[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOUXwdG2D7jCAACXFRCI-07ndmOHwCES9ChH1zRXVZEw":3,"$fNzkBwBVIad2vf9GCexm-nP1-N6gYbI4ZIojrVKLTpL8":128,"$fg70d_KpIaZSfwjSxf7kXGUJQML9M6TpY9Uu1G1htnes":133},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":26,"fingerprints":26},"tanur-social-login","Tanur Social Login","1.0.9","tunaman7787","https:\u002F\u002Fprofiles.wordpress.org\u002Ftunaman7787\u002F","\u003Cp>Tanur Social Login is a lightweight WordPress social login plugin that allows users to sign in or register using Google, Facebook, and LinkedIn. The plugin integrates seamlessly with WordPress and WooCommerce, supporting login, registration, My Account, and checkout pages.\u003C\u002Fp>\n\u003Cp>Designed for performance and simplicity, Tanur Social Login helps reduce registration friction, improve user experience, and increase conversions by enabling one-click social authentication without relying on third-party SaaS services.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Google, Facebook, and LinkedIn OAuth login.\u003C\u002Fli>\n\u003Cli>WooCommerce My Account, checkout, login, and registration integration.\u003C\u002Fli>\n\u003Cli>Default WordPress login page integration.\u003C\u002Fli>\n\u003Cli>Existing users are linked by verified provider ID or email address.\u003C\u002Fli>\n\u003Cli>New users are created with a generated secure password.\u003C\u002Fli>\n\u003Cli>One-time OAuth state tokens using WordPress transients.\u003C\u002Fli>\n\u003Cli>Same-site redirect validation with WordPress redirect helpers.\u003C\u002Fli>\n\u003Cli>Setup guide inside the WordPress admin.\u003C\u002Fli>\n\u003Cli>Copy-ready redirect URI fields for each provider.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>User account creation and login\u003C\u002Fh4>\n\u003Cp>This plugin creates and logs in WordPress users because that is the primary function of a social login plugin. A visitor who successfully completes OAuth with an enabled provider can be matched to an existing WordPress user or created as a new WordPress user.\u003C\u002Fp>\n\u003Cp>Existing accounts are linked by provider ID first. Email-based linking is only used when the provider email is trusted. Google and LinkedIn email verification signals are checked when available, and Facebook email is treated as trusted because Facebook Login returns account email through the email permission. The plugin does not create administrator users; new users receive the WooCommerce customer role when WooCommerce is active, otherwise the site’s configured default WordPress role is used.\u003C\u002Fp>\n\u003Ch4>Built by Tanur Graphics\u003C\u002Fh4>\n\u003Cp>Tanur Social Login is built by Tanur Graphics, a WordPress, WooCommerce, SEO, automation, and design team.\u003C\u002Fp>\n\u003Cp>Website: https:\u002F\u002Ftanur.graphics\u003C\u002Fp>\n\u003Cp>If you need help with OAuth setup, WooCommerce customization, SEO systems, or custom WordPress development, visit Tanur Graphics for support and services.\u003C\u002Fp>\n\u003Ch3>Setup Tutorial\u003C\u002Fh3>\n\u003Ch4>Google\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Open Google Cloud Console > APIs & Services > Credentials.\u003C\u002Fli>\n\u003Cli>Create an OAuth Client ID.\u003C\u002Fli>\n\u003Cli>Choose Web application.\u003C\u002Fli>\n\u003Cli>Add the Authorized Redirect URI shown by this plugin.\u003C\u002Fli>\n\u003Cli>Configure the OAuth consent screen.\u003C\u002Fli>\n\u003Cli>Copy the Client ID and Client Secret into the plugin settings.\u003C\u002Fli>\n\u003Cli>Enable Google in the plugin settings and save.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Facebook\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Open Facebook Developers and create or select an app.\u003C\u002Fli>\n\u003Cli>Add the Facebook Login product.\u003C\u002Fli>\n\u003Cli>In Facebook Login settings, add the Valid OAuth Redirect URI shown by this plugin.\u003C\u002Fli>\n\u003Cli>Copy the App ID and App Secret into the plugin settings.\u003C\u002Fli>\n\u003Cli>Make sure the app is in Live mode before public users log in.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>LinkedIn\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Open LinkedIn Developers and create or select an app.\u003C\u002Fli>\n\u003Cli>Request the Sign In with LinkedIn using OpenID Connect product.\u003C\u002Fli>\n\u003Cli>Add the OAuth redirect URI shown by this plugin.\u003C\u002Fli>\n\u003Cli>Copy the Client ID and Client Secret into the plugin settings.\u003C\u002Fli>\n\u003Cli>Enable LinkedIn in the plugin settings and save.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Security Tips\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Use HTTPS on every site that enables social login.\u003C\u002Fli>\n\u003Cli>Keep WordPress, WooCommerce, and all plugins updated.\u003C\u002Fli>\n\u003Cli>Restrict access to OAuth client secrets.\u003C\u002Fli>\n\u003Cli>Do not paste client secrets into screenshots or public support threads.\u003C\u002Fli>\n\u003Cli>Regenerate provider client secrets if they are exposed.\u003C\u002Fli>\n\u003Cli>Test social login after changing domains, SSL, permalinks, or caching settings.\u003C\u002Fli>\n\u003Cli>Use a separate OAuth app for staging and production sites.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects directly from the WordPress site to OAuth providers selected and configured by the site administrator. These services are required only when the related provider is enabled in the plugin settings.\u003C\u002Fp>\n\u003Ch4>Google\u003C\u002Fh4>\n\u003Cp>This plugin uses Google OAuth and Google userinfo endpoints to let users sign in with Google.\u003C\u002Fp>\n\u003Cp>Data sent: when a visitor clicks “Sign in with Google”, the visitor is sent to Google for OAuth authorization. During the callback, the site sends the OAuth authorization code, the configured Client ID, Client Secret, and redirect URI to Google’s token endpoint. The site then sends the returned access token to Google’s userinfo endpoint to request the user’s Google account ID, email address, email verification status, name, first name, last name, and profile image URL when available. This data is used only to create or link a WordPress user account and log the user in.\u003C\u002Fp>\n\u003Cp>Service provider: Google LLC.\u003Cbr \u002F>\nTerms: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fp>\n\u003Ch4>Facebook \u002F Meta\u003C\u002Fh4>\n\u003Cp>This plugin uses Facebook Login and Meta Graph API endpoints to let users sign in with Facebook.\u003C\u002Fp>\n\u003Cp>Data sent: when a visitor clicks “Sign in with Facebook”, the visitor is sent to Facebook for OAuth authorization. During the callback, the site sends the OAuth authorization code, the configured App ID, App Secret, and redirect URI to Meta’s token endpoint. The site then sends the returned access token to the Meta Graph API \u002Fme endpoint to request the user’s Facebook ID, name, email address, first name, last name, and profile picture URL when available. This data is used only to create or link a WordPress user account and log the user in.