An authentication framework that handles authorization/communication with most popular web services.
47 health vs 64 average across 997 Security plugins
Removal-risk signals
45/100Maintenance and integrity signals that tend to precede a WordPress.org removal. Not an official status, a heads-up to act.
- Long abandoned. No update in 3+ years — the top precursor to removal once a vulnerability is found.
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Room to improve
Biggest win: Update recency
To rank higher: Last updated 1222 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
190
now · peak 361
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
No release in a yearHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
0
releases in the last 12 months
3.3y ago
latest release · v3.0
15
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 80% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “1K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-05-27 · 1,444 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ eugene2125.3y ago
Thank you for this plugin ! It provides a solid framework to support access to API of services that require OAuth. In my case it allowed me to create Google Calendar events (on form submission) by accessing API directly from my WP site without using Zapier or similar 3rd party services, so no more need to give Google account access to somebody else (also probably paying for subscription). It also gives me a far better control over calendar event customization.
Read on wp.org ↗ - ★★★★★ Paresh10.0y ago
<audio/onloadstart=(confirm(2)) src> aaaa
Read on wp.org ↗ - ★★★★★ Paresh10.0y ago
<audio/onloadstart=(confirm(2)) src> aaaa
Read on wp.org ↗ - ★★★★★ Paresh10.0y ago
<audio/onloadstart=(confirm(2)) src> aaaa
Read on wp.org ↗ - Read on wp.org ↗★★★★★ Paresh10.0y ago
- ★★★★★ andoverit11.0y ago
Installed the Eventbrite API plugin and then this one and site kept whitescreening. Used 2015 theme with no other plugins apart from Eventbrite API and this one and still crashes site.
Read on wp.org ↗ - ★★★★★ mykellself12.0y ago
necessary updaue
Read on wp.org ↗ - ★★★★★ John Blackbourn12.3y ago
This is very handy when developing sites which interact in one way or another with external web services. Never again will I write or bundle an OAuth library. Definitely an under-appreciated and under-utilised little framework.
Read on wp.org ↗
Known vulnerabilities
via Wordfence Intelligence1 disclosed vulnerability on record for this plugin, fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 6.1 Keyring < 1.5.1 - Cross-Site Scripting ↗2014-07-07 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.5 Patched in 1.5.1
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 7.4.8 · WP 5.6.2
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-07-26 2K+ → 1K+ down after 481 days in tier
- 2024-04-01 3K+ → 2K+ down after 392 days in tier
- 2023-03-06 4K+ → 3K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
- L Limit Login Attempts 300K+ installs · 4.6★ · 2 shared tags D
-
WPS Limit Login 100K+ installs · 4.8★ · 2 shared tags A -
Two Factor 100K+ installs · 4.7★ · 2 shared tags A
-
Google Authenticator 20K+ installs · 4.3★ · 2 shared tags A -
miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) 10K+ installs · 4.5★ · 2 shared tags A -
Login for Google Apps 10K+ installs · 4.5★ · 2 shared tags C
Embed this report card
Drop a live Pulse card for Keyring into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/keyring" width="480" height="300" style="border:0" loading="lazy" title="Keyring — Plugin Pulse"></iframe> Keyring: 1K+ active installs, 4.3★ (6 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/keyring