WP OAuth Server (OAuth Authentication)
by Jayson T Cote · Uncategorized
Adds Authentication through OAuth 2. Provides the ability for Single Sign On for websites & Mobile Applications.
82 health vs 56 average across 16,376 Uncategorized plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
3.9K
now · peak 4.2K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Occasionally updatedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
1
releases in the last 12 months
7mo ago
latest release · v4.5.0
37
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 55% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “3K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-10 · 1,475 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from. The recent download trend is too spiky to read.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ Jonathan Afranio1.0y ago
I tested WP OAuth Server (OAuth Authentication) in integration with a client application and found a serious issue: even after the user logs out from WordPress, the issued access token is still accepted by the /oauth/me endpoint, returning all user data. This means any client application that has stored the token can continue accessing private information indefinitely, until the token expires, without verifying if the session on the server has ended. I tried to work around the issue by enabling the introspection endpoint and validating the token on each request, but the plugin does not revoke the token on logout, making introspection ineffective for detecting logouts. This flaw breaks a basic security principle of OAuth 2.0 and may expose sensitive data. I do not recommend using this plugin until token revocation upon logout is implemented.
Read on wp.org ↗ - ★★★★★ Vic2.3y ago
It looks like the plugin is abandoned. Moreover, I bought a Pro version but it doesn’t work and nobody replies via the support email. I can’t even access my license key because the password restore doesn’t work on their website. DO NOT use this plugin!
Read on wp.org ↗ - ★★★★★ Northern Beaches Websites3.0y ago
I just want to say thank you to the developer, you have done a great job and saved me a tonne of time 🙂
Read on wp.org ↗ - ★★★★★ robegb3.3y ago
Just what I expected, thanks!
Read on wp.org ↗ - ★★★★★ uusr3.3y ago
Gives an error while logging in “Missing required parameter: scope”
Read on wp.org ↗ - ★★★★★ ntalam3.3y ago
Fatal error: Uncaught TypeError: openssl_pkey_get_details(): Argument #1 ($key) must be of type OpenSSLAsymmetricKey, null given in F:\xampp2\htdocs\wp\wp-content\plugins\oauth2-provider\includes\functions.php:388 Stack trace: #0 …\functions.php(388): openssl_pkey_get_details(NULL) #1 This topic was modified 3 years, 2 months ago by ntalam.
Read on wp.org ↗ - ★★★★★ Ivan Hryhorenko4.0y ago
There is no answer even on the premium version website. The plugin is abandoned, with legacy code and some bugs. Please, choose an alternative decision. Didn’t use this one! This topic was modified 3 years, 10 months ago by Ivan Hryhorenko.
Read on wp.org ↗ - ★★★★★ sunmp124.2y ago
There are a lot of bugs and strange or malfunctioning in the plugin. Looking at the plugin forum, there is no support for the plugin at all. Maybe there is only support for the pro version, but so I don’t dare try it.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 4.5.0 Security Update: A patch has been added to protect the private key during certain server configurations. Updating is highly recommended. Added a new admin notice for permalink setting recommendations. Updated with WP 6.9 4.5.0
- — Version 4.4.0 (Security Update) Refactored the “destroy” endpoint to remove the auto redirect in favor for a manual checkpoint. Cleaned up misc functions. This should not effect any existing implementations. Tested with 6.4 installed. 4.4.0
- — Version 4.3.4 Updated to fix deprecated messages for PHP 8.1 and WP 6.2 Added prepare statements in CRON cleanup Adjustments to make some options more clear. 4.3.4
- — Version 4.3.3 Updated wpoauth_authenicate_bypass to return false. Tested with WP 6.2 4.3.3
- — Version 4.2.5 Updated sanity checks in AJAX 4.2.5
- — Version 4.2.3 Tested WP 6.0.3 4.2.3
Known vulnerabilities
via Wordfence Intelligence7 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 5.4 OAuth Server <= 4.3.3 - Open Redirect ↗2024-04-05 CVE-2024-31253 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 4.3.3 Patched in 4.4.0
- 2023-01-26 Cross-Site Request Forgery (CSRF) Affects <= 4.2.5 Patched in 4.3.0
- Medium · 5.5 WP OAuth Server (OAuth Authentication) <= 4.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting ↗2022-11-08 CVE-2022-3892 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.1 Patched in 4.2.2
- 2015-08-12 CVE-2015-9435 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Affects < 3.1.5 Patched in 3.1.5
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 5 languages, 0 at 90% or more
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2023-07-14 4K+ → 3K+ down after 2 days in tier
- 2023-07-12 3K+ → 4K+ up after 1 days in tier
- 2023-07-11 4K+ → 3K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
- W WP OAuth Integration 10+ installs · 3.6★ · 5 shared tags D
-
WP OAuth Server ( Login with WordPress ) 1K+ installs · 4.7★ · 2 shared tags A -
JWT Authentication for WP REST API 60K+ installs · 4.3★ · 1 shared tag B -
Gmail SMTP 10K+ installs · 4.1★ · 1 shared tag B -
Login for Google Apps 10K+ installs · 4.5★ · 1 shared tag C - O OpenID Connect Generic Client 10K+ installs · 4.6★ · 1 shared tag B
Embed this report card
Drop a live Pulse card for WP OAuth Server (OAuth Authentication) into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/oauth2-provider" width="480" height="300" style="border:0" loading="lazy" title="WP OAuth Server (OAuth Authentication) — Plugin Pulse"></iframe> WP OAuth Server (OAuth Authentication): 3K+ active installs, 3.8★ (41 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/oauth2-provider