\u003C\u002Fp>\n\u003Cp>Service provider: Meta Platforms, Inc.\u003Cbr \u002F>\nTerms: https:\u002F\u002Fwww.facebook.com\u002Flegal\u002Fterms\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwww.facebook.com\u002Fprivacy\u002Fpolicy\u002F\u003C\u002Fp>\n\u003Ch4>LinkedIn\u003C\u002Fh4>\n\u003Cp>This plugin uses LinkedIn OAuth and LinkedIn OpenID Connect userinfo endpoints to let users sign in with LinkedIn.\u003C\u002Fp>\n\u003Cp>Data sent: when a visitor clicks “Sign in with LinkedIn”, the visitor is sent to LinkedIn for OAuth authorization. During the callback, the site sends the OAuth authorization code, the configured Client ID, Client Secret, and redirect URI to LinkedIn’s token endpoint. The site then sends the returned access token to LinkedIn’s userinfo endpoint to request the user’s LinkedIn subject ID, email address, email verification status when available, name, first name, last name, and profile image URL when available. This data is used only to create or link a WordPress user account and log the user in.\u003C\u002Fp>\n\u003Cp>Service provider: LinkedIn Corporation.\u003Cbr \u002F>\nTerms: https:\u002F\u002Fwww.linkedin.com\u002Flegal\u002Fuser-agreement\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwww.linkedin.com\u002Flegal\u002Fprivacy-policy\u003C\u002Fp>\n","Social login plugin for WordPress and WooCommerce with Google, Facebook, and LinkedIn authentication.",0,127,"2026-06-06T20:43:00.000Z","7.0.2","6.0","7.4",[18,19,20,21,22],"facebook-login","google-login","linkedin-login","social-login","woocommerce","https:\u002F\u002Ftanur.graphics\u002Ftanur-social-login\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftanur-social-login.1.0.9.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},1,30,94,"2026-08-28T19:51:19.319Z",[36,55,73,94,113],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":46,"num_ratings":47,"last_updated":48,"tested_up_to":14,"requires_at_least":49,"requires_php":50,"tags":51,"homepage":53,"download_link":54,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"userswp-social-login","UsersWP – Social Login","1.5.7","Stiofan","https:\u002F\u002Fprofiles.wordpress.org\u002Fstiofansisland\u002F","\u003Cp>Social Login addon for \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fuserswp\u002F\" rel=\"ugc\">UsersWP\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>This addon lets your user to register and login with popular sites like Facebook, Google, Twitter, LinkedIn, Yahoo, WordPress etc.\u003C\u002Fp>\n\u003Cp>100% translatable.\u003C\u002Fp>\n","Social Login addon for UsersWP.",2000,134628,66,4,"2026-04-14T13:40:00.000Z","6.1","",[18,19,20,21,52],"twitter-login","https:\u002F\u002Fuserswp.io\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fuserswp-social-login.1.5.7.zip",{"slug":56,"name":57,"version":58,"author":59,"author_profile":60,"description":61,"short_description":62,"active_installs":63,"downloaded":64,"rating":65,"num_ratings":66,"last_updated":67,"tested_up_to":68,"requires_at_least":15,"requires_php":16,"tags":69,"homepage":50,"download_link":71,"security_score":72,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"happy-social-login","Happy Social Login","1.5.0","WPFOLK","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpfolk\u002F","\u003Cp>Let your users signup and login to your WordPress website using their favorite social media accounts Facebook, Google, LinkedIn, Github and 42+ more. Happy Social Login is a free, easy-to-use WordPress plugin that makes registration and login a breeze. With just its social profiles (like Facebook, Google, or X (formerly Twitter)), your visitors can quickly sign up and log in to your site. No lengthy forms, no waiting for validation emails, and no more forgotten passwords. It’s simple, fast, and user-friendly!\u003C\u002Fp>\n\u003Ch3>🔗 Useful Links\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpfolk.com\u002Fplugins\u002Fhappy-social-login\" rel=\"nofollow ugc\">Official Page\u003C\u002Fa> || \u003Ca href=\"https:\u002F\u002Fplayground.wordpress.net\u002F?plugin=happy-social-login\" rel=\"nofollow ugc\">Demo\u003C\u002Fa> || \u003Ca href=\"https:\u002F\u002Fwpfolk.com\u002Fdocs\u002Fhappy-social-login\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Key Features:\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Quick registration and login via Facebook, Google, LinkedIn, and Github\u003C\u002Fli>\n\u003Cli>Easy integration with WordPress user accounts\u003C\u002Fli>\n\u003Cli>Customizable redirect URLs after registration and login\u003C\u002Fli>\n\u003Cli>Display social profile pictures as avatars\u003C\u002Fli>\n\u003Cli>Simple setup and user-friendly interface\u003C\u002Fli>\n\u003Cli>Helpful support for any questions or issues\u003C\u002Fli>\n\u003Cli>Additional Features in the Pro Version:\u003C\u002Fli>\n\u003Cli>Compatibility with WooCommerce, BuddyPress, UserPro, and more\u003C\u002Fli>\n\u003Cli>Access to additional providers like Amazon, PayPal, and more\u003C\u002Fli>\n\u003Cli>Control over email and username collection during registration\u003C\u002Fli>\n\u003Cli>Different login layouts and button styles\u003C\u002Fli>\n\u003Cli>Role-based access control for social logins\u003C\u002Fli>\n\u003Cli>Automatic assignment of user roles based on social login provider\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Disclaimer\u003C\u002Fh3>\n\u003Cp>Happy Social Login is an independent plugin and is not affiliated with or endorsed by\u003Cbr \u002F>\nany of the third-party services mentioned in this documentation, including but not limited\u003Cbr \u002F>\nto Facebook, Google, Twitter, LinkedIn, GitHub, and others. All trademarks, service marks,\u003Cbr \u002F>\nand company names are the property of their respective owners. We do not hold any copyright\u003Cbr \u002F>\nover the APIs or services provided by these third parties. Any use of these services is subject\u003Cbr \u002F>\nto their respective terms of use and privacy policies. Users are responsible for complying with\u003Cbr \u002F>\nthe terms of the third-party services they choose to enable through this plugin.\u003C\u002Fp>\n\u003Cp>Happy Social Login relies on third-party services for authentication. When a user logs in using a\u003Cbr \u002F>\nsocial media account, their data is sent to the respective third-party service for authentication.