{"id":346795,"date":"2026-07-30T15:48:17","date_gmt":"2026-07-30T15:48:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/pixelhunter-social-login\/"},"modified":"2026-08-02T12:15:00","modified_gmt":"2026-08-02T12:15:00","slug":"pixelhunter-social-login","status":"publish","type":"plugin","link":"https:\/\/sw.wordpress.org\/plugins\/pixelhunter-social-login\/","author":21140199,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.4.3","stable_tag":"0.4.3","tested":"7.0.2","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"PixelHunter Social Login","header_author":"Miguel Carneiro","header_description":"Google and Microsoft login\/registration for WooCommerce (OAuth 2.0 \/ OpenID Connect) \u2014 self-contained, no third-party services.","assets_banners_color":"151516","last_updated":"2026-08-02 12:15:00","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/pixelhunter-social-login\/","header_author_uri":"https:\/\/pixelhunter.pt","rating":0,"author_block_rating":0,"active_installs":0,"downloads":83,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.4.2":{"tag":"0.4.2","author":"pixelhunter","date":"2026-07-30 15:47:42"},"0.4.3":{"tag":"0.4.3","author":"pixelhunter","date":"2026-08-02 12:15:00"}},"upgrade_notice":{"0.4.3":"<p>Fixes sign-in failing permanently on hosts that force browser caching of HTML\/PHP. Recommended for every store. No settings change.<\/p>","0.4.0":"<p>The Redirect URI changed. After updating, copy the new one from WooCommerce \u2192 Social Login into the Google Cloud Console and the Azure portal, or sign-in will fail. Settings and linked accounts are preserved.<\/p>","0.3.3":"<p>Screenshots now show as images in the plugin&#039;s &quot;View Details&quot; screen. No functional changes.<\/p>","0.3.2":"<p>Adds full plugin details (description, changelog, screenshots) to the WordPress &quot;View Details&quot; screen. No functional changes.<\/p>","0.3.1":"<p>Enables one-click updates straight from the Plugins screen via GitHub Releases.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3628865,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3628865,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3628865,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3628865,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.4.2","0.4.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3628865,"resolution":"1","location":"assets","locale":"","width":1199,"height":1008},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3628865,"resolution":"2","location":"assets","locale":"","width":1456,"height":840},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3628865,"resolution":"3","location":"assets","locale":"","width":1455,"height":840}},"screenshots":{"1":"Google and Microsoft buttons on the WooCommerce login\/register form (light and dark themes, responsive).","2":"Admin settings under WooCommerce \u2192 Social Login \u2014 Google tab with step-by-step guide, ready-to-copy Redirect URI, and live status.","3":"Admin settings \u2014 Microsoft tab (Azure setup guide and secret-expiry note)."}},"plugin_section":[],"plugin_tags":[150,602,3883,2061,286],"plugin_category":[38,45],"plugin_contributors":[273873],"plugin_business_model":[],"class_list":["post-346795","plugin","type-plugin","status-publish","hentry","plugin_tags-google","plugin_tags-login","plugin_tags-microsoft","plugin_tags-oauth","plugin_tags-woocommerce","plugin_category-authentication","plugin_category-ecommerce","plugin_contributors-pixelhunter","plugin_committers-pixelhunter"],"banners":{"banner":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/banner-772x250.png?rev=3628865","banner_2x":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/banner-1544x500.png?rev=3628865","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/icon-128x128.png?rev=3628865","icon_2x":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/icon-256x256.png?rev=3628865","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/screenshot-1.png?rev=3628865","caption":"Google and Microsoft buttons on the WooCommerce login\/register form (light and dark themes, responsive)."},{"src":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/screenshot-2.png?rev=3628865","caption":"Admin settings under WooCommerce \u2192 Social Login \u2014 Google tab with step-by-step guide, ready-to-copy Redirect URI, and live status."},{"src":"https:\/\/ps.w.org\/pixelhunter-social-login\/assets\/screenshot-3.png?rev=3628865","caption":"Admin settings \u2014 Microsoft tab (Azure setup guide and secret-expiry note)."