u003Ccode>\u002Fapi\u002Fv1\u002Ffacebook\u002Fsessions\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>The broker returns an allowlisted provider start URL and completes provider OAuth.\u003C\u002Fli>\n\u003Cli>The broker returns a one-use \u003Ccode>wxc_*\u003C\u002Fcode> code to \u003Ccode>\u002Fwapu-auth\u002Foauth\u002Fcallback\u003C\u002Fcode> on the WordPress site.\u003C\u002Fli>\n\u003Cli>WordPress consumes the local transaction and exchanges the code at \u003Ccode>\u002Fapi\u002Fv1\u002Foauth\u002Fexchange\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>The plugin requires the returned provider and subject to match the local transaction before resolving, linking or creating the WordPress user.\u003C\u002Fli>\n\u003Cli>WordPress issues its normal authentication cookies and applies the validated local return URL.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Compatibility and Removed Features\u003C\u002Fh4>\n\u003Cp>The deprecated \u003Ccode>[wapu_auth_popup]\u003C\u002Fcode> and \u003Ccode>[wapu_auth_popup_button]\u003C\u002Fcode> aliases still render the normal redirect control for one compatibility cycle. They do not open a popup.\u003C\u002Fp>\n\u003Cp>Version 2.0 removes Google One Tap, local modal authentication, emailed login links, email OTP, trusted-device bypasses and integrated SMTP configuration. Active Sessions, normal WordPress notifications through \u003Ccode>wp_mail()\u003C\u002Fcode>, the primary shortcodes, block, forms and WooCommerce flows remain available.\u003C\u002Fp>\n\u003Cp>WordPress Multisite is not supported. Activation is stopped before identity migrations on a network installation.\u003C\u002Fp>\n\u003Ch3>Hooks & Filters\u003C\u002Fh3>\n\u003Ch4>Actions\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>wapu_auth_before_login\u003C\u002Fcode> — before a broker authorization session is created.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_user_authenticated\u003C\u002Fcode> — after successful user resolution.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_user_created\u003C\u002Fcode> — after a WordPress user is created.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_provider_account_unlinked\u003C\u002Fcode> — after one provider mapping is removed.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_google_account_unlinked\u003C\u002Fcode> — compatibility action after a Google mapping is removed.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_analytics_event\u003C\u002Fcode> — after a local analytics event is recorded.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_log\u003C\u002Fcode> — after the plugin logger records an entry.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wp_login\u003C\u002Fcode> — standard WordPress action, fired exactly once for a successful broker login.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Filters\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>wapu_auth_user_data\u003C\u002Fcode> — presentation fields only; provider identity fields remain immutable.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_redirect_url\u003C\u002Fcode> — final redirect, subject to same-origin validation.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_error_message\u003C\u002Fcode> — local user-facing error copy.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_button_html\u003C\u002Fcode> — rendered provider control HTML.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_geoip_enabled\u003C\u002Fcode> — optional GeoIP enrichment.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The legacy \u003Ccode>wapu_auth_auth_params\u003C\u002Fcode>, \u003Ccode>wapu_auth_redirect_uri\u003C\u002Fcode> and \u003Ccode>wapu_auth_oauth_base_url\u003C\u002Fcode> filters are compatibility notifications. They cannot change the broker host, callback, provider, state, nonce, signature, ticket or one-use code.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Ch4>1. Wapu Auth Broker (required for social login)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Fixed origin:\u003C\u002Fstrong> \u003Ccode>https:\u002F\u002Fauth.wapuos.com\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When used:\u003C\u002Fstrong> after activation or update for background registration\u002Fverification and provider health; when a visitor starts or completes social login; when an administrator deliberately rotates a credential or uses the Support section.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Endpoints used:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>POST \u002Fapi\u002Fv1\u002Fsites\u002Fregister\u002Finit\u003C\u002Fcode> and \u003Ccode>POST \u002Fapi\u002Fv1\u002Fsites\u002Fregister\u002Fverify\u003C\u002Fcode> for proof-of-control registration.\u003C\u002Fli>\n\u003Cli>\u003Ccode>GET \u002Fhealth\u003C\u002Fcode> for a public, secret-free provider availability snapshot.\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fapi\u002Fv1\u002Fgoogle\u002Fsessions\u003C\u002Fcode> or \u003Ccode>POST \u002Fapi\u002Fv1\u002Ffacebook\u002Fsessions\u003C\u002Fcode> to begin login.\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fapi\u002Fv1\u002Foauth\u002Fexchange\u003C\u002Fcode> to exchange the callback’s one-use code.\u003C\u002Fli>\n\u003Cli>Browser paths under \u003Ccode>\u002Foauth\u002Fgoogle\u002F*\u003C\u002Fcode> or \u003Ccode>\u002Foauth\u002Ffacebook\u002F*\u003C\u002Fcode> during provider authorization.\u003C\u002Fli>\n\u003Cli>Site-scoped \u003Ccode>\u002Fapi\u002Fv1\u002Fsupport\u002F*\u003C\u002Fcode> operations only when an administrator uses Support.\u003C\u002Fli>\n\u003Cli>Signed binary support-image upload plus private thumbnail\u002Fcontent delivery only when the broker capability flag is enabled.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Registration data:\u003C\u002Fstrong> canonical site URL, fixed local callback URL, short-lived verification URL and registration identifier. The broker performs a public GET of the verification URL, which returns only the active short-lived challenge.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login data:\u003C\u002Fstrong> site ID, HMAC timestamp\u002Fnonce\u002Fsignature headers, provider-bound local state, validated return context and the one-use exchange code. Sensitive protocol values are not written to plugin logs.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Identity data received:\u003C\u002Fstrong> provider, provider subject, email and verification state, and optional name\u002Favatar fields. Provider tokens, refresh tokens, provider authorization codes and provider client secrets are not returned to WordPress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Support data:\u003C\u002Fstrong> the subject, allowlisted category, public messages and optional JPEG\u002FPNG\u002FWebP evidence deliberately entered by an administrator. Images are normalized to remove EXIF\u002FGPS and unnecessary metadata, remain in private broker storage and are returned only through authorized proxy requests. Internal broker notes and private agent data are not exposed to WordPress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Documents:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fauth.wapuos.com\u002Fabout\" rel=\"nofollow ugc\">About\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fauth.wapuos.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fauth.wapuos.com\u002Fterms\" rel=\"nofollow ugc\">Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>2. Google OAuth \u002F OpenID Connect (indirect)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>When used:\u003C\u002Fstrong> only after a visitor actively selects Google.\u003C\u002Fp>\n\u003Cp>The visitor reaches Google through the broker. Google receives normal OAuth request and browser\u002Fnetwork metadata under its own policies. Provider tokens stay at the broker and are not returned to WordPress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Google Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fterms\" rel=\"nofollow ugc\">Google Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>3. Meta \u002F Facebook Login (indirect)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>When used:\u003C\u002Fstrong> only after a visitor actively selects Facebook.\u003C\u002Fp>\n\u003Cp>The visitor reaches Facebook through the broker. Meta may receive normal OAuth request and browser\u002Fnetwork metadata under its own policies. Provider tokens stay at the broker and are not returned to WordPress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fprivacy\u002Fpolicy\u002F\" rel=\"nofollow ugc\">Meta Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fterms\u002F\" rel=\"nofollow ugc\">Meta Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>4. GeoIP providers (optional, disabled by default)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Services:\u003C\u002Fstrong> \u003Ccode>https:\u002F\u002Fipapi.co\u002F\u003C\u002Fcode>, with \u003Ccode>https:\u002F\u002Fipwho.is\u002F\u003C\u002Fcode> as fallback.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data sent:\u003C\u002Fstrong> visitor IP address and normal HTTP metadata.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When used:\u003C\u002Fstrong> only when the administrator enables GeoIP enrichment. The site owner is responsible for an appropriate legal basis and consent where required.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fipapi.co\u002Fprivacy\u002F\" rel=\"nofollow ugc\">ipapi.co Privacy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fipwhois.io\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">ipwho.is Privacy\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>5. Google Analytics 4 event bridge (optional, disabled by default)\u003C\u002Fh4>\n\u003Cp>The plugin can call a site’s existing \u003Ccode>gtag\u003C\u002Fcode> function with provider-aware social-login events and limited status metadata. It does not load Google Analytics itself. The site administrator is responsible for consent and the site’s Analytics configuration.\u003C\u002Fp>\n\u003Ch3>Privacy & Data Retention\u003C\u002Fh3>\n\u003Cp>Wapu Auth stores local configuration, encrypted broker credentials, a one-way verified-origin fingerprint, hashed and expiring transaction state, canonical provider mappings, compatibility metadata, WordPress session data and any enabled analytics or Activity Log records. Depending on settings, detailed logs can contain account email, IP address and derived location.\u003C\u002Fp>\n\u003Cp>The automatic-connection state contains only sanitized status codes, counters, timestamps, provider availability and a one-way origin hash. It never contains the broker challenge, registration ID, site secret, signature, request payload or remote response.\u003C\u002Fp>\n\u003Cp>While one proof-of-control operation is pending, its registration ID and challenge are held separately in a short-lived WordPress transient only until verification, explicit recovery or expiry; they are not copied to plugin logs.\u003C\u002Fp>\n\u003Cp>Wapu Auth does not store provider access tokens, provider refresh tokens, provider authorization codes, raw HMAC signatures, broker tickets or one-use exchange codes. Legacy Google Client ID\u002FSecret values from 1.x are retained only in separate authenticated encrypted storage until an administrator completes the protected removal flow.