{"id":330267,"date":"2026-06-23T10:26:49","date_gmt":"2026-06-23T10:26:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/4wp-account\/"},"modified":"2026-09-08T15:32:30","modified_gmt":"2026-09-08T15:32:30","slug":"4wp-account","status":"publish","type":"plugin","link":"https:\/\/ar.wordpress.org\/plugins\/4wp-account\/","author":17741300,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.1","stable_tag":"1.1.1","tested":"7.1.1","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"4WP Account","header_author":"4wpdev","header_description":"User account hub \u2014 Google\/GitHub social login, account page, and Gutenberg blocks.","assets_banners_color":"5b5e68","last_updated":"2026-09-08 15:32:30","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/4wpdev\/4wp-account","header_author_uri":"https:\/\/4wp.dev","rating":0,"author_block_rating":0,"active_installs":0,"downloads":319,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.4":{"tag":"1.0.4","author":"4wpdev","date":"2026-06-23 10:26:20","revision":3583054},"1.1.0":{"tag":"1.1.0","author":"4wpdev","date":"2026-09-08 14:57:15","revision":3686877},"1.1.1":{"tag":"1.1.1","author":"4wpdev","date":"2026-09-08 15:32:30","revision":3686924}},"upgrade_notice":{"1.1.1":"<p>Reinstall or update if 1.1.0 fatals with PasswordAuth not found \u2014 packaging fix only; no settings changes.<\/p>","1.1.0":"<p>Stable account hub: set the account page in Settings \u2192 Pages, add the Account block or [forwp_account], then optionally replace wp-login.php. Appearance and social button styles are under Appearance.<\/p>","1.0.4":"<p>Automated scan and Plugin Check fixes \u2014 includes T1 review items from 1.0.3.<\/p>","1.0.3":"<p>Review resubmit \u2014 OAuth state required on callback; use Redirect URIs from Auth settings after update.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3687239,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3687239,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3687239,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3687239,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":{"forwp\/account":{"$schema":"https:\/\/schemas.wp.org\/trunk\/block.json","apiVersion":3,"name":"forwp\/account","title":"4WP Account","category":"widgets","description":"Sign-in for guests or account cabinet with left menu for logged-in users.","textdomain":"4wp-account","icon":"admin-users","keywords":["4wp","4wp-account","account","login","profile","cabinet"],"supports":{"html":false,"align":["wide","full"]},"editorScript":"file:.\/editor.js","style":"file:..\/..\/css\/account.css","example":{"attributes":{}}},"forwp\/account-menu":{"$schema":"https:\/\/schemas.wp.org\/trunk\/block.json","apiVersion":3,"name":"forwp\/account-menu","title":"4WP Account Menu","category":"widgets","description":"User icon with a classic cabinet dropdown \u2014 account sections, custom links, and log out.","textdomain":"4wp-account","icon":"admin-users","keywords":["4wp","4wp-account","account","menu","cabinet","profile","user","header"],"attributes":{"accountUrl":{"type":"string","default":""}},"supports":{"html":false,"reusable":false,"multiple":true,"interactivity":false,"inserter":true},"editorScript":"file:.\/editor.js","editorStyle":"file:.\/editor.css","style":"file:..\/..\/css\/account-menu.css","viewScript":"file:..\/..\/js\/account-menu.js","example":{"attributes":{}}},"forwp\/auth-buttons":{"$schema":"https:\/\/schemas.wp.org\/trunk\/block.json","apiVersion":3,"name":"forwp\/auth-buttons","title":"4WP Sign-in Buttons","category":"widgets","description":"Social sign-in buttons (Google, GitHub, \u2026).","textdomain":"4wp-account","icon":"lock","keywords":["4wp","4wp-account","auth","login","google","github"],"attributes":{"providers":{"type":"string","default":"auto"}},"supports":{"html":false,"align":true},"editorScript":"file:.