WPGraphQL Extensions
Disable DEBUG_LOGS_INACTIVE message and add validateUserCredentials mutation
by biohzrdmx · github.com/biohzrdmx/wp-graphql-extensions · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/biohzrdmx/wp-graphql-extensions/archive/refs/heads/master.zipDisable DEBUG_LOGS_INACTIVE message and add validateUserCredentials mutation
Usage
Just copy/upload wpgraphql-extensions.php to wp-content/mu-plugins and you're set.
This plugin disables the DEBUG_LOGS_INACTIVE that appears on the extensions item of the response, for cleanliness.
Also it adds a new validateUserCredentials mutation:
mutation validateUserCredentials(
$password: String!,
$username: String!
) {
validateUserCredentials(input: {
password: $password,
username: $username
}) {
isValid
userId
}
}
It can return isValid a boolean that indicates whether the credentials are valid or not and userId which is an integer with the user ID.
{
"data": {
"validateUserCredentials": {
"isValid": true,
"userId": 1
}
}
}
Important: It is strongly recommended that you should enable the Restrict Endpoint to Authenticated Users option on WPGraphQL settings if you add this mutation to avoid security issues, since having this mutation open to the public effectively creates an attack vector for credential bruteforcing.
This plugin is intended for headless GraphQL clients, so that you can have a login on your site and check those credentials on a headless WordPress instance which acts as CMS, specifically for migrating users gradually (hence the lack of a register mutation).
I made another plugin to add personal access tokens which can be used with this to connect both instances without having to rely on app passwords or exposing admin user credentials, you can check it here.
Issues
If you have any problem with the plugin please don't hesitate open an issue and include as much data as possible about your environment: WordPress version, WPGraphQL version, server type/version, OS, etc.
Licensing
MIT licensed
Copyright © 2026 biohzrdmx.
Releases
1 release.
These releases are tags only. The author does not attach a packaged zip, so there are no download counts to report.