\u003Cbr \u002F>\nBelow is a list of the services used, along with their respective links to privacy policies:\u003C\u002Fp>\n\u003Ch3>🔗 Privacy Policy Links\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Ftwitter.com\u002Fen\u002Fprivacy\" rel=\"nofollow ugc\">X\u003C\u002Fa> || \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Google\u003C\u002Fa> || \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fpolicy.php\" rel=\"nofollow ugc\">Facebook\u003C\u002Fa>\u003C\u002Fp>\n","Enables user authentication through various social media accounts. Login through Google, Facebook, LinkedIn, GitHub and more.",90,10389,80,5,"2025-01-09T10:48:00.000Z","6.7.5",[18,70,19,20,21],"github-login","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhappy-social-login.1.5.0.zip",92,{"slug":74,"name":75,"version":76,"author":77,"author_profile":78,"description":79,"short_description":80,"active_installs":81,"downloaded":82,"rating":83,"num_ratings":84,"last_updated":85,"tested_up_to":68,"requires_at_least":86,"requires_php":87,"tags":88,"homepage":90,"download_link":91,"security_score":92,"vuln_count":31,"unpatched_count":11,"last_vuln_date":93,"fetched_at":27},"oa-social-login","Social Login","5.10.0","Claude","https:\u002F\u002Fprofiles.wordpress.org\u002Fclaudeschlesser\u002F","\u003Ch4>Social Login Plugin\u003C\u002Fh4>\n\u003Cp>Social Login is a \u003Cstrong>professionally developed\u003C\u002Fstrong> and free WordPress plugin that allows your visitors to \u003Cstrong>comment, login and register with 40+ Social Networks\u003C\u002Fstrong> like for example Facebook, Twitter \u002F X, TikTok, Google, LinkedIn, PayPal, LiveJournal, Instagram, Вконтакте or Yahoo amongst other.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Protection Guarantee\u003C\u002Fstrong>\u003Cbr \u002F>\nSocial Login is fully compliant with all European and U.S. data protection laws. As required by the General Data Protection Regulation (GDPR) the OneAll Terms of Service include a Data Processing Agreement that we can countersign on request.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Seamless Integration\u003C\u002Fstrong>\u003Cbr \u002F>\nSocial Login is fully customizable and seamlessly integrates with your existing login\u002Fregistration system so that your users don’t have to start from scratch. Existing existing accounts can add\u002Fremove their social network accounts in their WordPress profile settings and then also use the linked social networks to login.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Eliminates Spam and Bot Registrations\u003C\u002Fstrong>\u003Cbr \u002F>\nGet rid of long and complicated forms, improve your data quality and instantly eliminate spam and bot registrations. Social Login increases registration rates by up to 50% and provides permission-based access to users’ social network profile data, allowing you to start delivering a personalized experience.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Maintenance Free\u003C\u002Fstrong>\u003Cbr \u002F>\nDo not take the risk of losing any users or customers due to outdated social network integrations. Unlike other Social Login providers we monitor the APIs and technologies of the different social networks and update our service as soon as changes arise.\u003C\u002Fp>\n\u003Cp>By using OneAll you can be sure that your social media integration will always run smoothly and with the most up-to-date calls.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Fully Customizable\u003C\u002Fstrong>\u003Cbr \u002F>\nYou can easily configure which social accounts to enable\u002Fdisable for social login and on which areas of the website the social login icons should be displayed:\u003Cbr \u002F>\n* On the comment formular\u003Cbr \u002F>\n* On the login page\u003Cbr \u002F>\n* On the registration page\u003Cbr \u002F>\n* In your sidebar\u003Cbr \u002F>\n* With a shortcode\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Fully Compatible With Other Plugins\u003C\u002Fstrong>\u003Cbr \u002F>\nSocial Login uses standard WordPress hooks and is compatible with all plugins that follow WordPress coding conventions,\u003Cbr \u002F>\nlike per example BuddyPress or WooCommerce amongst others.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Export\u003C\u002Fstrong>\u003Cbr \u002F>\nEasily export your users or automatically push data of users that login using Social Login to Mailchimp or Campaign Monitor.\u003Cbr \u002F>\nThis feature is available in the premium version of Social Login and can be enabled in your OneAll account.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>45+ Social Networks\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Apple\u003C\u002Fli>\n\u003Cli>Amazon\u003C\u002Fli>\n\u003Cli>Battle.net\u003C\u002Fli>\n\u003Cli>Blogger\u003C\u002Fli>\n\u003Cli>Discord\u003C\u002Fli>\n\u003Cli>Draugiem\u003C\u002Fli>\n\u003Cli>Dribbble\u003C\u002Fli>\n\u003Cli>Epic Games\u003C\u002Fli>\n\u003Cli>Facebook\u003C\u002Fli>\n\u003Cli>Foursquare\u003C\u002Fli>\n\u003Cli>Github.com\u003C\u002Fli>\n\u003Cli>Google\u003C\u002Fli>\n\u003Cli>Instagram\u003C\u002Fli>\n\u003Cli>Line\u003C\u002Fli>\n\u003Cli>LinkedIn\u003C\u002Fli>\n\u003Cli>LiveJournal\u003C\u002Fli>\n\u003Cli>Mail.ru\u003C\u002Fli>\n\u003Cli>Meetup\u003C\u002Fli>\n\u003Cli>Mixer\u003C\u002Fli>\n\u003Cli>Odnoklassniki\u003C\u002Fli>\n\u003Cli>OpenID\u003C\u002Fli>\n\u003Cli>Patreon\u003C\u002Fli>\n\u003Cli>PayPal\u003C\u002Fli>\n\u003Cli>Pinterest\u003C\u002Fli>\n\u003Cli>PixelPin \u003C\u002Fli>\n\u003Cli>Reddit\u003C\u002Fli>\n\u003Cli>Skyrock.com\u003C\u002Fli>\n\u003Cli>SoundCloud        \u003C\u002Fli>\n\u003Cli>Spotify\u003C\u002Fli>\n\u003Cli>StackExchange\u003C\u002Fli>\n\u003Cli>Steam\u003C\u002Fli>\n\u003Cli>Strava\u003C\u002Fli>\n\u003Cli>TikTok\u003C\u002Fli>\n\u003Cli>Tumblr\u003C\u002Fli>\n\u003Cli>Twitch.tv\u003C\u002Fli>\n\u003Cli>Twitter \u002F X\u003C\u002Fli>\n\u003Cli>Vimeo\u003C\u002Fli>\n\u003Cli>VKontakte\u003C\u002Fli>\n\u003Cli>Weibo\u003C\u002Fli>\n\u003Cli>Windows Live\u003C\u002Fli>\n\u003Cli>WordPress.com\u003C\u002Fli>\n\u003Cli>XING\u003C\u002Fli>\n\u003Cli>Yahoo\u003C\u002Fli>\n\u003Cli>Yandex\u003C\u002Fli>\n\u003Cli>YouTube\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Social Login Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>GDPR compliant\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Social Link\u003C\u002Fstrong> – Users can use social login to link multiple social network accounts to their WordPress account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Woocommerce Connect\u003C\u002Fstrong> – Automatic integration of the social login icons on the Woocommerce checkout, login and registration pages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Woocommerce Profile\u003C\u002Fstrong> – Fill the user’s billing address with the first name, last name and email address received from the social network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>BuddyPress Connect\u003C\u002Fstrong> – Automatic integration of the social login icons on the BuddyPress account and registration pages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>BuddyPress Profile\u003C\u002Fstrong> – Use the social network avatar as BuddyPress avatar and fill out custom fields.