\u003C\u002Fp>\n\u003Cp>Optional GeoIP and GA4 features are disabled by default. Administrators should update their own privacy notice and select a retention period appropriate to their jurisdiction.\u003C\u002Fp>\n\u003Cp>Optional Support images are disabled until the broker advertises the compatible \u003Ccode>WAPU-SUPPORT-ATTACHMENT-V1\u003C\u002Fcode> capability. Pending images are temporary and pruned after expiry; linked images are retained only for the broker support workflow and removed under its ticket\u002Fsite retention policy. They are not attached to WhatsApp or administrative email notifications. The broker strips EXIF, GPS and unnecessary image metadata during normalization. Site administrators should avoid uploading secrets or unrelated personal information and describe this support processing in their own privacy notice when the feature is enabled.\u003C\u002Fp>\n","Google and Facebook social login for WordPress and WooCommerce through Wapu Auth Broker, with secure account linking, sessions and local analytics.",80,948,"2026-07-18T20:27:00.000Z","6.3","8.0",[90,91,92,24,93],"facebook-login","oauth2","passwordless-login","woocommerce-login","https:\u002F\u002Fwapuclub.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwapu-auth-social-login.2.0.0.zip",{"slug":97,"name":98,"version":99,"author":100,"author_profile":101,"description":102,"short_description":103,"active_installs":104,"downloaded":105,"rating":13,"num_ratings":106,"last_updated":107,"tested_up_to":16,"requires_at_least":108,"requires_php":51,"tags":109,"homepage":113,"download_link":114,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"ventraconnect-social-login","Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect","1.4.3","Fahad Aslam","https:\u002F\u002Fprofiles.wordpress.org\u002Ffahdaslam\u002F","\u003Cp>VentraConnect provides a \u003Cstrong>native authentication stack and unified login system\u003C\u002Fstrong> for WordPress: Social Login, Passkeys, Magic Link and Email OTP.\u003Cbr \u002F>\nBuilt around the native WordPress user system, it gives your site modern sign-in methods without routing sensitive authentication data through external proxy servers or relying on third-party passkey platforms.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Social Login\u003C\u002Fstrong>: with 15+ providers, including Google, Facebook, X\u002FTwitter, LinkedIn, Microsoft, GitHub and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Native Passkeys\u003C\u002Fstrong>: Secure passwordless sign-in using supported device authenticators such as Touch ID, Face ID and Windows Hello. Passkey authentication uses WebAuthn through your WordPress site, without relying on an external passkey platform.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Passwordless Login\u003C\u002Fstrong> with \u003Cstrong>Magic Link\u003C\u002Fstrong> and \u003Cstrong>Email OTP\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>Can run in \u003Cstrong>Login only\u003C\u002Fstrong> mode (existing users) or \u003Cstrong>Login & Register\u003C\u002Fstrong> mode (allow new accounts)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Guardrails (optional)\u003C\u002Fstrong>: Unlike standard plugins that automatically create a new account whenever an unknown visitor uses a social button on your login screen, VentraConnect gives you full control over registration. Guardrails allow \u003Cstrong>Social Login, Magic Link and Email OTP\u003C\u002Fstrong> to securely authenticate your existing users while blocking the creation of new accounts from the login form when you choose. This prevents random visitors from turning your login screen into an accidental open registration form, while your official registration screen and custom onboarding flows continue to work exactly as intended.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Use the login methods your site needs\u003C\u002Fh4>\n\u003Cp>VentraConnect is modular. Enable Social Login, Passkeys, Magic Link and Email OTP individually, or combine the available methods into one sign-in experience.\u003C\u002Fp>\n\u003Cp>For example, a site can offer one or more social providers only, Email OTP only, Magic Link only, Passkeys only, or several sign-in methods together alongside normal WordPress passwords.\u003C\u002Fp>\n\u003Cp>There is no required login-method bundle. Social Login, Magic Link and Email OTP can also use Guardrails to control whether unknown visitors are allowed to create new accounts, while still allowing existing users to sign in.\u003C\u002Fp>\n\u003Cp>Works out-of-the-box on the default WordPress login\u002Fregistration screens (\u003Ccode>wp-login.php\u003C\u002Fcode>) and also supports shortcodes for custom pages and page builders.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>No proxy servers. No third-party tracking.\u003C\u002Fstrong> VentraConnect connects directly to social providers through official OAuth flows. Passkey authentication is handled natively through your WordPress site using WebAuthn, without external platform dependencies.\u003C\u002Fp>\n\u003Cp>| \u003Ca href=\"https:\u002F\u002Fwpventra.com\u002Fdocs\u002Fwhat-is-ventraconnect-social-login\u002F\" rel=\"nofollow ugc\">Setup\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwpventra.com\u002Fdocs\u002F\" rel=\"nofollow ugc\">Docs\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwpventra.com\u002Fpricing\u002F\" rel=\"nofollow ugc\">Pro Addon\u003C\u002Fa> |\u003C\u002Fp>\n\u003Ch3>Modern WordPress login with VentraConnect\u003C\u002Fh3>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FFEi8XCa6sys?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch3>Best for\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Sites that want faster sign-in and fewer abandoned registrations\u003C\u002Fstrong> by offering Social Login, Passkeys, Magic Link and Email OTP alongside normal WordPress login.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce stores\u003C\u002Fstrong> that want a smoother checkout and account experience with Social Login and passwordless login on supported login, checkout and My Account flows (Pro).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>LMS, membership and community sites\u003C\u002Fstrong> that need simpler onboarding, modern login choices and advanced authentication placements across courses, memberships and member areas (Pro).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sites fighting spam registrations\u003C\u002Fstrong> that want Guardrails to control whether Social Login, Magic Link and Email OTP can create new accounts from the default wp-login.php screen, without locking out existing users.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security-focused site owners\u003C\u002Fstrong> who want native Passkey sign-in with supported device authenticators such as Touch ID, Face ID and Windows Hello, plus profile-based Passkey management.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Growing sites and agencies\u003C\u002Fstrong> that want one authentication foundation for WordPress, WooCommerce, LMS and membership workflows instead of stitching together separate login plugins.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexible site architectures\u003C\u002Fstrong> that want to introduce Passkeys, Magic Link or Email OTP without removing the classic username\u002Fpassword login fallback.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Key Features (Free)\u003C\u002Fh3>\n\u003Ch4>Social Login\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>15+ Social Providers:\u003C\u002Fstrong> Google, Facebook, X\u002FTwitter, LinkedIn, Microsoft, GitHub, Discord, Reddit, Slack, Twitch, Spotify, TikTok, Amazon, Yahoo, WordPress.com and LINE.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Native WordPress Login Screens:\u003C\u002Fstrong> Adds login buttons to default WordPress login and registration screens (\u003Ccode>wp-login.php\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Shortcodes:\u003C\u002Fstrong> Add login methods to custom pages, page builders and dedicated login layouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Account Linking:\u003C\u002Fstrong> Users can connect or remove multiple social providers from one WordPress account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Profile Sync:\u003C\u002Fstrong> Optionally sync display names and avatars from verified social providers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Button Styles:\u003C\u002Fstrong> Light, Dark and Minimal themes, with wide or compact social button layouts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Native Passkeys\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Native WordPress Architecture:\u003C\u002Fstrong> Passkey authentication is handled through your WordPress site using WebAuthn, without relying on an external passkey platform.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Modern Device Support:\u003C\u002Fstrong> Works with supported authenticators such as Touch ID, Face ID, Windows Hello, Android biometrics and hardware security keys.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Core Login and Registration Support:\u003C\u002Fstrong> Passkey sign-in and registration on supported default WordPress forms, plus the VentraConnect shortcode.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Profile Passkey Management:\u003C\u002Fstrong> Users can add and remove multiple Passkeys from their WordPress profile.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built-In Fallback Options:\u003C\u002Fstrong> Enable Magic Link or Email OTP alongside Passkeys, so users can still sign in from older devices, restricted browsers or situations where their Passkey is not available.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Passwordless Login: Magic Link and Email OTP\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Built-In Security:\u003C\u002Fstrong> Expiry windows, resend throttling, single-use Magic Links and verification attempt limits.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Per-Method Rules:\u003C\u002Fstrong> Set each method to \u003Cstrong>Login only\u003C\u002Fstrong> or \u003Cstrong>Login & Register\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Redirect Controls:\u003C\u002Fstrong> Redirect users to the same page, referrer, homepage or a custom URL after login.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Controls:\u003C\u002Fstrong> Edit sender details, subjects and email message templates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Polished HTML Emails:\u003C\u002Fstrong> Default Magic Link and Email OTP email templates designed for clear sign-in actions and easy code entry.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Guardrails: Spam and Signup Control\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Registration Control:\u003C\u002Fstrong> Choose whether Social Login, Magic Link and Email OTP can create new WordPress accounts from login forms.