\/editor.js","style":"file:..\/..\/css\/auth.css","example":{"attributes":{"providers":"gmail,github"}}},"forwp\/account-link":{"$schema":"https:\/\/schemas.wp.org\/trunk\/block.json","apiVersion":3,"name":"forwp\/account-link","title":"4WP Account Link","category":"theme","description":"Header link with user icon \u2014 guest sign-in or account page when logged in.","textdomain":"4wp-account","icon":"admin-users","keywords":["4wp","4wp-account","account","login","menu","header","user","profile"],"attributes":{"label":{"type":"string","default":""},"labelGuest":{"type":"string","default":""},"labelUser":{"type":"string","default":""}},"supports":{"html":false,"className":true,"reusable":false,"multiple":false},"editorScript":"file:.\/editor.js","editorStyle":"file:.\/editor.css","style":"file:..\/..\/css\/account.css","example":{"attributes":{}}}},"tagged_versions":["1.0.4","1.1.0","1.1.1"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Admin \u2014 Auth \/ Register methods (email and social networks).","2":"Front-end \u2014 membership account page sign-in (email\/password and social login).","3":"Header \u2014 account menu block dropdown (user profile).","4":"Admin \u2014 Appearance of the guest sign-in card.","5":"Admin \u2014 Settings \u2192 Pages (account page and wp-login replacement)."}},"plugin_section":[],"plugin_tags":[1932,14955,9246,5134],"plugin_category":[38],"plugin_contributors":[262731,262732],"plugin_business_model":[],"class_list":["post-330267","plugin","type-plugin","status-publish","hentry","plugin_tags-membership","plugin_tags-user-account","plugin_tags-user-profile","plugin_tags-user-registration","plugin_category-authentication","plugin_contributors-4wpdev","plugin_contributors-anatolikkk","plugin_committers-4wpdev","plugin_committers-anatolikkk"],"banners":{"banner":"https:\/\/ps.w.org\/4wp-account\/assets\/banner-772x250.png?rev=3687239","banner_2x":"https:\/\/ps.w.org\/4wp-account\/assets\/banner-1544x500.png?rev=3687239","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/4wp-account\/assets\/icon-128x128.png?rev=3687239","icon_2x":"https:\/\/ps.w.org\/4wp-account\/assets\/icon-256x256.png?rev=3687239","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>4WP Account<\/strong> is a membership-ready <strong>user account<\/strong> hub: <strong>user registration<\/strong>, a front-end <strong>user profile<\/strong> cabinet, email\/password sign-in, and <strong>social network<\/strong> login (OAuth). Native <strong>Gutenberg<\/strong> blocks each have a matching <strong>shortcode<\/strong>. WooCommerce is optional.<\/p>\n\n<p>A plugin by <a href=\"https:\/\/4wp.dev\/\">4wp.dev<\/a>. <strong>4WP<\/strong> is our project brand; the letters \"WP\" appear only as part of that brand name, not as a reference to WordPress. This plugin is not affiliated with, endorsed by, or sponsored by WordPress.<\/p>\n\n<p>Source code: <a href=\"https:\/\/github.com\/4wpdev\/4wp-account\">github.com\/4wpdev\/4wp-account<\/a><\/p>\n\n<h4>Membership and user account<\/h4>\n\n<ul>\n<li>One <strong>account page<\/strong> for guests (sign-in \/ registration) and members (cabinet)<\/li>\n<li><strong>User profile<\/strong> shell with a configurable account menu (dashboard, WooCommerce, extras)<\/li>\n<li><strong>User registration<\/strong> follows <strong>Settings \u2192 General \u2192 Anyone can register<\/strong><\/li>\n<li>Email\/password works <strong>without WooCommerce<\/strong><\/li>\n<li>Optional replacement of <code>wp-login.php<\/code> \u2014 only when the chosen page already has a login block or shortcode<\/li>\n<\/ul>\n\n<h4>Social login<\/h4>\n\n<p>Enable providers under <strong>4WP Account \u2192 Auth \/ Register<\/strong>:<\/p>\n\n<ul>\n<li><strong>Live:<\/strong> email\/password, Google, GitHub, TikTok<\/li>\n<li><strong>Coming soon:<\/strong> Facebook, X<\/li>\n<\/ul>\n\n<p>Buttons can use native brand colors and icons, a solid fill, or icon-only.