Login by Auth0
by Auth0 · Security
Login by Auth0 provides improved username/password login, Passwordless login, Social login and Single Sign On for all your sites.
48 health vs 64 average across 997 Security plugins
Removal-risk signals
28/100Maintenance and integrity signals that tend to precede a WordPress.org removal. Not an official status, a heads-up to act.
- Not actively maintained. No update in about 2 years.
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Room to improve
Biggest win: Update recency
To rank higher: Last updated 778 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
2.3K
now · peak 6.2K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
No release in a yearHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
0
releases in the last 12 months
2.1y ago
latest release · v4.6.2
44
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 30% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “10K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-10 · 1,467 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ arbbi1.6y ago
If you’re considering using the “Login by Auth0” plugin for WordPress authentication, DON’T. This plugin is an outdated, poorly maintained disaster that can break your site entirely. ❌ Fatal Errors & Crashes Installing and activating this plugin caused a fatal error on my WordPress site, making the entire login process unusable. It hasn’t been properly tested with the latest WordPress versions, and there’s no sign of maintenance or bug fixes. ❌ No Support, No Updates The plugin is practically abandoned – the last update was ages ago, and support requests are ignored or unanswered. If you run into issues, you’re on your own. For a security-focused plugin, this is completely unacceptable. ❌ Security Risks An authentication plugin that isn’t actively maintained is a massive security liability. If a vulnerability is found (which is likely, given the outdated codebase), you won’t get a fix anytime soon. ❌ Terrible User Experience Even if the plugin doesn’t crash your site (which it likely will), the configuration is a nightmare. The setup process is clunky, error-prone, and riddled with outdated documentation. Expect a frustrating experience from start to finish. 💀 Final Verdict: DO NOT USE. Auth0 is a great identity provider, but this WordPress plugin is a complete embarrassment. If you value site stability, security, and actual support, avoid this plugin at all costs. 🔹 Uninstall immediately.🔹 Look for a better alternative.🔹 Hope Auth0 either fixes or completely deprecates this mess. 🚨 DO NOT TRUST YOUR SITE’S LOGIN SECURITY TO THIS BROKEN PLUGIN. 🚨
Read on wp.org ↗ - ★★★★★ philbahz2.0y ago
The title says it all. I spent the better part of 3 days trying to get this to work with no luck. I even paid for a plan to get support. They were little to no help. I use miniorange for my SSO needs. It works decently and has good support.
Read on wp.org ↗ - ★★★★★ Ivan Hryhorenko2.3y ago
Unfortunately, plugin doesn’t work and abandoned. On official Github repository you can find this text: v4 of the plugin is no longer supported as of June 2023. We are no longer providing new features or bugfixes for that release. Please upgrade to v5 as soon as possible. OAuth0 Github But irony that v5 doesn’t work as well, so both versions of plugin are just a waste of time This topic was modified 2 years, 2 months ago by Ivan Hryhorenko.
Read on wp.org ↗ - ★★★★★ Donald Moore Jr.4.7y ago
I have some questions about signing JWT’s, but other than that, the documentation is exhaustive, which is one of the reasons why I chose it. You can tell when a project is put together well.
Read on wp.org ↗ - ★★★★★ Menn5.4y ago
I use multiple WordPress sites and other member platform. When I set every site login via Auth0, it creates seamless experience for users. I decide to user only Passwordless email. This will help people secure their accounts (because of no password to remember and no easy password remains.)
Read on wp.org ↗ - ★★★★★ svax5.5y ago
Multiple users are not allowed to login getting the error : “This site requires a verified email”, even though this is not enabled in the settings. I’ve tried reporting this, getting absolutely zero response after 6 months…
Read on wp.org ↗ - ★★★★★ Ajay Ghaghretiya8.2y ago
Does the latest version of plugin use the Lock 10 or Later version of the Lock API? Please do let me know your inputs about the same. Thanks
Read on wp.org ↗ - ★★★★★ earmbrust8.5y ago
. This topic was modified 8 years, 4 months ago by earmbrust. This topic was modified 8 years, 4 months ago by earmbrust. This topic was modified 8 years, 4 months ago by earmbrust.
Read on wp.org ↗
Known vulnerabilities
via Wordfence Intelligence7 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2024-07-09 CVE-2023-6813 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.6.0 Patched in 4.6.1
- 2020-04-01 CVE-2020-7948 Authorization Bypass Through User-Controlled Key Affects <= 3.11.3 Patched in 4.0.0
- Critical · 9.8 Login by Auth0 <= 3.11.3 - CSV Injection ↗2020-04-01 CVE-2020-7947 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 3.11.3 Patched in 4.0.0
- 2020-04-01 CVE-2020-6753 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.11.3 Patched in 4.0.0
- 2020-03-31 CVE-2020-5392 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.11.3 Patched in 4.0.0
- 2020-01-31 CVE-2019-20173 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 3.11.0 - 3.11.2 Patched in 3.11.3
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 6.5.5
Languages
via translate.wordpress.orgTranslated into 5 languages, 2 at 90% or more
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-09-16 20K+ → 10K+ down after 495 days in tier
- 2024-05-09 10K+ → 20K+ up after 7 days in tier
- 2024-05-02 6K+ → 10K+ up after 50 days in tier
- 2024-03-13 5K+ → 6K+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
- L Limit Login Attempts 300K+ installs · 4.6★ · 2 shared tags D
-
WPS Limit Login 100K+ installs · 4.8★ · 2 shared tags A -
Two Factor 100K+ installs · 4.7★ · 2 shared tags A
-
Google Authenticator 20K+ installs · 4.3★ · 2 shared tags A -
miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) 10K+ installs · 4.5★ · 2 shared tags A -
Passwords Evolved 1K+ installs · 4.1★ · 2 shared tags C
Embed this report card
Drop a live Pulse card for Login by Auth0 into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/auth0" width="480" height="300" style="border:0" loading="lazy" title="Login by Auth0 — Plugin Pulse"></iframe> Login by Auth0: 10K+ active installs, 3.1★ (18 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/auth0