{"id":225459,"date":"2025-07-21T00:17:07","date_gmt":"2025-07-21T00:17:07","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/attributes-user-access\/"},"modified":"2026-09-15T18:03:20","modified_gmt":"2026-09-15T18:03:20","slug":"attributes-user-access","status":"publish","type":"plugin","link":"https:\/\/it.wordpress.org\/plugins\/attributes-user-access\/","author":23240689,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.0.0","stable_tag":"2.0.0","tested":"7.1.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Attributes User Access","header_author":"Attributes WP","header_description":"Attributes User Access is a lightweight and flexible authentication solution for WordPress designed for greater control over login process.","assets_banners_color":"b2aed0","last_updated":"2026-09-15 18:03:20","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/attributeswp.com\/#features","header_author_uri":"https:\/\/attributeswp.com\/","rating":5,"author_block_rating":0,"active_installs":10,"downloads":888,"num_ratings":2,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"attributeswp","date":"2025-07-21 01:18:12","revision":3331080},"1.1.0":{"tag":"1.1.0","author":"attributeswp","date":"2025-07-21 18:36:27","revision":3331676},"1.2.0":{"tag":"1.2.0","author":"attributeswp","date":"2025-11-04 17:16:14","revision":3389834},"1.2.1":{"tag":"1.2.1","author":"attributeswp","date":"2025-11-04 18:14:36","revision":3389878},"1.2.2":{"tag":"1.2.2","author":"attributeswp","date":"2026-02-10 16:59:04","revision":3458264},"2.0.0":{"tag":"2.0.0","author":"attributeswp","date":"2026-09-15 18:03:20","revision":3697519}},"upgrade_notice":{"2.0.0":"<p>Published together with Pro 2.0. If you run the Pro extension, read its upgrade\nnotice first: three of its security switches start enforcing what they promised.<\/p>","1.3.0":"<p>Compatibility update for WordPress 7.0 plus asset-loading fixes. Recommended for all users.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":2},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3331090,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3331090,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3331079,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772-250.png":{"filename":"banner-772-250.png","revision":3331076,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":{"attrua\/form":{"name":"attrua\/form","title":"Attributes Login Form"}},"tagged_versions":["1.0.0","1.1.0","1.2.0","1.2.1","1.2.2","2.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3331130,"resolution":"1","location":"assets","locale":"","width":1200,"height":900},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3331130,"resolution":"2","location":"assets","locale":"","width":1200,"height":900},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3331130,"resolution":"3","location":"assets","locale":"","width":1200,"height":900},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3331130,"resolution":"4","location":"assets","locale":"","width":1200,"height":900},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3331130,"resolution":"5","location":"assets","locale":"","width":1200,"height":900}},"screenshots":{"1":"Branded custom login page rendered on the front end.","2":"Registration form with role-based redirection settings.","3":"Role and redirect configuration in the admin.","4":"Template override structure for developers."}},"plugin_section":[],"plugin_tags":[710,3691,5574,727,603],"plugin_category":[38,54],"plugin_contributors":[245154],"plugin_business_model":[],"class_list":["post-225459","plugin","type-plugin","status-publish","hentry","plugin_tags-authentication","plugin_tags-custom-login","plugin_tags-login-page","plugin_tags-redirect","plugin_tags-registration","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-attributeswp","plugin_committers-attributeswp"],"banners":{"banner":"https:\/\/ps.w.org\/attributes-user-access\/assets\/banner-772-250.png?rev=3331076","banner_2x":"https:\/\/ps.w.org\/attributes-user-access\/assets\/banner-1544x500.png?rev=3331079","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/attributes-user-access\/assets\/icon-128x128.png?rev=3331090","icon_2x":"https:\/\/ps.w.org\/attributes-user-access\/assets\/icon-256x256.png?rev=3331090","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/attributes-user-access\/assets\/screenshot-1.png?rev=3331130","caption":"Branded custom login page rendered on the front end."},{"src":"https:\/\/ps.w.org\/attributes-user-access\/assets\/screenshot-2.png?rev=3331130","caption":"Registration form with role-based redirection settings."},{"src":"https:\/\/ps.w.org\/attributes-user-access\/assets\/screenshot-3.png?rev=3331130","caption":"Role and redirect configuration in the admin."},{"src":"https:\/\/ps.w.org\/attributes-user-access\/assets\/screenshot-4.png?rev=3331130","caption":"Template override structure for developers."},{"src":"https:\/\/ps.w.org\/attributes-user-access\/assets\/screenshot-5.png?rev=3331130","caption":""}],"raw_content":"<!--section=description-->\n<p><strong>Attributes User Access<\/strong> replaces the generic <code>wp-login.php<\/code> screen with fully branded, on-theme <strong>login, lost password, password reset and registration pages<\/strong> \u2014 built with shortcodes or blocks, and completely compatible with WordPress core.