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Insights\u003C\u002Fstrong> – Access the analytics dashboard to discover which social networks your users prefer.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic Emails\u003C\u002Fstrong> – Send emails to users that register using social login.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic Notifications\u003C\u002Fstrong> – Send notifications to admins for every users that registers using social login.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comment Approval\u003C\u002Fstrong> – Automatically approve comments left by users that connected by using social login.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Retrieval\u003C\u002Fstrong>  – Ask users to enter their email when social login did not receive it from the social network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Redirections\u003C\u002Fstrong> – Fully customize the page to redirect user to after having connected using social login.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Integrated Widget\u003C\u002Fstrong> – Simply use the social login widget to display the icons wherever you want.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ShortCodes\u003C\u002Fstrong> – Easily embed social login anywhere by using the available shortcodes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hook\u003C\u002Fstrong> – Customize the social login behaviour by using the integrated hooks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Icon Themes\u003C\u002Fstrong> – Choose amongst three different social login icon themes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Documentation\u003C\u002Fstrong> – Access a \u003Ca href=\"https:\u002F\u002Fdocs.oneall.com\u002Fplugins\u002Fguide\u002Fsocial-login-wordpress\u002F\" rel=\"nofollow ugc\">complete documentation\u003C\u002Fa> on the available Social Login hooks and filters for WordPress.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Support\u003C\u002Fstrong> – Any questions about Social Login? Our support team is there to assist you. \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Social Login Premium Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Authentication Filters\u003C\u002Fstrong> – Use customisable filters to restrict which users may login with social login.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Export\u003C\u002Fstrong> – Automatically export social login data to Campaign Monitor or MailChimp or export as CSV.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Insights\u003C\u002Fstrong> – Access analytics and get demographic information about your social login users.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Icon Themes\u003C\u002Fstrong> – Choose amongst twenty different social login icon themes or use you own icons.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Professionally Developed and Maintained\u003C\u002Fstrong>\u003Cbr \u002F>\nSocial Login is maintained by \u003Ca href=\"https:\u002F\u002Fwww.oneall.com\" rel=\"nofollow ugc\">OneAll\u003C\u002Fa>, a technology company offering a set of web-delivered tools to simplify the integration of 40+ social networks into business and personal websites and apps.\u003C\u002Fp>\n\u003Cp>The OneAll API unifies 40+ Social Networks and consolidates the most powerful social network features in a single solution. You can work with multiple social networks at once and you will obtain a standardized field structure for data received from any of the social networks. Save time and development resources and focus on your core business.\u003C\u002Fp>\n\u003Ch3>Testimonials\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Used by thousands of users around the world!\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>The plugin in is one of the best I’ve seen so far. Extremely easy to implement and run. The support is great too.\u003Cbr \u002F>\nNo concerns on my side. Keep it up!\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>livia\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>Loving the service, seen a massive increase in painless signups to my blog. Thanks!\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Richard B.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>You have no idea how it THRILLED me to integrate oneall. It was SO amazingly easy, your team has simplified the whole process of signing up for\u003Cbr \u002F>\nauthorization on multiple social media sites. I HAD NO QUESTIONS\u002FSTEPS THAT YOU HADN’T ALREADY ANTICIPATED. It saved me HOURS of work!\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Kelly C.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>This is cool. Nice work. I’m VERY impressed. You’ve made this about as painless as it gets and the value it adds is incredible.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Jason M.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>This service is simply remarkable, I’ve tried integrating logins before and it has never been this easy!\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Andrew C.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>I found it extremely straightforward. I just figured it out easily and make my website capable of connecting\u003Cbr \u002F>\nto many social networks by your plugin.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Deha K.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>Just wanted to let you know how happy i am that i stumbled onto your service. This was the 6 Facebook\u002FTwitter integration\u003Cbr \u002F>\ni tried and was starting to lose hope that i could actually find one that worked for me.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Kyle L.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>I would like to thank YOU! Seriously, the WordPress plugin has been a huge life saver for me.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Piero B.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>Thank you for the wonderful plugin\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Martin P.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>The service is excellent for what i need, simple to set up. All situations about seting up are well explained, so\u003Cbr \u002F>\nthere are no difficulties\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Facundo S.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>I really like the plugin, the capabilities you provide for management and your prompt reply for support.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Tom B.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>It was extremely easy to set up and use.  