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Existing Users Can Still Sign In:\u003C\u002Fstrong> Keep login methods available for known users while blocking unwanted account creation when needed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Keep Your Existing Registration Process:\u003C\u002Fstrong> Normal WordPress registration, custom onboarding pages and third-party registration workflows continue to work as intended.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Admin and Diagnostic Tools\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Redirect Settings:\u003C\u002Fstrong> Configure global redirect behaviour for Social Login and passwordless methods.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Local Diagnostics and Logs:\u003C\u002Fstrong> Troubleshoot OAuth callbacks and login issues from the WordPress dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Account Creation Notifications:\u003C\u002Fstrong> Send email notifications to users and administrators when a new account is created through Social Login.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Pro Add-on (Optional)\u003C\u002Fh3>\n\u003Cp>VentraConnect Pro extends the same native authentication stack into WooCommerce, LMS, membership and community workflows with advanced Passkey placements, branded authentication experiences and deeper controls.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>New in Pro for 1.4.0:\u003C\u002Fstrong> Dedicated integrations for \u003Cstrong>Tutor LMS\u003C\u002Fstrong> and \u003Cstrong>Paid Membership Subscriptions (PMS)\u003C\u002Fstrong>, including supported login, registration and account experiences.\u003C\u002Fp>\n\u003Ch4>Advanced Passkey Integrations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>WooCommerce Passkey Experiences:\u003C\u002Fstrong> Add Passkey sign-in and setup prompts across supported login, checkout, Thank You and My Account flows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Floating Passkey Setup Prompt:\u003C\u002Fstrong> Encourage logged-in users who have not registered a Passkey to secure their account with a simple, non-intrusive setup panel.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Account Placements:\u003C\u002Fstrong> Add Passkey setup and management experiences across supported third-party account areas.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WooCommerce Integration\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Add Social Login, Passkeys, Magic Link and Email OTP to supported WooCommerce login, checkout and My Account flows.\u003C\u002Fli>\n\u003Cli>Let returning customers sign in with a saved Passkey during supported checkout and login experiences.\u003C\u002Fli>\n\u003Cli>Show optional Passkey setup prompts to eligible logged-in customers on checkout and Thank You pages.\u003C\u002Fli>\n\u003Cli>Keep Magic Link and Email OTP available alongside Passkeys as passwordless fallback options when needed.\u003C\u002Fli>\n\u003Cli>Control account creation through Guardrails-aware Social Login, Magic Link and Email OTP flows.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>LMS, Membership and Community Integrations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>LMS Platforms:\u003C\u002Fstrong> Tutor LMS, LearnDash, LifterLMS and LearnPress integrations for supported login, registration and account experiences.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Membership and Community Platforms:\u003C\u002Fstrong> MemberPress, Ultimate Member, Paid Memberships Pro (PMPro), Paid Membership Subscriptions (PMS) and BuddyPress.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Integration-Aware Login Methods:\u003C\u002Fstrong> Place supported authentication methods where they make sense across third-party login, registration and account screens.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Password Phaseout and Advanced Rules\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Password Phaseout:\u003C\u002Fstrong> Choose \u003Cstrong>Off\u003C\u002Fstrong>, \u003Cstrong>Recommended\u003C\u002Fstrong> or \u003Cstrong>Strict\u003C\u002Fstrong> modes to control how passwords are presented on supported forms, while keeping an administrator fallback available.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Redirect Rules:\u003C\u002Fstrong> Apply redirects based on login, registration, checkout or supported integration context.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Context-Based Shortcodes:\u003C\u002Fstrong> Control authentication placement for supported third-party login surfaces.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Branded Emails, Forms and Insights\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Inline Magic Link and Email OTP Forms:\u003C\u002Fstrong> Embed complete forms directly into custom pages, headers, Elementor popups, account areas and tailored login layouts.\u003C\u002Fp>\n\u003Cp>[ventraconnect_magic_link_form]\u003C\u002Fp>\n\u003Cp>[ventraconnect_email_otp_form]\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Branded Authentication Emails:\u003C\u002Fstrong> Add your logo, accent colour and footer text to Magic Link, Email OTP and Passkey registration emails.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Analytics and Login Insights:\u003C\u002Fstrong> Review login activity, popular social providers and authentication-method performance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Diagnostics:\u003C\u002Fstrong> Access additional logs and diagnostics for complex authentication setups.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Pro features require the separate \u003Ca href=\"https:\u002F\u002Fwpventra.com\u002Fpricing\u002F\" rel=\"nofollow ugc\">VentraConnect Pro\u003C\u002Fa> add-on.