<\/p>\n\n<p>It is a lightweight, developer-friendly authentication toolkit: you get clean front-end forms, flexible role-based redirects, and template overrides, without a page builder and without touching WordPress core.<\/p>\n\n<h4>Why site owners use it<\/h4>\n\n<p>The default WordPress login page sends every visitor to an unbranded <code>\/wp-admin\/<\/code> screen. Attributes User Access lets you serve a login and registration experience that matches your site, control exactly where each role lands after signing in, and keep everything update-safe.<\/p>\n\n<h4>Free features<\/h4>\n\n<ul>\n<li><strong>Custom authentication pages<\/strong> \u2014 Login, Lost Password, Reset Password and Registration, as shortcodes or blocks.<\/li>\n<li><strong>Redirect the native login<\/strong> \u2014 send <code>wp-login.php<\/code> requests to your own branded pages.<\/li>\n<li><strong>Role-based &amp; context-aware redirection<\/strong> \u2014 define where users go after login and logout, per role.<\/li>\n<li><strong>Theme template overrides<\/strong> \u2014 copy any form template into your theme (<code>your-theme\/attributes\/front\/forms\/login-form.php<\/code>) for full markup control; overrides survive updates.<\/li>\n<li><strong>Built for developers<\/strong> \u2014 PSR-4 autoloading, object-oriented, extensible with action and filter hooks (e.g. <code>attrua_login_form_fields<\/code>, <code>attrua_after_login_form<\/code>).<\/li>\n<li><strong>Lightweight by design<\/strong> \u2014 selective asset loading, transient caching, and minified production assets.<\/li>\n<li><strong>Update-safe<\/strong> \u2014 adapts to WordPress core changes so your login pages keep working.<\/li>\n<\/ul>\n\n<h4>Upgrade to Attributes User Access Pro<\/h4>\n\n<p>Pro turns the plugin into a complete authentication, security and user-management suite \u2014 the kind of stack most sites assemble from five or six separate plugins (login customizer, 2FA, IP firewall, audit log, SMTP, password policy, maintenance mode), unified in one.<\/p>\n\n<ul>\n<li><strong>Member pages<\/strong> \u2014 Account, Profile, Settings and Onboarding flows.<\/li>\n<li><strong>Visual Form Builder<\/strong> \u2014 20+ field types with validation, conditional logic, storage mapping to WordPress user columns\/meta, and dynamic default-value tokens.<\/li>\n<li><strong>Authentication methods<\/strong> \u2014 Two-Step (2FA), Passwordless email login, and Social OAuth sign-in.<\/li>\n<li><strong>Security<\/strong> \u2014 IP blocking (single IP, CIDR range, IPv6, with expiry), reCAPTCHA, and a password policy (complexity, expiration, history).<\/li>\n<li><strong>Audit log<\/strong> \u2014 50+ security events across categories, retention control and CSV export.<\/li>\n<li><strong>Registration control<\/strong> \u2014 email verification, disposable-email blocking and domain validation.<\/li>\n<li><strong>Email &amp; SMTP<\/strong> \u2014 Gmail \/ Google Workspace and Microsoft 365 via OAuth2, App Password, Resend or custom SMTP, plus templated emails and broadcast messaging.<\/li>\n<li><strong>Maintenance mode<\/strong> \u2014 proper 503 response, role\/IP whitelist, bypass URL and scheduling.<\/li>\n<li><strong>Block Editor &amp; Elementor<\/strong> \u2014 native form widgets with full style controls.<\/li>\n<li><strong>Emergency admin access<\/strong> \u2014 an anti-lockout safeguard for administrators.<\/li>\n<\/ul>\n\n<p>Learn more and view pricing at <a href=\"https:\/\/attributeswp.com\/\">attributeswp.com<\/a>. All Pro plans include updates, support and a 30-day money-back guarantee.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to <code>\/wp-content\/plugins\/attributes-user-access\/<\/code>, or install it through the <strong>Plugins &gt; Add New<\/strong> screen in WordPress.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> screen.<\/li>\n<li>Go to <strong>User Access<\/strong> in the admin menu to create your login, registration and password pages.<\/li>\n<li>(Optional) Set your role-based redirects and, if you use a page builder, drop the Attributes blocks or shortcodes onto your pages.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20work%20with%20my%20theme%3F\"><h3>Will this work with my theme?<\/h3><\/dt>\n<dd><p>Yes. The forms are built to work with any properly coded WordPress theme and adapt to your theme's styling. Developers can also override the templates from within the theme for complete control.<\/p><\/dd>\n<dt id=\"do%20i%20need%20coding%20knowledge%3F\"><h3>Do I need coding knowledge?<\/h3><\/dt>\n<dd><p>No. Custom login pages, registration and redirects are set up from the admin with a few clicks. Developers get extensive hooks and filters for deeper customization.<\/p><\/dd>\n<dt id=\"which%20wordpress%20version%20is%20this%20tested%20with%3F\"><h3>Which WordPress version is this tested with?<\/h3><\/dt>\n<dd><p>This release is tested up to WordPress 7.1 and follows WordPress coding standards. We update regularly to track new WordPress releases.<\/p><\/dd>\n<dt id=\"what%20is%20the%20difference%20between%20the%20free%20plugin%20and%20pro%3F\"><h3>What is the difference between the free plugin and Pro?