The documentation to set up the FB and twitter API\u003Cbr \u002F>\nwas easy to follow and implement. I was struggling with a couple of other plugins till I stumbled on this one.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Deepa V.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>Works like a charm!\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Fredrik L.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>Not sure how you can improve it’s a Damn! Good product. 100% User friendly easy to setup. Thanks!\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Cody L.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>So far oneall.com is the perfect solution for my site and works flawlessly.  I am extremely impressed and grateful.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Terry P.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>I’ve gone in and tweaked it, tested it and it’s good to go now! Wonderful, I feel like a grown up blogger now.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Brian J.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>I am really impressed with your product! Its very dynamic and its gives me the flexibility I need for integration into my own business.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Braxton D.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>Your delivery is superb. You should change your name to WONall because you won it all with me. You are awesome, stay that way please.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Nicholas L.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>I especially enjoy the step by step process that guides you through the Social website App creation process. In the end I would like to thank you\u003Cbr \u002F>\nfor putting together such a great product that so many users can implement with ease.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Stefan C.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>Thanks for a such a great plugin! I was really impressed with the simplicity of the installation directions and the clean design.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Janae S.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>I love your service the way it is, it’s amazing how easy the logging-in-via-social-network is integrated into a wordpress website!\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Martin S.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>The site and the plugin are working magnificently. Thank you one million times for making your products\u002Fservices available in the manner that you have.\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Herman G.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>Very user friendly, there are guides and screenshot on how to set things up. Thank you so much for this awesome plugin!\u003C\u002Fem>\u003Cbr \u002F>\n\u003Cstrong>Cebututs\u003C\u002Fstrong>\u003C\u002Fp>\n","With Social Login your users can login, register and comment with 40+ Social Networks. Maintenance Free. Uptime Guarantee. Fulltime devs",5000,944216,86,365,"2024-12-02T15:57:00.000Z","3.0","5.4",[18,20,21,89,52],"tiktok-login","http:\u002F\u002Fwww.oneall.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Foa-social-login.zip",89,"2024-11-22 15:08:42",{"slug":95,"name":96,"version":97,"author":98,"author_profile":99,"description":100,"short_description":101,"active_installs":65,"downloaded":102,"rating":11,"num_ratings":11,"last_updated":103,"tested_up_to":104,"requires_at_least":105,"requires_php":106,"tags":107,"homepage":111,"download_link":112,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"wapu-auth-social-login","Wapu Auth – Inicio de sesión social para WordPress y WooCommerce","2.0.0","Victor Flores","https:\u002F\u002Fprofiles.wordpress.org\u002Fvictor88lm\u002F","\u003Cp>\u003Cstrong>Wapu Auth\u003C\u002Fstrong> adds Google and Facebook social login to WordPress and WooCommerce. Provider OAuth processing is handled by the fixed \u003Cstrong>Wapu Auth Broker\u003C\u002Fstrong> at \u003Ccode>https:\u002F\u002Fauth.wapuos.com\u003C\u002Fcode>; provider client secrets and provider tokens never enter WordPress.\u003C\u002Fp>\n\u003Cp>On activation or update, Wapu Auth queues an asynchronous, one-shot background connection. An eligible public HTTPS site is registered, verified and checked without requiring a normal registration button click. The worker uses an expiring lock, reuses a pending broker challenge, retries temporary failures with bounded backoff and never rotates or re-registers a verified current-origin credential. Local, private, non-HTTPS and cloned origins fail closed. A protected manual retry remains available when the host, firewall or cron system needs attention.\u003C\u002Fp>\n\u003Cp>After the connection is verified, the plugin checks local HMAC signing, broker provider availability, schema integrity, identity preflight and safe backfill before enabling new broker login starts. Existing WordPress users, roles, WooCommerce customers, orders and downloads are not recreated or deleted by this workflow.\u003C\u002Fp>\n\u003Ch4>Main Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Google and Facebook login through full-page broker redirects and a closed provider registry.\u003C\u002Fli>\n\u003Cli>Automatic background site registration and proof-of-control verification for eligible public HTTPS sites.\u003C\u002Fli>\n\u003Cli>Encrypted, non-autoloaded per-site broker credentials with exact-origin binding.\u003C\u002Fli>\n\u003Cli>HMAC-signed server requests with timestamps, fresh nonces and fixed broker paths.\u003C\u002Fli>\n\u003Cli>Independent, expiring local transactions for concurrent login attempts.\u003C\u002Fli>\n\u003Cli>Canonical provider identities with conflict-aware account linking and safe unlinking.\u003C\u002Fli>\n\u003Cli>Adaptive provider controls: one enabled provider uses a full button; multiple providers use accessible circular buttons.\u003C\u002Fli>\n\u003Cli>Shortcodes \u003Ccode>[wapu_auth_button]\u003C\u002Fcode> and \u003Ccode>[wapu_auth_login_button]\u003C\u002Fcode>, plus the \u003Ccode>wapu-auth\u002Flogin-button\u003C\u002Fcode> block.\u003C\u002Fli>\n\u003Cli>Custom login and registration forms through \u003Ccode>[wapu_auth_login_form]\u003C\u002Fcode> and \u003Ccode>[wapu_auth_register_form]\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>WooCommerce login, registration, checkout return, profile autofill and My Account integration.\u003C\u002Fli>\n\u003Cli>Active WordPress session management, including individual revocation and closing other sessions.\u003C\u002Fli>\n\u003Cli>Safe return URLs, domain rules and a local sandbox allowlist.\u003C\u002Fli>\n\u003Cli>Local multiprovider analytics for Google, Facebook and traditional WordPress access, with provider filters and sanitized exports.\u003C\u002Fli>\n\u003Cli>Optional detailed Activity Log, GeoIP enrichment and GA4 event bridge.