\u003C\u002Fp>\n\u003Ch3>Supported Social Providers\u003C\u002Fh3>\n\u003Cp>Google, Facebook, X (Twitter), LinkedIn, Microsoft, GitHub, Discord, Reddit, Slack, Twitch, Spotify, TikTok, Amazon, Yahoo, WordPress.com and LINE.\u003C\u002Fp>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Cp>Users can sign in with Social Login, Passkeys, Magic Link or Email OTP.\u003C\u002Fp>\n\u003Cp>Social Login uses the selected provider’s official OAuth flow.\u003Cbr \u002F>\nPasskeys use WebAuthn through the user’s supported browser and device.\u003Cbr \u002F>\nMagic Link and Email OTP verify ownership of the user’s email address.\u003Cbr \u002F>\nVentraConnect matches verified provider or email data with an existing WordPress user and signs them in. New accounts may be created based on your registration settings and Guardrails configuration.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>VentraConnect acts as an OAuth client only. During Social Login, users are redirected to the selected provider, which returns an authorization token to your WordPress site. VentraConnect then retrieves basic profile data such as provider ID, email address, display name and avatar URL.\u003C\u002Fp>\n\u003Cp>Passkey authentication is handled natively on your WordPress site using WebAuthn and the user’s browser or device authenticator. No external passkey service is required.\u003C\u002Fp>\n\u003Cp>No user data is sent to or stored on servers owned by the plugin author. Communication happens directly between your WordPress site and the enabled provider’s official APIs.\u003C\u002Fp>\n\u003Ch3>Provider Domains Used\u003C\u002Fh3>\n\u003Cp>Google: accounts.google.com, oauth2.googleapis.com, people.googleapis.com\u003Cbr \u002F>\nFacebook: graph.facebook.com\u003Cbr \u002F>\nMicrosoft: login.microsoftonline.com, graph.microsoft.com\u003Cbr \u002F>\nTikTok: open.tiktokapis.com\u003Cbr \u002F>\nReddit: www.reddit.com, oauth.reddit.com\u003Cbr \u002F>\nLINE: access.line.me, api.line.me\u003Cbr \u002F>\nSlack: slack.com\u003Cbr \u002F>\nDiscord: discord.com\u003Cbr \u002F>\nTwitch: id.twitch.tv, api.twitch.tv\u003Cbr \u002F>\nGitHub: github.com, api.github.com\u003Cbr \u002F>\nAmazon: www.amazon.com, api.amazon.com\u003Cbr \u002F>\nYahoo: api.login.yahoo.com\u003Cbr \u002F>\nWordPress.com: public-api.wordpress.com\u003Cbr \u002F>\nLinkedIn: www.linkedin.com, api.linkedin.com\u003C\u002Fp>\n\u003Cp>Each provider has its own Terms of Service and Privacy Policy. You are responsible for complying with those terms when enabling a provider.\u003C\u002Fp>\n","Social login & passwordless login with Passkeys, Magic Link and Email OTP, plus Guardrails to control spam registrations.",50,1734,3,"2026-07-01T14:32:00.000Z","6.2",[110,111,112,92,24],"email-otp","magic-link","passkeys","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fventraconnect-social-login.1.4.3.zip",{"slug":116,"name":117,"version":118,"author":119,"author_profile":120,"description":121,"short_description":122,"active_installs":123,"downloaded":124,"rating":27,"num_ratings":27,"last_updated":125,"tested_up_to":126,"requires_at_least":127,"requires_php":113,"tags":128,"homepage":132,"download_link":133,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"keyless-auth","Keyless Auth – Login without Passwords","3.2.4","Chris Martens","https:\u002F\u002Fprofiles.wordpress.org\u002Fchrmrtns\u002F","\u003Cp>Transform your WordPress login experience with passwordless authentication. Users simply enter their email address and receive a secure magic link – click to login instantly. It’s more secure than weak passwords and infinitely more user-friendly.\u003C\u002Fp>\n\u003Ch4>Why Choose Keyless Auth?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enhanced Security\u003C\u002Fstrong>: No more weak, reused, or compromised passwords\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Better User Experience\u003C\u002Fstrong>: One click instead of remembering complex passwords\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reduced Support\u003C\u002Fstrong>: Eliminate “forgot password” requests\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Modern Authentication\u003C\u002Fstrong>: Enterprise-grade security used by Slack, Medium, and others\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Hardening\u003C\u002Fstrong>: Built-in protection against brute force attacks and username enumeration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Quick Start\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install and activate the plugin\u003C\u002Fli>\n\u003Cli>Create a new page and add the shortcode \u003Ccode>[keyless-auth]\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Configure email templates in \u003Cstrong>Keyless Auth \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Templates\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Done! Users can now login passwordlessly\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Core Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Ready to Use\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Magic Link Authentication\u003C\u002Fstrong> – Secure, one-time login links via email\u003Cbr \u002F>\n* \u003Cstrong>Two-Factor Authentication (2FA)\u003C\u002Fstrong> – Complete TOTP support with Google Authenticator\u003Cbr \u002F>\n* \u003Cstrong>Role-Based 2FA\u003C\u002Fstrong> – Require 2FA for specific user roles (admins, editors, etc.)