<\/p>\n\n<h4>Gutenberg blocks and shortcodes<\/h4>\n\n<p>Every block has a shortcode equivalent:<\/p>\n\n<ul>\n<li><code>forwp\/account<\/code> \u2014 <code>[forwp_account]<\/code> \u2014 account page (sign-in or cabinet)<\/li>\n<li><code>forwp\/account-menu<\/code> \u2014 <code>[forwp_account_menu]<\/code> \u2014 header user menu<\/li>\n<li><code>forwp\/account-link<\/code> \u2014 <code>[forwp_account_link]<\/code> \u2014 header\/menu account link<\/li>\n<li><code>forwp\/auth-buttons<\/code> \u2014 <code>[forwp_account_signin_buttons]<\/code> \u2014 social sign-in buttons<\/li>\n<li><code>[forwp_account_login provider=\"gmail\"]<\/code> \u2014 single provider button (shortcode only)<\/li>\n<\/ul>\n\n<p>Place them in the Site Editor or on a page. Sign-in methods are configured in <strong>Auth \/ Register<\/strong>. Appearance of the guest card is under <strong>Appearance<\/strong>. The account page is selected in <strong>Settings \u2192 Pages<\/strong>.<\/p>\n\n<h4>Also included<\/h4>\n\n<ul>\n<li>REST API \u2014 <code>\/wp-json\/forwp-account\/v1\/auth\/{provider}<\/code> and OAuth callbacks<\/li>\n<li>Optional social buttons on WooCommerce login\/register forms<\/li>\n<li>Hide the admin bar for subscribers; redirect subscribers away from <code>\/wp-admin\/<\/code><\/li>\n<\/ul>\n\n<h4>Privacy<\/h4>\n\n<p>OAuth tokens are exchanged server-side. Profile email and name from the provider are stored in WordPress user records. No data is sent to 4wp.dev.<\/p>\n\n<h4>Development<\/h4>\n\n<p>Run tests: <code>composer install &amp;&amp; composer run lint &amp;&amp; composer run test<\/code><\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to third-party OAuth providers when a visitor starts social login and when an administrator saves API credentials.<\/p>\n\n<h4>Google<\/h4>\n\n<ul>\n<li><strong>When:<\/strong> User clicks Google sign-in; server exchanges the authorization code and reads profile email.<\/li>\n<li><strong>Terms:<\/strong> <a href=\"https:\/\/developers.google.com\/terms\">Google API Terms of Service<\/a><\/li>\n<li><strong>Privacy:<\/strong> <a href=\"https:\/\/policies.google.com\/privacy\">Google Privacy Policy<\/a><\/li>\n<\/ul>\n\n<h4>GitHub<\/h4>\n\n<ul>\n<li><strong>When:<\/strong> User clicks GitHub sign-in; server exchanges the code and reads the primary verified email.<\/li>\n<li><strong>Terms:<\/strong> <a href=\"https:\/\/docs.github.com\/en\/site-policy\/github-terms\/github-terms-of-service\">GitHub Terms of Service<\/a><\/li>\n<li><strong>Privacy:<\/strong> <a href=\"https:\/\/docs.github.com\/en\/site-policy\/privacy-policies\/github-privacy-statement\">GitHub Privacy Statement<\/a><\/li>\n<\/ul>\n\n<h4>TikTok<\/h4>\n\n<ul>\n<li><strong>When:<\/strong> User clicks TikTok sign-in; server exchanges the Login Kit code (enable in Auth \/ Register).<\/li>\n<li><strong>Terms:<\/strong> <a href=\"https:\/\/www.tiktok.com\/legal\/terms-of-service\">TikTok Terms of Service<\/a><\/li>\n<li><strong>Privacy:<\/strong> <a href=\"https:\/\/www.tiktok.com\/legal\/privacy-policy\">TikTok Privacy Policy<\/a><\/li>\n<\/ul>\n\n<h4>Meta (Facebook) \u2014 planned<\/h4>\n\n<ul>\n<li><strong>When:<\/strong> Not enabled in this release. Listed in admin as <em>coming soon<\/em>.<\/li>\n<li><strong>Terms:<\/strong> <a href=\"https:\/\/developers.facebook.com\/terms\/\">Meta Platform Terms<\/a><\/li>\n<li><strong>Privacy:<\/strong> <a href=\"https:\/\/www.facebook.com\/privacy\/policy\/\">Meta Privacy Policy<\/a><\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/4wp-account\/<\/code> or install from the Plugins screen.