\u003C\u002Fli>\n\u003Cli>Identity migration diagnostics, bounded safe backfill and non-destructive broker pause\u002Fresume controls.\u003C\u002Fli>\n\u003Cli>Site-scoped support conversations through the broker’s audited HMAC API.\u003C\u002Fli>\n\u003Cli>Optional private image attachments in Support, capability-gated by the broker and proxied without exposing site credentials.\u003C\u002Fli>\n\u003Cli>Native WordPress login remains available when allowed by the site’s configuration.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How Broker Login Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>A visitor selects Google or Facebook.\u003C\u002Fli>\n\u003Cli>WordPress validates the return URL and creates an expiring, provider-bound local transaction.\u003C\u002Fli>\n\u003Cli>WordPress sends a signed request to \u003Ccode>\u002Fapi\u002Fv1\u002Fgoogle\u002Fsessions\u003C\u002Fcode> or \u003Ccode>\u002Fapi\u002Fv1\u002Ffacebook\u002Fsessions\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>The broker returns an allowlisted provider start URL and completes provider OAuth.\u003C\u002Fli>\n\u003Cli>The broker returns a one-use \u003Ccode>wxc_*\u003C\u002Fcode> code to \u003Ccode>\u002Fwapu-auth\u002Foauth\u002Fcallback\u003C\u002Fcode> on the WordPress site.\u003C\u002Fli>\n\u003Cli>WordPress consumes the local transaction and exchanges the code at \u003Ccode>\u002Fapi\u002Fv1\u002Foauth\u002Fexchange\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>The plugin requires the returned provider and subject to match the local transaction before resolving, linking or creating the WordPress user.\u003C\u002Fli>\n\u003Cli>WordPress issues its normal authentication cookies and applies the validated local return URL.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Compatibility and Removed Features\u003C\u002Fh4>\n\u003Cp>The deprecated \u003Ccode>[wapu_auth_popup]\u003C\u002Fcode> and \u003Ccode>[wapu_auth_popup_button]\u003C\u002Fcode> aliases still render the normal redirect control for one compatibility cycle. They do not open a popup.\u003C\u002Fp>\n\u003Cp>Version 2.0 removes Google One Tap, local modal authentication, emailed login links, email OTP, trusted-device bypasses and integrated SMTP configuration. Active Sessions, normal WordPress notifications through \u003Ccode>wp_mail()\u003C\u002Fcode>, the primary shortcodes, block, forms and WooCommerce flows remain available.\u003C\u002Fp>\n\u003Cp>WordPress Multisite is not supported. Activation is stopped before identity migrations on a network installation.\u003C\u002Fp>\n\u003Ch3>Hooks & Filters\u003C\u002Fh3>\n\u003Ch4>Actions\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>wapu_auth_before_login\u003C\u002Fcode> — before a broker authorization session is created.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_user_authenticated\u003C\u002Fcode> — after successful user resolution.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_user_created\u003C\u002Fcode> — after a WordPress user is created.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_provider_account_unlinked\u003C\u002Fcode> — after one provider mapping is removed.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_google_account_unlinked\u003C\u002Fcode> — compatibility action after a Google mapping is removed.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_analytics_event\u003C\u002Fcode> — after a local analytics event is recorded.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_log\u003C\u002Fcode> — after the plugin logger records an entry.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wp_login\u003C\u002Fcode> — standard WordPress action, fired exactly once for a successful broker login.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Filters\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>wapu_auth_user_data\u003C\u002Fcode> — presentation fields only; provider identity fields remain immutable.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_redirect_url\u003C\u002Fcode> — final redirect, subject to same-origin validation.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_error_message\u003C\u002Fcode> — local user-facing error copy.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_button_html\u003C\u002Fcode> — rendered provider control HTML.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wapu_auth_geoip_enabled\u003C\u002Fcode> — optional GeoIP enrichment.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The legacy \u003Ccode>wapu_auth_auth_params\u003C\u002Fcode>, \u003Ccode>wapu_auth_redirect_uri\u003C\u002Fcode> and \u003Ccode>wapu_auth_oauth_base_url\u003C\u002Fcode> filters are compatibility notifications. They cannot change the broker host, callback, provider, state, nonce, signature, ticket or one-use code.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Ch4>1. Wapu Auth Broker (required for social login)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Fixed origin:\u003C\u002Fstrong> \u003Ccode>https:\u002F\u002Fauth.wapuos.com\u003C\u002Fcode>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When used:\u003C\u002Fstrong> after activation or update for background registration\u002Fverification and provider health; when a visitor starts or completes social login; when an administrator deliberately rotates a credential or uses the Support section.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Endpoints used:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>POST \u002Fapi\u002Fv1\u002Fsites\u002Fregister\u002Finit\u003C\u002Fcode> and \u003Ccode>POST \u002Fapi\u002Fv1\u002Fsites\u002Fregister\u002Fverify\u003C\u002Fcode> for proof-of-control registration.\u003C\u002Fli>\n\u003Cli>\u003Ccode>GET \u002Fhealth\u003C\u002Fcode> for a public, secret-free provider availability snapshot.\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fapi\u002Fv1\u002Fgoogle\u002Fsessions\u003C\u002Fcode> or \u003Ccode>POST \u002Fapi\u002Fv1\u002Ffacebook\u002Fsessions\u003C\u002Fcode> to begin login.\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fapi\u002Fv1\u002Foauth\u002Fexchange\u003C\u002Fcode> to exchange the callback’s one-use code.\u003C\u002Fli>\n\u003Cli>Browser paths under \u003Ccode>\u002Foauth\u002Fgoogle\u002F*\u003C\u002Fcode> or \u003Ccode>\u002Foauth\u002Ffacebook\u002F*\u003C\u002Fcode> during provider authorization.\u003C\u002Fli>\n\u003Cli>Site-scoped \u003Ccode>\u002Fapi\u002Fv1\u002Fsupport\u002F*\u003C\u002Fcode> operations only when an administrator uses Support.\u003C\u002Fli>\n\u003Cli>Signed binary support-image upload plus private thumbnail\u002Fcontent delivery only when the broker capability flag is enabled.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Registration data:\u003C\u002Fstrong> canonical site URL, fixed local callback URL, short-lived verification URL and registration identifier. The broker performs a public GET of the verification URL, which returns only the active short-lived challenge.