}],"raw_content":"<!--section=description-->\n<p>Login and registration with <strong>Google<\/strong> and <strong>Microsoft<\/strong> (personal accounts: Hotmail, Outlook.com, Live) for WooCommerce stores, via <strong>OAuth 2.0 \/ OpenID Connect<\/strong> \u2014 self-contained, with no third-party plugins or intermediary services. Customer credentials never pass through the store: authentication happens at Google\/Microsoft and the plugin only cryptographically validates the result.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>Two providers, one architecture<\/strong> \u2014 every provider-specific fact (endpoints, claim policy, branding) lives in a single registry; the rest of the code is provider-agnostic. Adding a third provider is adding one registry entry.<\/li>\n<li><strong>Automatic account creation<\/strong> \u2014 the first login creates a WooCommerce customer (role <code>customer<\/code>) with a strong random password.<\/li>\n<li><strong>Secure linking of existing accounts<\/strong> \u2014 if the email already has a store account, the plugin does <strong>not<\/strong> log in directly: it asks for the password once to prove ownership, and only then links the external identity (prevents account takeover by email).<\/li>\n<li><strong>The same email on both providers lands on the same WP account<\/strong> \u2014 linked identities are stored in distinct per-provider meta.<\/li>\n<li><strong>Full <code>id_token<\/code> validation<\/strong> \u2014 signature against the provider's JWKS (with cache), <code>iss<\/code>, <code>aud<\/code>, <code>exp<\/code>, <code>nonce<\/code>, and per-provider <code>email_verified<\/code> policy.<\/li>\n<li><strong>CSRF protection<\/strong> \u2014 single-use <code>state<\/code> + <code>nonce<\/code> in a transient with an <code>HttpOnly<\/code>\/<code>SameSite=Lax<\/code> cookie.<\/li>\n<li><strong>Secrets outside the database (optional, recommended)<\/strong> \u2014 constants in <code>wp-config.php<\/code> take priority and lock the admin field.<\/li>\n<li><strong>Organized admin<\/strong> \u2014 page under WooCommerce \u2192 Social Login with per-provider tabs, a step-by-step guide with deep links to the consoles, a ready-to-copy Redirect URI, and live status.<\/li>\n<li><strong>Accessible, responsive buttons<\/strong> \u2014 side by side when there's width, stacked when there isn't; short labels with full <code>aria-label<\/code>; light\/dark themes.<\/li>\n<li><strong>No runtime dependencies beyond <code>firebase\/php-jwt<\/code><\/strong> (vendored in the repo \u2014 the plugin installs by copy, with no <code>composer install<\/code>).<\/li>\n<\/ul>\n\n<h4>How it works<\/h4>\n\n<p>The customer authenticates <strong>at the provider<\/strong> (the store never sees the password); the plugin verifies the signed <code>id_token<\/code> (JWKS), validates the claims (<code>iss<\/code> \/ <code>aud<\/code> \/ <code>exp<\/code> \/ <code>nonce<\/code> \/ email), and resolves the account:<\/p>\n\n<ul>\n<li>Identity already linked (<code>sub<\/code> known) \u2192 immediate login<\/li>\n<li>New email \u2192 creates a WooCommerce customer + links the identity + login<\/li>\n<li>Email already exists, no linked identity \u2192 asks for password login once and links on success<\/li>\n<li>Email not verified at the provider \u2192 rejected with a message to the customer<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin is an interface to the sign-in services of Google and Microsoft. It contacts them only when you, the site administrator, enable and configure a provider, and only while a visitor is actively signing in with that provider. There is no telemetry, no analytics, and no data is ever sent to PixelHunter or to any other third party.<\/p>\n\n<h4>Google Sign-In (used only when the Google provider is enabled)<\/h4>\n\n<ul>\n<li><code>accounts.google.com<\/code> \u2014 the visitor's browser is redirected here to sign in. The request carries the Client ID you configured, the redirect URI of your site, the requested scopes (<code>openid email profile<\/code>), and a single-use <code>state<\/code>\/<code>nonce<\/code>. The visitor enters their credentials <strong>at Google<\/strong>; the store never sees them.<\/li>\n<li><code>oauth2.googleapis.com<\/code> \u2014 server-to-server exchange of the authorization code for an <code>id_token<\/code>. Sends the Client ID, the Client Secret, the authorization code, and the redirect URI.