\u003Cbr \u002F>\n* \u003Cstrong>Custom 2FA Setup URLs\u003C\u002Fstrong> – Direct users to branded frontend 2FA setup pages\u003Cbr \u002F>\n* \u003Cstrong>SMTP Integration\u003C\u002Fstrong> – Reliable email delivery through your mail server\u003Cbr \u002F>\n* \u003Cstrong>Email Templates\u003C\u002Fstrong> – Professional, customizable login emails\u003Cbr \u002F>\n* \u003Cstrong>Mail Logging\u003C\u002Fstrong> – Track all sent emails with delivery status\u003Cbr \u002F>\n* \u003Cstrong>Custom Database Tables\u003C\u002Fstrong> – Scalable architecture with dedicated audit logs\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Security\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Token Security\u003C\u002Fstrong>: 10-minute expiration, single-use tokens\u003Cbr \u002F>\n* \u003Cstrong>Audit Logging\u003C\u002Fstrong>: IP addresses, device types, login attempts\u003Cbr \u002F>\n* \u003Cstrong>Emergency Mode\u003C\u002Fstrong>: Grace period system with admin controls\u003Cbr \u002F>\n* \u003Cstrong>Secure Storage\u003C\u002Fstrong>: SMTP credentials in wp-config.php option\u003Cbr \u002F>\n* \u003Cstrong>XML-RPC Disable\u003C\u002Fstrong>: Block brute force attacks via XML-RPC interface\u003Cbr \u002F>\n* \u003Cstrong>Application Passwords Control\u003C\u002Fstrong>: Disable programmatic authentication when not needed\u003Cbr \u002F>\n* \u003Cstrong>User Enumeration Prevention\u003C\u002Fstrong>: Block username discovery attacks\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Customization\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>WYSIWYG Email Editor\u003C\u002Fstrong>: Full HTML support with live preview\u003Cbr \u002F>\n* \u003Cstrong>Advanced Color Controls\u003C\u002Fstrong>: Hex, RGB, HSL color formats\u003Cbr \u002F>\n* \u003Cstrong>Template System\u003C\u002Fstrong>: German, English, and custom templates\u003Cbr \u002F>\n* \u003Cstrong>Branding Options\u003C\u002Fstrong>: Custom sender names and professional styling\u003C\u002Fp>\n\u003Ch4>Installation & Setup\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Basic Installation\u003C\u002Fstrong>\u003Cbr \u002F>\n1. WordPress Admin \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Plugins \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add New\u003Cbr \u002F>\n2. Search for “Keyless Auth”\u003Cbr \u002F>\n3. Install and activate\u003Cbr \u002F>\n4. Add [keyless-auth] shortcode to any page\u003C\u002Fp>\n\u003Cp>\u003Cstrong>SMTP Configuration (Recommended)\u003C\u002Fstrong>\u003Cbr \u002F>\n1. Navigate to Keyless Auth \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> SMTP\u003Cbr \u002F>\n2. Configure your email provider (Gmail, Outlook, SendGrid, etc.)\u003Cbr \u002F>\n3. Test email delivery\u003Cbr \u002F>\n4. Save settings\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Two-Factor Authentication Setup\u003C\u002Fstrong>\u003Cbr \u002F>\n1. Go to Keyless Auth \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Options\u003Cbr \u002F>\n2. Enable “Two-Factor Authentication”\u003Cbr \u002F>\n3. Select required user roles\u003Cbr \u002F>\n4. Users scan QR code with authenticator app\u003C\u002Fp>\n\u003Ch4>Email Templates\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Template Options\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>German Professional\u003C\u002Fstrong>: Sleek German-language template\u003Cbr \u002F>\n* \u003Cstrong>English Simple\u003C\u002Fstrong>: Clean, minimalist design\u003Cbr \u002F>\n* \u003Cstrong>Custom HTML\u003C\u002Fstrong>: Create your own with WYSIWYG editor\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Customization Features\u003C\u002Fstrong>\u003Cbr \u002F>\n* Full HTML and CSS support\u003Cbr \u002F>\n* Color picker for buttons and links\u003Cbr \u002F>\n* Responsive email design\u003Cbr \u002F>\n* Live template preview\u003Cbr \u002F>\n* Placeholder system for dynamic content\u003C\u002Fp>\n\u003Ch4>Security & Compliance\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Token Security\u003C\u002Fstrong>\u003Cbr \u002F>\n* Generated using WordPress security standards\u003Cbr \u002F>\n* Based on user ID, timestamp, and wp-config.php salt\u003Cbr \u002F>\n* 10-minute expiration with single-use enforcement\u003Cbr \u002F>\n* Secure database storage with automatic cleanup\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Two-Factor Authentication\u003C\u002Fstrong>\u003Cbr \u002F>\n* TOTP-based system compatible with Google Authenticator, Authy\u003Cbr \u002F>\n* Role-based requirements for granular control\u003Cbr \u002F>\n* Grace period system for smooth user transitions\u003Cbr \u002F>\n* Custom verification forms with professional styling\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Database Architecture\u003C\u002Fstrong>\u003Cbr \u002F>\n* Custom tables for optimal performance\u003Cbr \u002F>\n* Comprehensive audit logging\u003Cbr \u002F>\n* Device tracking and IP monitoring\u003Cbr \u002F>\n* Automatic maintenance and cleanup routines\u003C\u002Fp>\n\u003Ch4>Security Hardening\u003C\u002Fh4>\n\u003Cp>Keyless Auth includes comprehensive security hardening features to protect your WordPress site from common attack vectors. All features are optional and can be enabled based on your site’s needs.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>XML-RPC Disable\u003C\u002Fstrong>\u003Cbr \u002F>\n* Prevents brute force attacks via WordPress XML-RPC interface\u003Cbr \u002F>\n* Reduces attack surface by disabling legacy API\u003Cbr \u002F>\n* Recommended for sites not using Jetpack, mobile apps, or pingbacks\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Application Passwords Control\u003C\u002Fstrong>\u003Cbr \u002F>\n* Disable REST API and XML-RPC authentication when programmatic access isn’t needed\u003Cbr \u002F>\n* Prevents unauthorized API access\u003Cbr \u002F>\n* Recommended for simple sites without third-party integrations\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User Enumeration Prevention\u003C\u002Fstrong>\u003Cbr \u002F>\n* Blocks REST API user endpoints (\u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fusers\u003C\u002Fcode>)\u003Cbr \u002F>\n* Redirects author archives and \u003Ccode>?author=N\u003C\u002Fcode> queries\u003Cbr \u002F>\n* Removes login error messages that reveal usernames\u003Cbr \u002F>\n* Strips comment author CSS classes\u003Cbr \u002F>\n* Removes author data from oEmbed responses\u003Cbr \u002F>\n* Recommended for business\u002Fcorporate sites without author profiles\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Benefits\u003C\u002Fstrong>\u003Cbr \u002F>\n* Combined protection against brute force attacks\u003Cbr \u002F>\n* Prevents username discovery for targeted attacks\u003Cbr \u002F>\n* Reduces unauthorized API access\u003Cbr \u002F>\n* Easy to configure without code or .htaccess modifications\u003Cbr \u002F>\n* All features include comprehensive documentation\u003Cbr \u002F>\n* FTP recovery available if needed\u003C\u002Fp>\n\u003Ch4>SMTP & Email Delivery\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Supported Providers\u003C\u002Fstrong>\u003Cbr \u002F>\n* Gmail \u002F Google Workspace\u003Cbr \u002F>\n* Outlook \u002F Microsoft 365\u003Cbr \u002F>\n* Mailgun, SendGrid, Amazon SES\u003Cbr \u002F>\n* Any SMTP-compatible service\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Email Features\u003C\u002Fstrong>\u003Cbr \u002F>\n* Message-ID domain alignment for deliverability\u003Cbr \u002F>\n* SPF\u002FDKIM\u002FDMARC compliance\u003Cbr \u002F>\n* Custom sender names and addresses\u003Cbr \u002F>\n* Bulk email log management\u003Cbr \u002F>\n* Delivery status tracking\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Secure Credential Storage\u003C\u002Fstrong>\u003Cbr \u002F>\nStore SMTP credentials securely in wp-config.php:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>define('CHRMRTNS_KLA_SMTP_USERNAME', 'your-email@example.com');\ndefine('CHRMRTNS_KLA_SMTP_PASSWORD', 'your-smtp-password');\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>WordPress Integration\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Login Page Integration\u003C\u002Fstrong>\u003Cbr \u002F>\n* Optional magic login field on wp-login.php\u003Cbr \u002F>\n* Seamless integration with existing login flow\u003Cbr \u002F>\n* Toggle control for easy enable\u002Fdisable\u003Cbr \u002F>\n* Clean, responsive form styling\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Shortcode Usage\u003C\u002Fstrong>\u003Cbr \u002F>\nUse \u003Ccode>[keyless-auth]\u003C\u002Fcode> anywhere: pages, posts, widgets, or custom templates.\u003C\u002Fp>\n\u003Ch4>Developer Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Hooks & Filters\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Customize login redirect:\u003Cbr \u002F>\n    add_filter(‘wpa_after_login_redirect’, ‘custom_redirect_function’);\u003C\u002Fp>\n\u003Cp>Modify email headers:\u003Cbr \u002F>\n    add_filter(‘wpa_email_headers’, ‘custom_email_headers’);\u003C\u002Fp>\n\u003Cp>Change token expiration:\u003Cbr \u002F>\n    add_filter(‘wpa_change_link_expiration’, ‘custom_expiration_time’);\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Modular Architecture\u003C\u002Fstrong>\u003Cbr \u002F>\n* Clean, organized class structure\u003Cbr \u002F>\n* Separated concerns for easy maintenance\u003Cbr \u002F>\n* WordPress coding standards compliance\u003Cbr \u002F>\n* Extensive documentation and comments\u003C\u002Fp>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>WordPress\u003C\u002Fstrong>: 3.9 or higher (tested up to 6.8)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP\u003C\u002Fstrong>: 7.4 or higher\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Delivery\u003C\u002Fstrong>: SMTP recommended for reliability\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Note\u003C\u002Fstrong>: Keyless Auth complements WordPress’s default login system – it doesn’t replace it.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Developed by Chris Martens | Based on the original Passwordless Login plugin by Cozmoslabs\u003C\u002Fstrong>\u003C\u002Fp>\n","Secure, passwordless authentication for WordPress. Your users login via magic email links – no passwords to remember or forget.",40,1488,"2025-11-24T22:55:00.000Z","6.8.6","3.9",[129,20,22,130,131],"2fa","secure-login","smtp","https:\u002F\u002Fgithub.com\u002Fchrmrtns\u002Fkeyless-auth","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fkeyless-auth.3.2.4.zip",{"error":135,"url":136,"statusCode":137,"statusMessage":138,"message":138},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fqrauth-passwordless-social-login\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":68,"versions":140},[141,147],{"version":6,"download_url":26,"svn_tag_url":142,"released_at":28,"has_diff":143,"diff_files_changed":144,"diff_lines":28,"trac_diff_url":145,"vulnerabilities":146,"is_current":135},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fqrauth-passwordless-social-login\u002Ftags\u002F0.1.23\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fqrauth-passwordless-social-login%2Ftags%2F0.1.21&new_path=%2Fqrauth-passwordless-social-login%2Ftags%2F0.1.23",[],{"version":148,"download_url":149,"svn_tag_url":150,"released_at":28,"has_diff":143,"diff_files_changed":151,"diff_lines":28,"trac_diff_url":28,"vulnerabilities":152,"is_current":143},"0.1.21","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fqrauth-passwordless-social-login.0.1.21.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fqrauth-passwordless-social-login\u002Ftags\u002F0.1.21\u002F",[],[]]