This plugin allows admininstators to generate autologin links for their
WordPress website, logging in visitors under a certain user name. Administrators
can edit (generate and delete) autologin links for users, users can only view
their autologin links. Note that This plugin bypasses the standard
authentication method of wordpress via login and password and should only be
used if you understand the security issues mentioned below and on the
Once this plugin is activated, administrators can generate autologin links on
the edit profile administration pages for different users. Users can view their
autlogin links on their profile pages. Autologin links are of the form:
For more convenience it is possible since version 1.05 to generate login links
directly using the wordpress, site-preview functionality. When viewing the page
while being logged in as an administrator, the top-bar will show an extra item
“Auto-login link”. When pointing at the menu item, a dropdown list will list
all users for whom autologin links were generated on their profile pages. When
clicking on one of the users, a popup will open showing the link that will
automatically login a visitor as the selected user and bring him to the
Since autologin links are meant to be an OPEN way to login to
your website and can be viewed by users on their profile, it might be considered
an INSECURE plugin for WordPress. I did my best to make it as secure as possible
to fit my own needs, but this lead to some design choices which might not sit
well with all administrators:
Autologin codes are saved as plain text. This means that anyone who can
execute queries on the WordPress database (plugins, administrators, system
administrators) can obtain the autologin code for a certain user. I planned an
extension of this plugin where login codes are hashed. However, this again has
the disadvantage that noone can redisplay a once generated login link.
This is the most severe problem. For a full self-assesment of possible security
issues regarding this problem, please visit the
- Download autologin.zip
- Extract the contents of autologin.zip into /wp-contents/plugins
- Activate the plugin through the ‘Plugins’ menu in WordPress
Great Plugin beyond thoughts.
Works as described, a very useful plugin. Good job and thank you.
We were going to create a complicated SSO integration and this plugin has saved the day. Now we have the ability to generate custom links for each user to drop them right into the pages we want. Fantastic, works like a charm.
Thanks to the developer! This tool helps me a lot in my daily work.
This is an important plugin. It’s well made and works when installed. Hopefully a feature will be added to redirect users to a specific page once they’re logged in.
Contributors & Developers
“Autologin Links” is open source software. The following people have contributed to this plugin.Contributors
- First published version
- Fixed directory name to match conventions on wordpress.org
- Quick-fix was too quick, more inline directory strings changes were necessary
- Minor update of a line checking on invalid userid
- Major review checking if the code still is working with the newest version of
Wordpress which is should. I cannot find any vulnerabilities that are related
to this plugin except for the ones mentioned in the module description.
- New UI for administrators to generate autologin links for arbitrary pages
- Added screenshots
- Updated i10n files, however…
- TODO: …i10n seems to be broken at the moment (.mo file is ignored)
- Fixed long standing bug, not allowing one to update their profile page when
an autologin link was set for the user.