Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Beryl Admin Gate

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Beryl Admin Gate

By berylstudio
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Beryl Admin Gate connects a site to the Beryl Studio WP Admin Gate service. The service supplies user authorization, an authenticated proxy, short-lived signed access assertions and known-vulnerability matching. It is a substantive external service, not a license-validation server.

An account and the companion Chrome extension are required for proxy access. The service is currently available as a free beta; future paid subscriptions require separate agreement. Current availability and pricing: https://auth.beryl-studio.jp/. The plugin contains no subscription checkout, time-limited local functionality, remote PHP/JavaScript loader or private signing key. Local configuration checks and optional XML-RPC authentication control work without a service account.

Activation starts in connection-check mode (access restrictions OFF). Registration alone does not enable restrictions. After confirming a connection through the Chrome extension, an administrator can explicitly enable protection. WordPress’s own login is still required. Normal updates preserve the selected protection state; explicit reactivation/reinstallation resets restrictions to OFF while retaining pairing information.

This plugin limits access to administrative routes, including authenticated AJAX and REST requests. Public pages and unauthenticated AJAX remain available. Compatibility with membership plugins, front-end logged-in functionality, external editors, backup tools and other authentication plugins must be tested before enabling protection. It does not guarantee prevention of intrusion, scan all files, patch vulnerabilities or back up the site.

External services and data

The service provider is Beryl Studio. Service: https://auth.beryl-studio.jp/
Terms: https://auth.beryl-studio.jp/terms/
Privacy policy: https://auth.beryl-studio.jp/privacy-policy/
Setup: https://auth.beryl-studio.jp/gate-setup/
Support: https://beryl-susukino.jp/design/

No WP Admin Gate service request is made merely by activating the plugin. An administrator starts pairing with a registration code and explicitly confirms the external-service disclosure in Settings > WP Admin Gate.

  • Site registration: sends the one-time registration code, a random challenge and Cloudflare-use flag to https://auth.beryl-studio.jp/wp-json/wp-admin-gate/v1/site/register. The service verifies site ownership by retrieving the challenge proof and the WordPress login URL from this site’s temporary proof endpoint. Pairing stores the site’s domain, service public verification key and approved proxy/Cloudflare addresses locally.
  • Extension download: only after an administrator requests it, sends the site domain, random challenge and temporary proof key to https://auth.beryl-studio.jp/wp-json/wp-admin-gate/v1/extension-ticket. The service verifies site registration and returns a short-lived download URL. The plugin redirects to this URL; it never installs or executes extension code in WordPress. The administrator separately installs the companion extension in Chrome.
  • Automated vulnerability matching: after pairing, the service normally requests this site’s inventory daily through signed, expiring, replay-protected HTTPS requests. Responses contain the domain and WordPress/plugin/theme software type, slug, display name, version and active status. The service may request the protection mode and sends vulnerability findings back for local display. This endpoint does not return file contents, WordPress passwords, user lists or the local diagnostic report.
  • Vulnerability intelligence: the service retrieves Wordfence Intelligence data and matches inventory on its VPS. The customer plugin does not call Wordfence or contain a Wordfence API key. Information and attribution are displayed with the findings. Provider: https://www.wordfence.com/threat-intel/ ; terms: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/ ; privacy: https://www.wordfence.com/privacy-policy/ . Unpublished or unlisted issues cannot be detected.
  • Proxy traffic: when the companion extension connects, selected site administration traffic passes through the service VPS. This is separate from the inventory endpoint. The service necessarily processes connection metadata and forwarded requests; consult the service privacy policy before enabling it.
  • Manual local diagnostic: only when an administrator clicks the diagnostic button, WordPress’s own update functions contact api.wordpress.org for core/plugin/theme update checks. The plugin also performs up to five unauthenticated HTTPS GET requests to its own site to inspect public responses. Standard WordPress update requests may include software inventory and site/server details. WordPress.org privacy: https://wordpress.org/about/privacy/ . Results remain on this WordPress site.

Local records and removal

The plugin records login success/failure (submitted username and time) and update events locally, retaining the latest 100 events. These are visible to administrators in the security report and are not included in the service inventory. Stored pairing, settings and reports remain when the plugin is deactivated. Removing the plugin through WordPress deletes its options and temporary challenges from that installation. Deletion does not cancel a service contract or remove the service-side site record; manage those separately in the service account.

Requirements

PHP 8.1 or later with OpenSSL and mbstring; HTTPS and working WordPress REST API for pairing. A single WordPress installation/site is supported; multisite network activation is not supported in this release. Test Cloudflare/WAF rules, custom login URLs and other security plugins before enabling access restrictions.

Installation

  1. Install and activate Beryl Admin Gate. Access restrictions start OFF.
  2. Open Settings > WP Admin Gate and read the external-service disclosure.
  3. Register a service account and your site at https://auth.beryl-studio.jp/ ; obtain its registration code.
  4. Paste the code, confirm the disclosure and register this site. Select Cloudflare only if used.
  5. Download the companion Chrome extension from this registered site’s plugin settings. Extract the ZIP, enable Chrome Developer mode and load the extracted extension folder.
  6. Sign in to the extension with your service account, connect, and open the site’s actual login/admin URL. Sign in to WordPress separately.
  7. Confirm the extension connection in plugin settings, then enable access restrictions. Verify both permitted and denied access in separate browsers.

FAQ

Does it make my entire website secure?

No. It controls administrative access paths and provides limited configuration checks and known-vulnerability findings. Keep WordPress, themes, plugins, credentials and recovery procedures maintained.

What if I use SiteGuard or a custom login URL?

Pairing reports the URL returned by WordPress’s wp_login_url(). Test that the extension opens the actual custom URL and that direct access is denied after protection is enabled. Compatibility with every URL-rewriting plugin is not guaranteed.

What if the service or proxy is unavailable?

Protected administration may be unavailable. Use FTP or your host file manager to rename wp-content/plugins/beryl-admin-gate, which disables this plugin. Keep access to hosting tools available independently. Reactivation starts in connection-check mode; explicitly verify before enabling restrictions again.

What does the XML-RPC option disable?

It disables authenticated XML-RPC methods through WordPress’s xmlrpc_enabled filter. External posting applications or integrations that use those methods may stop working. It does not disable pingbacks or override restrictions imposed by another plugin when switched off.

Does the Chrome extension have to be in an extension store?

The current companion extension is privately distributed to registered sites through plugin settings. The WordPress plugin itself does not install browser software.

How do I stop inventory sharing?

Deactivate the plugin to stop its service endpoints and restrictions. Remove the site from your service account as well. Merely switching protection OFF retains pairing and automated inventory checks.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Beryl Admin Gate” is open source software. The following people have contributed to this plugin.

Contributors
  • berylstudio

Translate “Beryl Admin Gate” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

0.6.0

  • Prepare readable source distribution for WordPress.org review.
  • Add plugin metadata, GPL license, external-service and data disclosures.
  • Require disclosure confirmation for new pairing and migration.
  • Limit status notices to this plugin’s settings screen.
  • Remove local records when the plugin is deleted through WordPress.

0.5.8

  • Explicit activation starts in connection-check mode while preserving pairing; ordinary updates keep protection settings.

Meta

  • Version 0.6.1
  • Last updated 18 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.0 or higher
  • Tested up to 7.1.3
  • PHP version 8.1 or higher
  • Tags
    access-controlloginproxysecurity
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • berylstudio

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry