{"id":346795,"date":"2026-07-30T15:48:17","date_gmt":"2026-07-30T15:48:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/pixelhunter-social-login\/"},"modified":"2026-07-30T15:47:42","modified_gmt":"2026-07-30T15:47:42","slug":"pixelhunter-social-login","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/pixelhunter-social-login\/","author":21140199,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.4.2","stable_tag":"0.4.2","tested":"7.0.2","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"PixelHunter Social Login","header_author":"Miguel Carneiro","header_description":"Google and Microsoft login\/registration for WooCommerce (OAuth 2.0 \/ OpenID Connect) \u2014 self-contained, no third-party services.","assets_banners_color":"151516","last_updated":"2026-07-30 15:47:42","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/pixelhunter-social-login\/","header_author_uri":"https:\/\/pixelhunter.pt","rating":0,"author_block_rating":0,"active_installs":0,"downloads":32,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.4.2":{"tag":"0.4.2","author":"pixelhunter","date":"2026-07-30 15:47:42"}},"upgrade_notice":{"0.4.0":"<p>The Redirect URI changed. After updating, copy the new one from WooCommerce \u2192 Social Login into the Google Cloud Console and the Azure portal, or sign-in will fail. Settings and linked accounts are preserved.<\/p>","0.3.3":"<p>Screenshots now show as images in the plugin&#039;s &quot;View Details&quot; screen. No functional changes.<\/p>","0.3.2":"<p>Adds full plugin details (description, changelog, screenshots) to the WordPress &quot;View Details&quot; screen. No functional changes.<\/p>","0.3.1":"<p>Enables one-click updates straight from the Plugins screen via GitHub Releases.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3628865,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3628865,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3628865,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3628865,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.4.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3628865,"resolution":"1","location":"assets","locale":"","width":1199,"height":1008},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3628865,"resolution":"2","location":"assets","locale":"","width":1456,"height":840},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3628865,"resolution":"3","location":"assets","locale":"","width":1455,"height":840}},"screenshots":{"1":"Google and Microsoft buttons on the WooCommerce login\/register form (light and dark themes, responsive).","2":"Admin settings under WooCommerce \u2192 Social Login \u2014 Google tab with step-by-step guide, ready-to-copy Redirect URI, and live status.","3":"Admin settings \u2014 Microsoft tab (Azure setup guide and secret-expiry note)."}},"plugin_section":[],"plugin_tags":[150,602,3883,2061,286],"plugin_category":[38,45],"plugin_contributors":[273873],"plugin_business_model":[],"class_list":["post-346795","plugin","type-plugin","status-publish","hentry","plugin_tags-google","plugin_tags-login","plugin_tags-microsoft","plugin_tags-oauth","plugin_tags-woocommerce","plugin_category-authentication","plugin_category-ecommerce","plugin_contributors-pixelhunter","plugin_committers-pixelhunter"],"banners":{"banner":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/banner-772x250.png?rev=3628865","banner_2x":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/banner-1544x500.png?rev=3628865","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/icon-128x128.png?rev=3628865","icon_2x":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/icon-256x256.png?rev=3628865","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/screenshot-1.png?rev=3628865","caption":"Google and Microsoft buttons on the WooCommerce login\/register form (light and dark themes, responsive)."},{"src":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/screenshot-2.png?rev=3628865","caption":"Admin settings under WooCommerce \u2192 Social Login \u2014 Google tab with step-by-step guide, ready-to-copy Redirect URI, and live status."},{"src":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/screenshot-3.png?rev=3628865","caption":"Admin settings \u2014 Microsoft tab (Azure setup guide and secret-expiry note)."}],"raw_content":"<!--section=description-->\n<p>Login and registration with <strong>Google<\/strong> and <strong>Microsoft<\/strong> (personal accounts: Hotmail, Outlook.com, Live) for WooCommerce stores, via <strong>OAuth 2.0 \/ OpenID Connect<\/strong> \u2014 self-contained, with no third-party plugins or intermediary services. Customer credentials never pass through the store: authentication happens at Google\/Microsoft and the plugin only cryptographically validates the result.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>Two providers, one architecture<\/strong> \u2014 every provider-specific fact (endpoints, claim policy, branding) lives in a single registry; the rest of the code is provider-agnostic. Adding a third provider is adding one registry entry.<\/li>\n<li><strong>Automatic account creation<\/strong> \u2014 the first login creates a WooCommerce customer (role <code>customer<\/code>) with a strong random password.<\/li>\n<li><strong>Secure linking of existing accounts<\/strong> \u2014 if the email already has a store account, the plugin does <strong>not<\/strong> log in directly: it asks for the password once to prove ownership, and only then links the external identity (prevents account takeover by email).<\/li>\n<li><strong>The same email on both providers lands on the same WP account<\/strong> \u2014 linked identities are stored in distinct per-provider meta.<\/li>\n<li><strong>Full <code>id_token<\/code> validation<\/strong> \u2014 signature against the provider's JWKS (with cache), <code>iss<\/code>, <code>aud<\/code>, <code>exp<\/code>, <code>nonce<\/code>, and per-provider <code>email_verified<\/code> policy.<\/li>\n<li><strong>CSRF protection<\/strong> \u2014 single-use <code>state<\/code> + <code>nonce<\/code> in a transient with an <code>HttpOnly<\/code>\/<code>SameSite=Lax<\/code> cookie.<\/li>\n<li><strong>Secrets outside the database (optional, recommended)<\/strong> \u2014 constants in <code>wp-config.php<\/code> take priority and lock the admin field.<\/li>\n<li><strong>Organized admin<\/strong> \u2014 page under WooCommerce \u2192 Social Login with per-provider tabs, a step-by-step guide with deep links to the consoles, a ready-to-copy Redirect URI, and live status.<\/li>\n<li><strong>Accessible, responsive buttons<\/strong> \u2014 side by side when there's width, stacked when there isn't; short labels with full <code>aria-label<\/code>; light\/dark themes.<\/li>\n<li><strong>No runtime dependencies beyond <code>firebase\/php-jwt<\/code><\/strong> (vendored in the repo \u2014 the plugin installs by copy, with no <code>composer install<\/code>).<\/li>\n<\/ul>\n\n<h4>How it works<\/h4>\n\n<p>The customer authenticates <strong>at the provider<\/strong> (the store never sees the password); the plugin verifies the signed <code>id_token<\/code> (JWKS), validates the claims (<code>iss<\/code> \/ <code>aud<\/code> \/ <code>exp<\/code> \/ <code>nonce<\/code> \/ email), and resolves the account:<\/p>\n\n<ul>\n<li>Identity already linked (<code>sub<\/code> known) \u2192 immediate login<\/li>\n<li>New email \u2192 creates a WooCommerce customer + links the identity + login<\/li>\n<li>Email already exists, no linked identity \u2192 asks for password login once and links on success<\/li>\n<li>Email not verified at the provider \u2192 rejected with a message to the customer<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin is an interface to the sign-in services of Google and Microsoft. It contacts them only when you, the site administrator, enable and configure a provider, and only while a visitor is actively signing in with that provider. There is no telemetry, no analytics, and no data is ever sent to PixelHunter or to any other third party.<\/p>\n\n<h4>Google Sign-In (used only when the Google provider is enabled)<\/h4>\n\n<ul>\n<li><code>accounts.google.com<\/code> \u2014 the visitor's browser is redirected here to sign in. The request carries the Client ID you configured, the redirect URI of your site, the requested scopes (<code>openid email profile<\/code>), and a single-use <code>state<\/code>\/<code>nonce<\/code>. The visitor enters their credentials <strong>at Google<\/strong>; the store never sees them.<\/li>\n<li><code>oauth2.googleapis.com<\/code> \u2014 server-to-server exchange of the authorization code for an <code>id_token<\/code>. Sends the Client ID, the Client Secret, the authorization code, and the redirect URI.<\/li>\n<li><code>www.googleapis.com<\/code> \u2014 fetches Google's public signing keys (JWKS) to verify the <code>id_token<\/code> signature. No site or visitor data is sent; the response is cached.<\/li>\n<\/ul>\n\n<p>Data received back from Google and stored on your site: the account identifier (<code>sub<\/code>), email address, name, and the <code>email_verified<\/code> flag. The <code>sub<\/code> is stored as user meta so the account can be recognised on the next sign-in.<\/p>\n\n<p>Google terms of service: https:\/\/policies.google.com\/terms \u2014 Google privacy policy: https:\/\/policies.google.com\/privacy<\/p>\n\n<h4>Microsoft identity platform (used only when the Microsoft provider is enabled)<\/h4>\n\n<ul>\n<li><code>login.microsoftonline.com<\/code> \u2014 the same three roles as above (visitor sign-in redirect, code-for-token exchange, and JWKS key fetch), against the <code>consumers<\/code> tenant for personal Microsoft accounts.<\/li>\n<\/ul>\n\n<p>Data received back from Microsoft and stored on your site: the account identifier (<code>sub<\/code>), email address, and name.<\/p>\n\n<p>Microsoft services agreement: https:\/\/www.microsoft.com\/servicesagreement \u2014 Microsoft privacy statement: https:\/\/privacy.microsoft.com\/privacystatement<\/p>\n\n<!--section=installation-->\n<ol>\n<li>In wp-admin: <strong>Plugins \u2192 Add New<\/strong>, search for \"PixelHunter Social Login\", then <strong>Install Now<\/strong>. The <code>vendor\/<\/code> directory is bundled \u2014 no <code>composer install<\/code> needed.<\/li>\n<li>Activate the plugin in Plugins.<\/li>\n<li>Configure under <strong>WooCommerce \u2192 Social Login<\/strong> \u2014 each tab has the step-by-step guide for its console and the ready-to-copy Redirect URI.<\/li>\n<\/ol>\n\n<p>The buttons appear automatically on the WooCommerce login and register forms (<code>woocommerce_login_form_start<\/code> \/ <code>woocommerce_register_form_start<\/code>). No theme changes needed.<\/p>\n\n<p>You bring your own free OAuth credentials: Google Cloud Console and\/or the Azure portal.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20store%20ever%20see%20the%20customer%27s%20google%2Fmicrosoft%20password%3F\"><h3>Does the store ever see the customer's Google\/Microsoft password?<\/h3><\/dt>\n<dd><p>No. Authentication happens entirely at the provider. The plugin only receives and cryptographically verifies a signed <code>id_token<\/code>.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20the%20email%20already%20has%20an%20account%20in%20the%20store%3F\"><h3>What happens if the email already has an account in the store?<\/h3><\/dt>\n<dd><p>The plugin does not log in directly. It requires a one-time password login to prove ownership before linking the external identity, which prevents account takeover by email address.<\/p><\/dd>\n<dt id=\"can%20i%20keep%20the%20client%20secrets%20out%20of%20the%20database%3F\"><h3>Can I keep the client secrets out of the database?<\/h3><\/dt>\n<dd><p>Yes, and it's recommended. Define the constants in <code>wp-config.php<\/code>; they take priority over the admin fields and lock them.<\/p><\/dd>\n<dt id=\"why%20is%20the%20%60email_verified%60%20policy%20different%20for%20microsoft%3F\"><h3>Why is the `email_verified` policy different for Microsoft?<\/h3><\/dt>\n<dd><p>Google emits the <code>email_verified<\/code> claim and the plugin requires <code>true<\/code>. Microsoft personal accounts (tenant <code>consumers<\/code>) do not emit the claim \u2014 the email is that of the Microsoft account itself \u2014 so its absence is accepted <strong>only<\/strong> for Microsoft, and the <code>iss<\/code> is validated against the fixed personal-accounts tenant GUID. An explicit <code>email_verified=false<\/code> is always rejected, whatever the source.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.4.2<\/h4>\n\n<ul>\n<li>First release from the WordPress.org Plugin Directory.<\/li>\n<li>Added the <code>Requires Plugins: woocommerce<\/code> header: the plugin only hooks into the WooCommerce login and registration forms, so WordPress now refuses to activate it without WooCommerce instead of activating and doing nothing.<\/li>\n<\/ul>\n\n<h4>0.4.1<\/h4>\n\n<ul>\n<li>The Client Secret is no longer passed through <code>sanitize_text_field()<\/code> when saved: it is an opaque credential and sanitizing could corrupt valid secrets. Same for the OAuth authorization code on the callback.<\/li>\n<li>Translation files are no longer bundled; translations come from translate.wordpress.org.<\/li>\n<\/ul>\n\n<h4>0.4.0<\/h4>\n\n<ul>\n<li>Prepared for the WordPress.org Plugin Directory: plugin folder, main file and text domain renamed to <code>pixelhunter-social-login<\/code>; the bundled update checker and the <code>Update URI<\/code> header were removed (updates now come from the directory).<\/li>\n<li><strong>Breaking:<\/strong> the Redirect URI changed to <code>\/wp-json\/pixelhunter-social-login\/v1\/\u2026<\/code>. Re-copy it from <strong>WooCommerce \u2192 Social Login<\/strong> into the Google Cloud Console and the Azure portal, otherwise sign-in fails with <code>redirect_uri_mismatch<\/code>.<\/li>\n<li>Added an \"External services\" section documenting every request made to Google and Microsoft and the data involved.<\/li>\n<li>No change to stored settings or to already-linked customer accounts.<\/li>\n<\/ul>\n\n<h4>0.3.3<\/h4>\n\n<ul>\n<li>Screenshots now render as images in the \"View Details\" modal. WordPress's readme parser strips <code>&lt;img&gt;<\/code> from the screenshots section, so the images are injected after parsing (from the repo assets) instead.<\/li>\n<\/ul>\n\n<h4>0.3.2<\/h4>\n\n<ul>\n<li>Plugin metadata: author and plugin URI in the header, and a WordPress.org-format <code>readme.txt<\/code> that populates the \"View Details\" modal (Description, Installation, FAQ, Changelog).<\/li>\n<li>Screenshots of the login buttons and the admin settings.<\/li>\n<\/ul>\n\n<h4>0.3.1<\/h4>\n\n<ul>\n<li>Auto-update via GitHub Releases (Plugin Update Checker): the release tag is compared against the plugin's <code>Version:<\/code> header and offered on the normal Plugins \u2192 Updates screen. <code>Update URI: false<\/code> keeps wordpress.org from hijacking the slug.<\/li>\n<\/ul>\n\n<h4>0.3.0<\/h4>\n\n<ul>\n<li>Canonical WordPress i18n: English source strings with bundled pt_PT translation.<\/li>\n<li>Simplified account-linking decision logic.<\/li>\n<\/ul>\n\n<h4>0.2.1<\/h4>\n\n<ul>\n<li>Multi-provider: generalized from Google-only to Google + Microsoft (personal accounts) on one provider-agnostic architecture.<\/li>\n<li>Layout\/CSS refinements to the buttons.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>Fire <code>wp_login<\/code> on OAuth login; JWT clock-skew leeway; stored admin secret masked in the UI.<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li><code>box-sizing<\/code> fix on the buttons; setup-instruction updates.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release: OAuth <code>\/start<\/code> and <code>\/callback<\/code> endpoints, single-use <code>state<\/code>\/<code>nonce<\/code> CSRF protection, full <code>id_token<\/code> claim validation against the provider JWKS, secure account lookup\/create\/link, the Google button via WooCommerce hooks, and the admin settings page with setup guide and live status.<\/li>\n<\/ul>","raw_excerpt":"Google and Microsoft login\/registration for WooCommerce (OAuth 2.0 \/ OpenID Connect) \u2014 self-contained, no third-party services.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/346795","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=346795"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/pixelhunter"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=346795"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=346795"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=346795"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=346795"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=346795"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=346795"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}