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login data:\u003C\u002Fstrong> site ID, HMAC timestamp\u002Fnonce\u002Fsignature headers, provider-bound local state, validated return context and the one-use exchange code. Sensitive protocol values are not written to plugin logs.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Identity data received:\u003C\u002Fstrong> provider, provider subject, email and verification state, and optional name\u002Favatar fields. Provider tokens, refresh tokens, provider authorization codes and provider client secrets are not returned to WordPress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Support data:\u003C\u002Fstrong> the subject, allowlisted category, public messages and optional JPEG\u002FPNG\u002FWebP evidence deliberately entered by an administrator. Images are normalized to remove EXIF\u002FGPS and unnecessary metadata, remain in private broker storage and are returned only through authorized proxy requests. Internal broker notes and private agent data are not exposed to WordPress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Documents:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fauth.wapuos.com\u002Fabout\" rel=\"nofollow ugc\">About\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fauth.wapuos.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fauth.wapuos.com\u002Fterms\" rel=\"nofollow ugc\">Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>2. Google OAuth \u002F OpenID Connect (indirect)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>When used:\u003C\u002Fstrong> only after a visitor actively selects Google.\u003C\u002Fp>\n\u003Cp>The visitor reaches Google through the broker. Google receives normal OAuth request and browser\u002Fnetwork metadata under its own policies. Provider tokens stay at the broker and are not returned to WordPress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Google Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fterms\" rel=\"nofollow ugc\">Google Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>3. Meta \u002F Facebook Login (indirect)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>When used:\u003C\u002Fstrong> only after a visitor actively selects Facebook.\u003C\u002Fp>\n\u003Cp>The visitor reaches Facebook through the broker. Meta may receive normal OAuth request and browser\u002Fnetwork metadata under its own policies. Provider tokens stay at the broker and are not returned to WordPress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fprivacy\u002Fpolicy\u002F\" rel=\"nofollow ugc\">Meta Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fterms\u002F\" rel=\"nofollow ugc\">Meta Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>4. GeoIP providers (optional, disabled by default)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Services:\u003C\u002Fstrong> \u003Ccode>https:\u002F\u002Fipapi.co\u002F\u003C\u002Fcode>, with \u003Ccode>https:\u002F\u002Fipwho.is\u002F\u003C\u002Fcode> as fallback.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data sent:\u003C\u002Fstrong> visitor IP address and normal HTTP metadata.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When used:\u003C\u002Fstrong> only when the administrator enables GeoIP enrichment. The site owner is responsible for an appropriate legal basis and consent where required.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fipapi.co\u002Fprivacy\u002F\" rel=\"nofollow ugc\">ipapi.co Privacy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fipwhois.io\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">ipwho.is Privacy\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>5. Google Analytics 4 event bridge (optional, disabled by default)\u003C\u002Fh4>\n\u003Cp>The plugin can call a site’s existing \u003Ccode>gtag\u003C\u002Fcode> function with provider-aware social-login events and limited status metadata. It does not load Google Analytics itself. The site administrator is responsible for consent and the site’s Analytics configuration.\u003C\u002Fp>\n\u003Ch3>Privacy & Data Retention\u003C\u002Fh3>\n\u003Cp>Wapu Auth stores local configuration, encrypted broker credentials, a one-way verified-origin fingerprint, hashed and expiring transaction state, canonical provider mappings, compatibility metadata, WordPress session data and any enabled analytics or Activity Log records. Depending on settings, detailed logs can contain account email, IP address and derived location.\u003C\u002Fp>\n\u003Cp>The automatic-connection state contains only sanitized status codes, counters, timestamps, provider availability and a one-way origin hash. It never contains the broker challenge, registration ID, site secret, signature, request payload or remote response.\u003C\u002Fp>\n\u003Cp>While one proof-of-control operation is pending, its registration ID and challenge are held separately in a short-lived WordPress transient only until verification, explicit recovery or expiry; they are not copied to plugin logs.\u003C\u002Fp>\n\u003Cp>Wapu Auth does not store provider access tokens, provider refresh tokens, provider authorization codes, raw HMAC signatures, broker tickets or one-use exchange codes. Legacy Google Client ID\u002FSecret values from 1.x are retained only in separate authenticated encrypted storage until an administrator completes the protected removal flow.\u003C\u002Fp>\n\u003Cp>Optional GeoIP and GA4 features are disabled by default. Administrators should update their own privacy notice and select a retention period appropriate to their jurisdiction.\u003C\u002Fp>\n\u003Cp>Optional Support images are disabled until the broker advertises the compatible \u003Ccode>WAPU-SUPPORT-ATTACHMENT-V1\u003C\u002Fcode> capability. Pending images are temporary and pruned after expiry; linked images are retained only for the broker support workflow and removed under its ticket\u002Fsite retention policy. They are not attached to WhatsApp or administrative email notifications. The broker strips EXIF, GPS and unnecessary image metadata during normalization. Site administrators should avoid uploading secrets or unrelated personal information and describe this support processing in their own privacy notice when the feature is enabled.\u003C\u002Fp>\n","Google and Facebook social login for WordPress and WooCommerce through Wapu Auth Broker, with secure account linking, sessions and local analytics.",948,"2026-07-18T20:27:00.000Z","6.9.5","6.3","8.0",[18,108,109,21,110],"oauth2","passwordless-login","woocommerce-login","https:\u002F\u002Fwapuclub.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwapu-auth-social-login.2.0.0.zip",{"slug":114,"name":115,"version":116,"author":117,"author_profile":118,"description":119,"short_description":120,"active_installs":11,"downloaded":121,"rating":11,"num_ratings":11,"last_updated":122,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":123,"homepage":126,"download_link":127,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"pnscode-social-login-and-register","Pnscode Social Login and Register","1.0.0","partho800","https:\u002F\u002Fprofiles.wordpress.org\u002Fpartho800\u002F","\u003Cp>Social Login & Custom Registration is the ultimate solution for simplifying user registration and login on your WordPress site. With a powerful drag-and-drop form builder and support for major social providers, you can create a seamless user experience that increases conversion rates.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Social Login & Registration\u003C\u002Fstrong>: Users can log in or register with Google, Facebook, X (Twitter), LinkedIn, and GitHub.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Registration Form Builder\u003C\u002Fstrong>: Build professional registration forms with custom fields (text, email, password, select, etc.).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security & Protection\u003C\u002Fstrong>: Built-in brute force protection and Google reCAPTCHA v3 support.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Verification\u003C\u002Fstrong>: Ensure user authenticity with mandatory email verification before account activation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce Integration\u003C\u002Fstrong>: Seamlessly adds social login buttons to WooCommerce login, registration, and checkout pages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Modern UI\u003C\u002Fstrong>: Stylish, indigo-themed admin interface and responsive frontend layouts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to third-party services to provide social login functionality and security features. Below is a detailed disclosure of all external services used:\u003C\u002Fp>\n\u003Ch4>Google OAuth 2.0\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Enables users to log in or register using their Google account\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>: User’s Google profile information (email, name, profile picture) when user authorizes the connection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When\u003C\u002Fstrong>: Only when a user clicks “Login with Google” and authorizes access\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Provider\u003C\u002Fstrong>: Google LLC\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service\u003C\u002Fstrong>: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Facebook Graph API\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Enables users to log in or register using their Facebook account\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>: User’s Facebook profile information (email, name, profile picture) when user authorizes the connection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When\u003C\u002Fstrong>: Only when a user clicks “Login with Facebook” and authorizes access\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Provider\u003C\u002Fstrong>: Meta Platforms, Inc.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service\u003C\u002Fstrong>: https:\u002F\u002Fwww.facebook.com\u002Fterms.php\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fwww.facebook.com\u002Fprivacy\u002Fexplanation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Google reCAPTCHA v3\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Protects forms from spam and abuse\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>: User interactions, browser information, and IP address for bot detection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When\u003C\u002Fstrong>: When reCAPTCHA is enabled and users interact with login\u002Fregistration forms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Provider\u003C\u002Fstrong>: Google LLC\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service\u003C\u002Fstrong>: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Twitter\u002FX OAuth\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Enables login\u002Fregistration via Twitter\u002FX\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>: Public profile details and email address (if authorized)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Provider\u003C\u002Fstrong>: X Corp.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Ftwitter.com\u002Fen\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>LinkedIn OAuth\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Enables login\u002Fregistration via LinkedIn\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>: Full name, profile photo, and primary email address\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Provider\u003C\u002Fstrong>: LinkedIn Corporation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fwww.linkedin.com\u002Flegal\u002Fprivacy-policy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>GitHub OAuth\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Enables login\u002Fregistration via GitHub\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>: GitHub profile information and public email\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Provider\u003C\u002Fstrong>: GitHub, Inc.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fdocs.github.com\u002Fen\u002Fsite-policy\u002Fprivacy-policies\u002Fgithub-privacy-statement\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Google Fonts\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Provides modern typography for the admin interface and frontend forms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>: User’s IP address and browser information to Google servers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Provider\u003C\u002Fstrong>: Google LLC\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service\u003C\u002Fstrong>: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n","Social login (Google, Facebook, X, etc.) and registration builder with security, email verification & WooCommerce support.",111,"2026-06-21T07:34:00.000Z",[18,124,19,125,21],"form-builder","registration","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fpnscode-social-login-and-register\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpnscode-social-login-and-register.1.0.0.zip",{"error":129,"url":130,"statusCode":131,"statusMessage":132,"message":132},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Ftanur-social-login\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":31,"versions":134},[135],{"version":6,"download_url":24,"svn_tag_url":136,"released_at":26,"has_diff":137,"diff_files_changed":138,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":139,"is_current":129},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftanur-social-login\u002Ftags\u002F1.0.9\u002F",false,[],[]]