<\/li>\n<li><code>www.googleapis.com<\/code> \u2014 fetches Google's public signing keys (JWKS) to verify the <code>id_token<\/code> signature. No site or visitor data is sent; the response is cached.<\/li>\n<\/ul>\n\n<p>Data received back from Google and stored on your site: the account identifier (<code>sub<\/code>), email address, name, and the <code>email_verified<\/code> flag. The <code>sub<\/code> is stored as user meta so the account can be recognised on the next sign-in.<\/p>\n\n<p>Google terms of service: https:\/\/policies.google.com\/terms \u2014 Google privacy policy: https:\/\/policies.google.com\/privacy<\/p>\n\n<h4>Microsoft identity platform (used only when the Microsoft provider is enabled)<\/h4>\n\n<ul>\n<li><code>login.microsoftonline.com<\/code> \u2014 the same three roles as above (visitor sign-in redirect, code-for-token exchange, and JWKS key fetch), against the <code>consumers<\/code> tenant for personal Microsoft accounts.<\/li>\n<\/ul>\n\n<p>Data received back from Microsoft and stored on your site: the account identifier (<code>sub<\/code>), email address, and name.<\/p>\n\n<p>Microsoft services agreement: https:\/\/www.microsoft.com\/servicesagreement \u2014 Microsoft privacy statement: https:\/\/privacy.microsoft.com\/privacystatement<\/p>\n\n<!--section=installation-->\n<ol>\n<li>In wp-admin: <strong>Plugins \u2192 Add New<\/strong>, search for \"PixelHunter Social Login\", then <strong>Install Now<\/strong>. The <code>vendor\/<\/code> directory is bundled \u2014 no <code>composer install<\/code> needed.<\/li>\n<li>Activate the plugin in Plugins.<\/li>\n<li>Configure under <strong>WooCommerce \u2192 Social Login<\/strong> \u2014 each tab has the step-by-step guide for its console and the ready-to-copy Redirect URI.<\/li>\n<\/ol>\n\n<p>The buttons appear automatically on the WooCommerce login and register forms (<code>woocommerce_login_form_start<\/code> \/ <code>woocommerce_register_form_start<\/code>). No theme changes needed.<\/p>\n\n<p>You bring your own free OAuth credentials: Google Cloud Console and\/or the Azure portal.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20store%20ever%20see%20the%20customer%27s%20google%2Fmicrosoft%20password%3F\"><h3>Does the store ever see the customer's Google\/Microsoft password?<\/h3><\/dt>\n<dd><p>No. Authentication happens entirely at the provider. The plugin only receives and cryptographically verifies a signed <code>id_token<\/code>.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20the%20email%20already%20has%20an%20account%20in%20the%20store%3F\"><h3>What happens if the email already has an account in the store?<\/h3><\/dt>\n<dd><p>The plugin does not log in directly. It requires a one-time password login to prove ownership before linking the external identity, which prevents account takeover by email address.<\/p><\/dd>\n<dt id=\"can%20i%20keep%20the%20client%20secrets%20out%20of%20the%20database%3F\"><h3>Can I keep the client secrets out of the database?<\/h3><\/dt>\n<dd><p>Yes, and it's recommended. Define the constants in <code>wp-config.php<\/code>; they take priority over the admin fields and lock them.<\/p><\/dd>\n<dt id=\"why%20is%20the%20%60email_verified%60%20policy%20different%20for%20microsoft%3F\"><h3>Why is the `email_verified` policy different for Microsoft?<\/h3><\/dt>\n<dd><p>Google emits the <code>email_verified<\/code> claim and the plugin requires <code>true<\/code>. Microsoft personal accounts (tenant <code>consumers<\/code>) do not emit the claim \u2014 the email is that of the Microsoft account itself \u2014 so its absence is accepted <strong>only<\/strong> for Microsoft, and the <code>iss<\/code> is validated against the fixed personal-accounts tenant GUID. An explicit <code>email_verified=false<\/code> is always rejected, whatever the source.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.4.3<\/h4>\n\n<ul>\n<li><strong>Fixed:<\/strong> sign-in could fail permanently on hosts that force browser caching of HTML\/PHP (WP-Optimize, LiteSpeed Cache, W3TC and similar). The browser replayed a cached redirect carrying an expired one-time state, so every attempt ended in \"Signing in failed\". The sign-in URL is now unique per page render and the OAuth routes send no-cache headers.<\/li>\n<li>Credential fields warn when the value does not match the provider's known format (for example, the Azure \"Secret ID\" pasted into the Client Secret field, which should be the secret's \"Value\"). The Status panel now distinguishes \"filled in\" from \"correct format\" instead of showing a green check for any non-empty value.