<\/li>\n<li>Activate <strong>4WP Account<\/strong>.<\/li>\n<li>Open <strong>4WP Account \u2192 Auth \/ Register<\/strong> \u2014 enable email\/password and any social networks, then paste OAuth credentials.<\/li>\n<li>Copy each <strong>Redirect URI<\/strong> from settings into the Google, GitHub, or TikTok app.<\/li>\n<li>Create a page, add the <strong>Account<\/strong> block (<code>forwp\/account<\/code>) or <code>[forwp_account]<\/code>, then select that page under <strong>Settings \u2192 Pages<\/strong>.<\/li>\n<li>Optional: add <strong>Account Menu<\/strong> to the header; style the guest card under <strong>Appearance<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20this%20a%20membership%20plugin%20for%20a%20user%20account%3F\"><h3>Is this a membership plugin for a user account?<\/h3><\/dt>\n<dd><p>Yes. 4WP Account is a <strong>membership<\/strong> hub: one front-end <strong>user account<\/strong> for sign-in, <strong>user registration<\/strong>, and a logged-in <strong>user profile<\/strong> cabinet. It does not sell plans or paywalls \u2014 it is the account layer those membership sites sit on.<\/p><\/dd>\n<dt id=\"does%20it%20support%20user%20registration%3F\"><h3>Does it support user registration?<\/h3><\/dt>\n<dd><p><strong>User registration<\/strong> uses the native WordPress membership setting: <strong>Settings \u2192 General \u2192 Anyone can register<\/strong>. When that is on, the account page shows Create account next to email\/password sign-in. Social networks can also create a subscriber on first login.<\/p><\/dd>\n<dt id=\"where%20is%20the%20user%20profile%3F\"><h3>Where is the user profile?<\/h3><\/dt>\n<dd><p>The <strong>user profile<\/strong> (cabinet) is the same account page after login: left menu plus section body. Configure the page in <strong>Settings \u2192 Pages<\/strong> and menu items in <strong>Settings \u2192 Account Menu<\/strong>. Guests see sign-in; members see the account.<\/p><\/dd>\n<dt id=\"can%20members%20sign%20in%20with%20social%20networks%3F\"><h3>Can members sign in with social networks?<\/h3><\/dt>\n<dd><p>Yes. <strong>Social login<\/strong> is first-class next to email\/password: Google, GitHub, and TikTok are live when you enable them under <strong>Auth \/ Register<\/strong>. Facebook and X are listed as coming soon. Buttons can use native brand colors and icons.<\/p><\/dd>\n<dt id=\"are%20there%20gutenberg%20blocks%20and%20shortcodes%3F\"><h3>Are there Gutenberg blocks and shortcodes?<\/h3><\/dt>\n<dd><p>Yes. Native <strong>Gutenberg<\/strong> blocks: <code>forwp\/account<\/code>, <code>forwp\/account-menu<\/code>, <code>forwp\/account-link<\/code>, <code>forwp\/auth-buttons<\/code>. Each has a <strong>shortcode<\/strong>: <code>[forwp_account]<\/code>, <code>[forwp_account_menu]<\/code>, <code>[forwp_account_link]<\/code>, <code>[forwp_account_signin_buttons]<\/code>. There is also <code>[forwp_account_login provider=\"gmail\"]<\/code> for a single social button. See <strong>Settings \u2192 Blocks \/ Shortcodes<\/strong>.<\/p><\/dd>\n<dt id=\"can%20i%20hide%20the%20default%20wordpress%20login%20screen%3F\"><h3>Can I hide the default WordPress login screen?<\/h3><\/dt>\n<dd><p>Only if a real entry point exists. Under <strong>Settings \u2192 Pages<\/strong>, pick a published page that already contains the Account block or a login shortcode, then enable <strong>Use the account page instead of wp-login.php<\/strong>. If the block is removed later, <code>wp-login.php<\/code> stays available. Logout and password-reset links on <code>wp-login.php<\/code> are not blocked.