Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

EgyDevInfo Sign In with Google

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

EgyDevInfo Sign In with Google

By Egypt Web Developers – مُطَوِّرِي مِصْرَ
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Most “Sign in with Google” setups fail in the Google Cloud console, not in WordPress: a redirect URI pasted slightly wrong, an app left in “Testing” mode so real visitors are blocked, or a site moved to a new domain and login silently breaking. This plugin is built around fixing that.

A setup page that walks you through Google Cloud

  • Step-by-step instructions with direct links to the right Google Cloud pages.
  • The exact redirect URI and authorized domain for your site, each with a copy button.
  • Warnings for the common traps: publishing the app so it is not stuck in “Testing”, and why not to upload a logo (it triggers a brand verification review).
  • A Run test sign-in button that performs a real Google sign-in without logging you in, and explains any failure in plain language (wrong Client ID/Secret, redirect URI mismatch, server cannot reach Google).
  • If your site address changes (staging copy, new domain, http to https, www change), you get a clear notice with the new redirect URI to add in Google.

A button that keeps working on real sites

  • The button is a plain link that runs a server-side sign-in. It needs no JavaScript on your pages and carries no nonce, so full-page caching and JavaScript “delay/defer/combine” optimizers do not break it.
  • Works on the WordPress login and registration pages, the WooCommerce My Account login and registration forms, and the WooCommerce checkout for guests — both the classic checkout and the Checkout block.
  • A shortcode for anywhere else: [egydevinfo_siwg_button].
  • Light, dark and neutral styles following Google’s sign-in button guidelines. RTL-ready.

Careful account handling

  • Accounts are matched on Google’s permanent account ID, not the email address.
  • An existing account is linked automatically only when Google is authoritative for the email address (a verified Gmail or Google Workspace address). Anyone else logs in with their password once and clicks “Connect Google account”.
  • Administrators, editors and shop managers are never linked automatically unless you allow it.
  • ID tokens are checked for signature, issuer, audience, expiry and a one-time nonce; the sign-in uses a one-time state value bound to the visitor’s browser, plus PKCE.
  • New accounts follow your site’s registration settings (or your choice), and new users only ever get a role without back-end editing powers (Customer with WooCommerce).
  • Optional: restrict sign-in to your company’s Google Workspace domain.
  • Users can connect and disconnect Google from their profile or the WooCommerce “Account details” page.

External services

This plugin connects to Google’s sign-in service (Google Identity / OAuth 2.0) so visitors can sign in with their Google account. Nothing is sent to Google until a visitor clicks the button (or an administrator runs the test sign-in).

  • When the button is clicked, the visitor’s browser is sent to accounts.google.com with your Client ID, the redirect URI, and one-time security values.
  • After the visitor approves, your server sends the one-time authorization code, your Client ID and Client Secret to oauth2.googleapis.com and receives the visitor’s Google account ID, name and email address.
  • Your server downloads Google’s public signing keys from www.googleapis.com to verify the response (cached).

Google Terms of Service: https://policies.google.com/terms
Google Privacy Policy: https://policies.google.com/privacy
Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy

Privacy

The plugin stores the visitor’s Google account ID and email address as user meta so they can sign in again. It uses their name and email address to create an account when allowed. It does not store Google access tokens and never receives the visitor’s Google password. It adds suggested text to your site’s privacy policy guide. Uninstalling removes the stored Google links; user accounts are kept.

Screenshots

Installation

  1. Install and activate the plugin. You are taken straight to the setup wizard.
  2. Follow the wizard (about five minutes). Your site must use HTTPS — Google requires it.
  3. Afterwards, find the wizard again any time from Settings → Sign In with Google → Change credentials.

For agencies: you can define the credentials in wp-config.php instead of the database:

define( 'EGYDEVINFO_SIWG_CLIENT_ID', '...' );
define( 'EGYDEVINFO_SIWG_CLIENT_SECRET', '...' );

FAQ

Google says “Error 400: redirect_uri_mismatch”

The redirect URI in your Google OAuth client does not match your site. Reopen the setup wizard (Settings → Sign In with Google → Change credentials → Back to the OAuth client step), copy the redirect URI again, and paste it into “Authorized redirect URIs” exactly. It can take a few minutes for Google to apply the change.

Visitors see “Access blocked” but it works for me

Your Google app is still in “Testing” mode, where only listed test users can sign in. Open Google Auth Platform → Audience and click “Publish app”.

Does it work with page caching (LiteSpeed Cache, WP Rocket, etc.)?

The button is a plain link with no nonce and no JavaScript, so cached pages keep working. The sign-in endpoints themselves send no-cache headers. Please still test once on your live site after setup.

Does it work with the WooCommerce Checkout block?

Yes. The button is added above the Checkout block for guests, and above the classic checkout form on shortcode-based checkouts.

A customer already has an account with the same email. What happens?

If the address is a verified Gmail or Google Workspace address, the accounts are linked automatically and the customer is signed in. Otherwise, for safety, they are asked to log in with their password once and connect Google from their account page.

Can I use it for staff only / my company domain only?

Yes. Set “Allowed email domains” to your Google Workspace domain, and set “New accounts” to “Never” if staff accounts are created manually.

Does it support Facebook or X?

Not at the moment. This plugin focuses on Google only.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“EgyDevInfo Sign In with Google” is open source software. The following people have contributed to this plugin.

Contributors
  • Egypt Web Developers – مُطَوِّرِي مِصْرَ

Translate “EgyDevInfo Sign In with Google” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.1.2

  • Enhancement: redesigned the setup wizard — a connected step indicator (numbered circles, checkmarks for completed steps), a clearer required/optional badge on the Google Cloud field table, and a more polished card layout, shared with the simplified settings page.
  • Plugin Check: addressed all warnings/errors from a Plugin Check run (nonce-verification and input-sanitization notes on the credentials save handler, false-positive “offloaded content” flags on Google-domain placeholder/help text, and a false-positive unprefixed-constant flag on the required DONOTCACHEPAGE constant name).

1.1.1

  • Fix: a “Passing null to strip_tags()” PHP deprecation notice on activation/wp-admin, caused by hiding the setup wizard’s Dashboard menu entry with remove_submenu_page() — that also broke WordPress’s own page-title lookup for that page. The entry is now hidden with CSS instead, so the page stays properly registered.

1.1.0

  • New: a guided setup wizard opens automatically right after activation (also reachable any time from Settings → “Change credentials”), replacing the old numbered steps on the settings page.
  • Fix: Google Cloud’s client-creation page now shown with both fields in Google’s own order — “Authorized JavaScript origins” before “Authorized redirect URIs” — with a warning against pasting the redirect URI into the origins box, the single most common setup mistake.
  • Fix: the wizard’s first step now asks whether you already have a Google Cloud project for this site and skips straight to the OAuth client step if so, instead of assuming a blank-slate Google account.
  • Fix: “Run test sign-in” now returns to wherever it was launched from (the wizard or the settings page) instead of always landing on the settings page.
  • The settings page is now settings only (placement, accounts, button style); Client ID/Secret are managed from the wizard.

1.0.0

  • First release.

Meta

  • Version 1.1.2
  • Last updated 16 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.0 or higher
  • Tested up to 7.1.3
  • PHP version 7.4 or higher
  • Tags
    Google Loginloginoauthsocial loginwoocommerce
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • Egypt Web Developers – مُطَوِّرِي مِصْرَ

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry