OpenID Connect Generic Client
by Jonathan Daggerhart · Login & Users
Also makes 2 other plugins · 10.7K+ installs across the portfolio →
A simple client that provides SSO or opt-in authentication against a generic OAuth2 Server implementation.
84 health vs 59 average across 1,442 Login & Users plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
6.8K
now · peak 18.1K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
8
releases in the last 12 months
7mo ago
latest release · v3.11.3
23
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 62% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “10K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2019-07-20 · 1,430 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 3.11.3 Feature/improvement: Added configurable issuer setting for JWT validation. 3.11.3
- — Version 3.11.2 Improvement: Support identity providers that omit algorithm parameter in JWKS (Microsoft Entra ID). 3.11.2
- — Version 3.11.1 Fix bug created in 3.11.0 release when comparing issuer to derived expected value. 3.11.1
- — Version 3.11.0 SECURITY RELEASE Security: Added JWT signature verification using JWKS to prevent token forgery Security: Enhanced token claim validation (exp, aud, iss, iat, nonce) Security: Replaced weak state generation with cryptogr 3.11.0
- — Version 3.10.4 Fix issue with finding users on multisite after switch to user options in place of user meta. Improvement: Retry logins for some IDP errors to bypass issue with Safari ITP. Also improves display of error messages that co 3.10.4
- — Version 3.10.3 Fix issue with log corruption causing fatal error. Fix: Fallback to a POST request for userinfo when GET fails. Fix: Improves multisite compatibility by switching to *_user_options() functions. Fix: Fix for WordPress use 3.10.3
Known vulnerabilities
via Wordfence Intelligence2 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 6.4 OpenID Connect Generic Client <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2025-12-17 CVE-2025-13730 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.10.0 Patched in 3.10.1
- 2021-04-07 CVE-2021-24214 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 3.8.0 - 3.8.2 Patched in 3.8.2
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 5 languages, 0 at 90% or more
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-10-24 9K+ → 10K+ up after 2 days in tier
- 2025-10-22 10K+ → 9K+ down after 1 days in tier
- 2025-10-21 9K+ → 10K+ up after 11 days in tier
- 2025-10-10 10K+ → 9K+ down after 3 days in tier
- 2025-10-07 9K+ → 10K+ up after 224 days in tier
- 2025-02-25 8K+ → 9K+ up after 136 days in tier
- 2024-10-12 7K+ → 8K+ up after 39 days in tier
- 2024-09-03 6K+ → 7K+ up after 37 days in tier
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Loginizer 1M+ installs · 4.8★ · 2 shared tags A -
Security Optimizer – The All-In-One Protection Plugin 1M+ installs · 4.5★ · 2 shared tags A - L Limit Login Attempts 300K+ installs · 4.6★ · 2 shared tags D
-
WPS Limit Login 100K+ installs · 4.8★ · 2 shared tags A -
WP Ghost (Hide My WP Ghost) – Security & Firewall 100K+ installs · 4.5★ · 2 shared tags A -
WP fail2ban – Advanced Security 60K+ installs · 4.1★ · 2 shared tags C
Embed this report card
Drop a live Pulse card for OpenID Connect Generic Client into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/daggerhart-openid-connect-generic" width="480" height="300" style="border:0" loading="lazy" title="OpenID Connect Generic Client — Plugin Pulse"></iframe> OpenID Connect Generic Client: 10K+ active installs, 5.0★ (20 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/daggerhart-openid-connect-generic