<\/p><\/dd>\n<dt id=\"do%20i%20need%20woocommerce%3F\"><h3>Do I need WooCommerce?<\/h3><\/dt>\n<dd><p>No. Email\/password, social login, the account page, and Gutenberg blocks work without WooCommerce. If WooCommerce is active, you can show social buttons on My Account forms and fall back to My Account when no account page is selected.<\/p><\/dd>\n<dt id=\"where%20is%20the%20oauth%20callback%20url%3F\"><h3>Where is the OAuth callback URL?<\/h3><\/dt>\n<dd><p><strong>4WP Account \u2192 Auth \/ Register<\/strong> \u2014 open a live provider and copy the Redirect URI (built with <code>rest_url()<\/code>, compatible with custom REST prefixes).<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Hotfix: ship the full Auth module and production Composer <code>vendor\/<\/code> in the WordPress.org package (incomplete 1.1.0 ZIP could fatal on activate).<\/li>\n<li>Auth \/ Register: highlight method cards that are Enabled (Live \u2260 On).<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Stable membership release: user account page, user registration, user profile cabinet.<\/li>\n<li>Settings \u2192 Pages: replace <code>wp-login.php<\/code> only when the chosen page has an Account block or login shortcode.<\/li>\n<li>Move toolbar \/ subscriber redirect Behavior next to the account page setting.<\/li>\n<li>Document every Gutenberg block and its shortcode under Settings \u2192 Blocks \/ Shortcodes.<\/li>\n<li>OAuth: prevent cached auth URL \/ state (REST no-store headers + front-end fetch cache bust).<\/li>\n<li>Tested up to WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>Appearance tab: guest card background, border color\/width\/radius, live preview (two fields side by side; stack when narrow).<\/li>\n<li>Social buttons: native brand colors and icons, solid fill, or icon-only.<\/li>\n<li>Auth \/ Register method cards: email\/password, Google, GitHub, TikTok (live); Facebook and X (coming soon).<\/li>\n<li>Email\/password as a first-class provider; registration follows WordPress \u201cAnyone can register\u201d; WooCommerce not required.<\/li>\n<li>Remove the extra Forms tab.<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Remove unused <code>register_setting()<\/code> calls (automated Plugin Check).<\/li>\n<li>Plugin Check warnings: input sanitization, migration SQL <code>%i<\/code>, distignore moved to docs.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Review fixes: required OAuth <code>state<\/code> validation, <code>rest_url()<\/code> for callback URLs, readme aligned with active providers.<\/li>\n<li>Account blocks and GitHub provider (from ongoing development).<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>WordPress.org packaging: readme, GPL license, text domain <code>4wp-account<\/code>, quality toolchain.<\/li>\n<li>Provider enable toggle respected before login.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Gmail OAuth, shortcodes, WooCommerce integration.<\/li>\n<\/ul>","raw_excerpt":"Membership user account hub: registration, user profile cabinet, and social login with Gutenberg blocks and shortcodes.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/330267","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=330267"}],"author":[{"embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/4wpdev"}],"wp:attachment":[{"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=330267"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=330267"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=330267"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=330267"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=330267"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=330267"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}