<\/li>\n<li>Clearer sign-in error messages: an expired session now says so and tells the customer to try again from the account page, instead of a generic failure notice.<\/li>\n<\/ul>\n\n<h4>0.4.2<\/h4>\n\n<ul>\n<li>First release from the WordPress.org Plugin Directory.<\/li>\n<li>Added the <code>Requires Plugins: woocommerce<\/code> header: the plugin only hooks into the WooCommerce login and registration forms, so WordPress now refuses to activate it without WooCommerce instead of activating and doing nothing.<\/li>\n<\/ul>\n\n<h4>0.4.1<\/h4>\n\n<ul>\n<li>The Client Secret is no longer passed through <code>sanitize_text_field()<\/code> when saved: it is an opaque credential and sanitizing could corrupt valid secrets. Same for the OAuth authorization code on the callback.<\/li>\n<li>Translation files are no longer bundled; translations come from translate.wordpress.org.<\/li>\n<\/ul>\n\n<h4>0.4.0<\/h4>\n\n<ul>\n<li>Prepared for the WordPress.org Plugin Directory: plugin folder, main file and text domain renamed to <code>pixelhunter-social-login<\/code>; the bundled update checker and the <code>Update URI<\/code> header were removed (updates now come from the directory).<\/li>\n<li><strong>Breaking:<\/strong> the Redirect URI changed to <code>\/wp-json\/pixelhunter-social-login\/v1\/\u2026<\/code>. Re-copy it from <strong>WooCommerce \u2192 Social Login<\/strong> into the Google Cloud Console and the Azure portal, otherwise sign-in fails with <code>redirect_uri_mismatch<\/code>.<\/li>\n<li>Added an \"External services\" section documenting every request made to Google and Microsoft and the data involved.<\/li>\n<li>No change to stored settings or to already-linked customer accounts.<\/li>\n<\/ul>\n\n<h4>0.3.3<\/h4>\n\n<ul>\n<li>Screenshots now render as images in the \"View Details\" modal. WordPress's readme parser strips <code>&lt;img&gt;<\/code> from the screenshots section, so the images are injected after parsing (from the repo assets) instead.<\/li>\n<\/ul>\n\n<h4>0.3.2<\/h4>\n\n<ul>\n<li>Plugin metadata: author and plugin URI in the header, and a WordPress.org-format <code>readme.txt<\/code> that populates the \"View Details\" modal (Description, Installation, FAQ, Changelog).<\/li>\n<li>Screenshots of the login buttons and the admin settings.<\/li>\n<\/ul>\n\n<h4>0.3.1<\/h4>\n\n<ul>\n<li>Auto-update via GitHub Releases (Plugin Update Checker): the release tag is compared against the plugin's <code>Version:<\/code> header and offered on the normal Plugins \u2192 Updates screen. <code>Update URI: false<\/code> keeps wordpress.org from hijacking the slug.<\/li>\n<\/ul>\n\n<h4>0.3.0<\/h4>\n\n<ul>\n<li>Canonical WordPress i18n: English source strings with bundled pt_PT translation.<\/li>\n<li>Simplified account-linking decision logic.<\/li>\n<\/ul>\n\n<h4>0.2.1<\/h4>\n\n<ul>\n<li>Multi-provider: generalized from Google-only to Google + Microsoft (personal accounts) on one provider-agnostic architecture.<\/li>\n<li>Layout\/CSS refinements to the buttons.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>Fire <code>wp_login<\/code> on OAuth login; JWT clock-skew leeway; stored admin secret masked in the UI.<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li><code>box-sizing<\/code> fix on the buttons; setup-instruction updates.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release: OAuth <code>\/start<\/code> and <code>\/callback<\/code> endpoints, single-use <code>state<\/code>\/<code>nonce<\/code> CSRF protection, full <code>id_token<\/code> claim validation against the provider JWKS, secure account lookup\/create\/link, the Google button via WooCommerce hooks, and the admin settings page with setup guide and live status.<\/li>\n<\/ul>","raw_excerpt":"Google and Microsoft login\/registration for WooCommerce (OAuth 2.0 \/ OpenID Connect) \u2014 self-contained, no third-party services.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/346795","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=346795"}],"author":[{"embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/pixelhunter"}],"wp:attachment":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=346795"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=346795"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=346795"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=346795"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=346795"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=346795"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}