<\/h3><\/dt>\n<dd><p>The free plugin covers custom login, registration and password pages plus role-based redirects. Pro adds a visual form builder, two-factor and passwordless authentication, IP blocking, an audit log, SMTP, password policies, maintenance mode and more. See <a href=\"https:\/\/attributeswp.com\/\">attributeswp.com<\/a>.<\/p><\/dd>\n<dt id=\"does%20it%20replace%20or%20break%20the%20default%20wordpress%20login%3F\"><h3>Does it replace or break the default WordPress login?<\/h3><\/dt>\n<dd><p>It redirects the native login to your custom pages while keeping standard WordPress authentication intact underneath, so nothing in core is modified.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.0.0<\/h4>\n\n<p>Core and Pro are published together as 2.0.<\/p>\n\n<ul>\n<li>Fixed: a broken installation \u2014 an upload that stopped halfway, a restored\nbackup \u2014 switches the plugin off with a notice instead of taking the site\ndown with it.<\/li>\n<li>Fixed: a refused sign-in says why. Any error the extensions raise \u2014 a\npassword policy, a reCAPTCHA challenge, a second factor \u2014 reached the form as\n\"An unknown error occurred\". The sentence it was given is now shown. The key\nused to carry that sentence was drawn from an alphabet the reader lowercased,\nso it almost never matched and the generic message showed regardless; the two\nnow agree.<\/li>\n<li>Removed: two public AJAX endpoints, attrua_check_username and\nattrua_check_email, that answered \"does this account exist?\" to anyone with no\nlimit of any kind. Nothing called them \u2014 the registration form makes no such\nrequest \u2014 and the Pro extension already dropped its own copies for the same\nreason.<\/li>\n<li>Fixed: the emergency access link that reaches wp-login.php exchanges its token\nfor a short-lived cookie and comes back without the token in the address,\nwhere it would otherwise sit in access logs, browser history and Referer\nheaders. When Pro is active, every use and refusal is written to the audit\nlog. It declines the redirect to a custom login page and nothing more \u2014 a\nsecond factor still applies.<\/li>\n<li>Changed: the nonce-refresh endpoint, which hands a fresh sign-in nonce to a\ncached login page, is served to signed-out visitors only. Its logged-in\nregistration handed a session-bound nonce to any page that could make the\nbrowser ask, and served nobody \u2014 someone already signed in is not looking at\na sign-in form.<\/li>\n<li>Removed: a decorative nonce on the settings tabs. It protected nothing \u2014 the\ntab was already chosen before it was checked \u2014 and expired, so a bookmarked\ntab URL stopped working after a day.<\/li>\n<li>Added: the plugin speaks five languages \u2014 French, Spanish, Simplified\nChinese, Japanese and Traditional Chinese (Taiwan).<\/li>\n<li>Changed: the footer of the plugin's own admin screens reports the state of\nthe site \u2014 authentication pages live, wp-login.php, registration \u2014 instead of\nasking for a review. Each fact links to the screen that changes it.<\/li>\n<li>Changed: the download is a third of the size, 3.31 MB down to 1.14 MB. The\nicon font shipped in three formats and browsers only ever requested one.<\/li>\n<li>Changed: the version is read from the plugin header alone. It used to be\nwritten a second time as a constant, and the two could disagree.<\/li>\n<li>Fixed: after an update, \"Create Page\" could do nothing. The admin script's\naddress carried the WordPress version instead of the plugin's, so browsers\nand caches kept serving the previous copy. Each file's address now changes\nwith the package.<\/li>\n<li>Fixed: the Elementor widget's Max Width setting was ignored at 380px and\nbelow.<\/li>\n<li>Changed: the admin screens no longer advertise the Elite plan. The\n\"WooCommerce Pages\" rows and the Elite card of the \"Unlock More with\nAttributes User Access\" section are held back \u2014 they promised a tier that\ndoes not ship yet. Nothing was deleted; both come back from one switch. The\nPro half of that section still appears on a site running Core alone.<\/li>\n<li>Maintenance: two .bak copies and a dead redefinition of the version constant\nin uninstall.php are gone.<\/li>\n<\/ul>\n\n<p>Everything else in this release is on the Pro side; see its changelog.<\/p>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Compatibility: tested with WordPress 7.0.<\/li>\n<li>Maintenance: regenerated all minified assets from original sources.<\/li>\n<li>Maintenance: improved asset loading consistency across admin and front end.<\/li>\n<\/ul>","raw_excerpt":"Custom login, registration and account pages with role-based redirects for WordPress. Developer-friendly; Pro adds 2FA, security and more.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/225459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=225459"}],"author":[{"embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/attributeswp"}],"wp:attachment":[{"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=225459"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=225459"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=225459"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=225459"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=225459"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=225459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}