Description
Membership sites lose revenue every day to shared accounts — one login passed around an office, posted in a group chat, or resold. This plugin limits account sharing using WordPress native session management (WP_Session_Tokens). No polling, no extra server load.
Three configurable strategies:
- Kick oldest (kick, default) — a new login instantly terminates all other sessions of that account. The old device is logged out on its next request. Smoothest experience, similar to single-device streaming policies.
- Exclusive online (deny) — while any device is active, new-device logins are rejected outright. Strictest mode.
- Device binding limit — each account can bind up to N devices (default 2), slots auto-release after X days (default 30). An anonymous device identifier cookie is set on first login.
More features:
- Heartbeat detection: every visit refreshes activity time (60-second write throttle, no slowdown)
- Admin exemption: administrators can bypass all restrictions
- Unbind tool: one click in the admin to clear a user’s device bindings and force all devices offline — perfect for device-change appeals
- Zero external dependencies: no third-party requests, all data stays in your database
The plugin interface is written in Chinese and fully internationalized (text domain: east115-account-guard). Translations for other languages are welcome via translate.wordpress.org.
Privacy
This plugin collects and transmits no personal data. The only data stored is an anonymous device-identifier cookie (eastacgu_device) in the browser and device binding timestamps in user meta. Uninstalling removes all settings and binding data.
Installation
- Upload and activate the plugin in the admin.
- Go to Settings – Prevent Account Sharing, pick a strategy and device limit.
- To handle device-change appeals, use the unbind tool at the bottom of the settings page.
FAQ
-
A member changed phones and is now locked out. What now?
-
Go to Settings – Prevent Account Sharing, enter the user’s ID or login name in the unbind tool, and clear their bindings. They log in again on the new device.
-
Yes. The device identifier lives in a browser cookie; clearing cookies, switching browsers, or incognito mode all register as new devices. This is the intended anti-sharing behavior. Legitimate users can be unbound by an admin.
-
Yes. One anonymous cookie named
eastacgu_device(random 32-character hex string, HttpOnly, one-year lifetime). It only distinguishes devices, contains no personal information, and is never sent to third parties. -
Will it slow down my site?
-
No. Heartbeat writes are throttled to once per 60 seconds per session; every check uses native WordPress sessions and user meta. No polling, no external requests.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“east115 Account Guard” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “east115 Account Guard” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.2.1
- Removed the Author URI header (connection to the site is restricted for some regions, which triggered a review error)
- Renamed all function/class/option/menu prefixes from
pas_to the uniqueeastacgu_prefix (previous prefix was too short and risked conflicts) - Added automatic migration of settings, device bindings, and device cookies from versions 1.2.0 and earlier
1.2.0
- Renamed to a distinctive name and slug: east115 Account Guard / east115-account-guard
- Removed load_plugin_textdomain() — translations auto-load for WordPress.org-hosted plugins since WP 4.6
1.1.0
- Added internationalization (i18n) — all strings translatable
- Added uninstall cleanup (uninstall.php)
- Added plugin header metadata
1.0.0
- Initial release: kick-oldest, device binding limit, concurrent denial, heartbeat detection, admin exemption, admin unbind tool
