Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

ESM Membership & Auth

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

ESM Membership & Auth

By SMBAforum
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

ESM Membership & Auth provides a complete front-end membership and authentication workflow for WordPress.

The plugin works independently on a standard WordPress installation. ESM Platform is not required for its primary membership and authentication features.

Standalone features include:

  • Front-end user registration.
  • Required and optional terms and consent handling.
  • Email OTP verification using the WordPress mail system.
  • WordPress user creation after successful registration.
  • Login and logout.
  • Username recovery by email.
  • WordPress-native password reset keys.
  • Profile access and editing.
  • Versioned consent evidence.
  • WordPress personal-data export and erasure integration.
  • Administrator-managed setup, settings, diagnostics, and shortcodes.

When ESM Platform Core is present, the plugin can operate through an optional compatibility/provider contract. Shadow mode leaves the existing Core authentication owner in place. External Provider mode can be enabled only after the required cutover gates pass. The plugin does not silently replace Core-owned authentication routes, the Participant ledger, My Page, Wallet, Rewards, Evaluation, or the site presentation shell.

Passive activation

Activation is intentionally passive. Installing, uploading, updating, or activating the plugin does not create membership pages or workflow tables, write operational defaults, schedule cleanup, change rewrite rules, connect to a remote service, or take ownership of an existing authentication page.

On a standalone WordPress site, site-changing setup occurs only after an administrator explicitly chooses Membership setup > Apply membership setup. Existing pages with compatible slugs are reused without overwriting their content; only missing plugin-owned membership pages are created.

Internationalization

English is the source language. The plugin uses the esm-membership-auth text domain and follows the WordPress site/user locale. Korean (ko_KR) is included for direct-install quality assurance, and the plugin remains compatible with WordPress.org language packs after publication.

Privacy

When standalone membership features are enabled, the plugin can process account registration data, email-verification state, mobile phone data entered for membership, and versioned consent evidence. Completed accounts are stored as normal WordPress users.

Temporary registration and verification records are cleaned on a bounded schedule after explicit setup. The plugin integrates with the WordPress personal-data exporter and eraser. Consent evidence may be retained in anonymized form so the site can preserve a record that a decision occurred without retaining direct account identifiers.

Site owners should update their privacy policy to describe the membership fields and retention rules they actually enable.

External services

The primary standalone registration and authentication workflow does not make direct outbound HTTP requests from this plugin.

Email is sent through WordPress wp_mail(). The transport used by wp_mail() depends on the site owner’s WordPress/mail configuration.

Optional ESM Connected mode delegates identity, Participant, and canonical mail ownership to the active ESM Platform Core contract. ESM Platform is not required for standalone operation, and this plugin does not silently enable that integration.

Source code

The distributed plugin contains human-readable PHP, JavaScript, and CSS source. First-party JavaScript and CSS are not minified, and no build step is required to inspect or modify the distributed source.

Installation

  1. Install and activate ESM Membership & Auth.
  2. Open ESM Membership & Auth > Dashboard. Activation itself has not changed the site.
  3. Open Membership setup and review the setup description.
  4. On a standalone WordPress site, choose Apply membership setup when you are ready. You may create or map the canonical membership pages during that explicit action.
  5. Replace the starter terms/privacy text with the site owner’s actual policies before opening registration to visitors.
  6. Test registration, OTP mail delivery, login, username recovery, and password reset.
  7. On an ESM Connected site, keep Shadow mode unless every required provider cutover gate passes.

FAQ

Does this plugin require ESM Platform?

No. Its primary membership and authentication features work on a standalone WordPress installation.

Does activation automatically create pages or database tables?

No. Activation is load-only. Site-changing setup is performed only after an administrator explicitly applies Membership setup.

Does it overwrite existing login or registration pages?

No. Explicit setup reuses compatible existing routes where possible and does not overwrite the content or ownership metadata of pages owned by another system.

How are registration emails sent?

Standalone authentication mail is sent through WordPress wp_mail(). Site administrators may use their normal WordPress SMTP or mail-delivery plugin.

Does this plugin create a separate WordPress member account table?

No. Completed standalone registrations create normal WordPress users in wp_users. Plugin-owned tables store bounded registration workflow data, verification state, consent evidence, and outbox records.

What happens when ESM Platform Core is active?

Shadow mode remains the default. External Provider mode is opt-in and runtime-gated. WordPress accounts remain in wp_users, while ESM Participant and connected ESM services remain owned by Core.

Does uninstall delete WordPress users?

No. WordPress users and Core-owned ESM data are never deleted by this plugin. Plugin-owned tables, options, and plugin-owned user meta are removed only when the administrator explicitly enables the uninstall deletion setting before uninstalling.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“ESM Membership & Auth” is open source software. The following people have contributed to this plugin.

Contributors
  • SMBAforum

Translate “ESM Membership & Auth” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.0.7

  • Updated the Membership product icon to the canonical ESM plugin-family symbol with the Membership indigo/violet product palette.
  • Added versioned icon cache-busting; no membership workflow or Activation Zero-Work behavior changed.

1.0.6

  • Lightweight packaging: optimized the runtime Membership product icon without changing its visual design.
  • Added package-size auditing while preserving the v1.0.5 Plugin Check remediation and Zero-Work activation behavior.

1.0.5

  • Removed remaining direct REQUEST_URI superglobal access and normalized request URI intake through filter_input() for Plugin Check cleanliness.
  • No functional change to routing, Activation Zero-Work, or membership ownership.

1.0.4

  • Plugin Check hardening: translators comments for placeholders, WordPress.org JIT translation loading, unique root namespace, nonce/input hygiene, sanitized server/query inputs, and documented custom-table exceptions.
  • No functional change to the Activation Zero-Work contract or membership workflow ownership.

1.0.3

  • Increased administrator typography scale and text contrast across dashboard, workspace tabs, cards, forms, tables, status text, and help copy for improved readability.
  • Bumped admin asset cache key to ui5.

1.0.2

  • Redesigned the WordPress admin workspace to match the ESM public-plugin visual system.
  • Moved the full-color Membership hero banner to the top of every plugin admin screen.
  • Added large in-content workspace navigation and page headings.
  • Moved the Zero-Work activation notice directly below the dashboard hero for first-run visibility.
  • Refined dashboard status cards and refreshed admin asset cache versioning.

1.0.1

  • First WordPress.org submission candidate.
  • Activation Golden Lock: install, update, activation, and first reads perform no operational setup.
  • Explicit administrator-owned Membership setup for schema, defaults, cleanup scheduling, and optional standalone page provisioning.
  • Standalone registration with terms/consent, email OTP, WordPress account creation, login, logout, username recovery, password reset, and profile editing.
  • Optional ESM Connected Shadow/External provider boundary with runtime fallback to Core.
  • ESM public-plugin admin design system with Membership Indigo identity.
  • WordPress locale-based internationalization and complete Korean QA target.
  • Privacy exporter/eraser and privacy-policy helper content.
  • Human-readable source and WordPress.org update-authority compliance.

Meta

  • Version 1.0.7
  • Last updated 2 days ago
  • Active installations Fewer than 10
  • WordPress version 6.4 or higher
  • Tested up to 7.1.3
  • PHP version 7.4 or higher
  • Tags
    authenticationconsentloginmembershipregistration
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • SMBAforum

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry