WP Manifestindependent plugin directory
manifest / users / loginly

Loginly - Login, Register & Password Reset Forms

Frontend login, registration, forgot password and reset password forms, with redirect control and an admin settings dashboard.

by Pixels Digital · github.com/shakib6472/loginly · website

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/shakib6472/loginly/archive/refs/heads/master.zip

Frontend login, registration and password reset forms with six templates, a design panel, custom fields, reCAPTCHA and login attempt limiting.

Description

Loginly puts login, registration and password reset on your own pages instead of wp-login.php. You place a shortcode, and the form is rendered by your theme with your styling around it.

Five shortcodes are provided:

  • [loginly_login]
  • [loginly_register]
  • [loginly_forgot_password]
  • [loginly_reset_password]
  • [loginly_logout]

Each accepts attributes that apply to that one instance, including template="" to use a different template just there and redirect_url="" to override where it sends someone afterwards. The Dashboard lists all five with the attributes each one takes, so you do not have to read documentation to find them.

Forms

Every form submits over AJAX and falls back to a normal POST when JavaScript is off. Both paths run the same validation, the same redirect rules and the same spam checks, because both call one shared layer rather than each having their own. Password fields carry a show and hide button, which is a real button, works from the keyboard, and never submits the form.

Templates

Six templates ship: Default, Dark, Minimal, Floating Label, Full Screen and Split Screen. Each works for all five form types. Pick one per form type, or override it on a single shortcode. A template can also be overridden from your theme by copying the file into yourtheme/loginly/.

Design panel

97 controls across 10 groups, editing CSS custom properties rather than writing a stylesheet. Colours, sizes, spacing, alignment, borders and the password meter are all editable, per template, with a live preview beside the controls and undo and redo while you work. Eight colour palettes are included, each with its text and border pairings measured for contrast. Nothing is written to a file: your choices are stored as options and printed as an inline style block after the stylesheet.

Wording and fields

45 visitor facing strings across the five forms are editable, including every label, button, link and notice. Wording is stored per form type rather than per template, so changing template never loses it. Fields can be reordered or hidden, except the ones a form cannot work without.

Custom registration fields can be added in 10 types: text, email, number, paragraph, dropdown, radio buttons, checkbox, date, website and telephone. Each is stored in user meta and appears on the user's profile screen in wp-admin. Deleting a field asks what should happen to the values already collected, and keeping them is the default.

Security

reCAPTCHA v2 checkbox and reCAPTCHA v3 are supported, on any of the four forms that authenticate or create an account. Verification happens on your server, in the shared layer both submission paths use, so a request that fails it never reaches account creation or sign in. It is off until you enter both keys.

Login attempt limiting counts failures per address and per username, and covers every route into the site rather than only this plugin's forms: wp-login.php, XML-RPC and the REST API all count against the same limits, because all of them authenticate through WordPress itself. A locked out visitor is told how long is left, never how many attempts they used. It is off by default.

Emails

Four emails: welcome, password reset, password changed and a new registration notice to the administrator. Subject and body are editable with 10 merge tags, and any of them can be sent to yourself from the Emails screen so you can see exactly what a recipient gets, and read the real reason if your host refuses to send it.

For developers

Every registry is filterable, so an add-on can add a setting, an admin tab, a template directory, an email type, a redirect destination, a form control, a captcha provider, a shortcode, a design token or a dashboard section without editing a core file.

Installation

  1. Upload the plugin to /wp-content/plugins/loginly or install it through Plugins, Add New.
  2. Activate it. Four pages are created: Login, Register, Forgot Password and Reset Password, each containing the matching shortcode.
  3. Open Loginly, Dashboard to check the pages exist and to copy any shortcode.
  4. Set where people go after logging in under Loginly, Redirects.

Nothing is switched on that changes how your site behaves until you configure it. The captcha and attempt limiting are both off on a fresh install.

External services

This plugin makes no external request at all until you configure one of the two features below. Both are off on a fresh install, and with either one unconfigured nothing is loaded from anywhere else and nothing is sent anywhere.

Google reCAPTCHA

When you choose reCAPTCHA v2 or v3 under Loginly, Security and enter both keys, the plugin uses Google reCAPTCHA on the forms you tick.

What is sent, and when:

  • On any page that renders a protected form, the visitor's browser loads https://www.google.com/recaptcha/api.js from Google. Google receives what any script request carries, including the visitor's IP address and user agent, and reCAPTCHA collects interaction data from that page in order to score the visitor. The script is not loaded on pages without a protected form, and never in wp-admin.
  • When that form is submitted, your server sends one request to https://www.google.com/recaptcha/api/siteverify containing your secret key, the response token the visitor's browser produced, and the visitor's IP address. Google answers with whether the token is valid, and for v3 a score. Nothing else is sent, and nothing is sent when a form is merely displayed.

No account data, no password, no email address and no form field other than the captcha token is sent to Google at any point.

Service provided by Google. Terms of service: https://policies.google.com/terms Privacy policy: https://policies.google.com/privacy

Facebook Login

When you enable Facebook under Loginly, Social Login and enter both an App ID and an App Secret, the plugin offers a Facebook button on the forms you tick. With it disabled, or with either credential empty, no button is rendered and no request is made.

What is sent, and when:

  • Nothing at all until a visitor clicks the button. Displaying the form sends nothing and loads no script from Facebook.
  • When a visitor clicks the button, their browser is sent to https://www.facebook.com/v25.0/dialog/oauth with your App ID, this site's callback address, and a one-time token. Facebook receives what any page request carries, including the visitor's IP address and user agent, and asks them to approve the sign in.
  • When Facebook sends them back, your server makes three requests: one to https://graph.facebook.com/v25.0/oauth/access_token carrying your App ID, your App Secret and the one-time code, to obtain an access token; one to https://graph.facebook.com/debug_token to confirm that token was issued to your application and not somebody else's; and one to https://graph.facebook.com/v25.0/me to read that account's Facebook identifier, name and email address.

Facebook does not always share an email address, and it never says whether it confirmed one. A person whose Facebook account shares no address cannot create an account here, and a Facebook sign in is never joined to an account that already exists.

The plugin never sends a password, an existing account's data, or anything a visitor typed into a form to Facebook. Only the account identifier is stored on the WordPress user.

Service provided by Meta. Terms of service: https://www.facebook.com/terms.php Privacy policy: https://www.facebook.com/privacy/policy/

Google Sign-In

When you enable Google under Loginly, Social Login and enter both a client ID and a client secret, the plugin offers a Google button on the forms you tick. With it disabled, or with either credential empty, no button is rendered and no request is made.

What is sent, and when:

  • Nothing at all until a visitor clicks the button. Displaying the form sends nothing and loads no script from Google.
  • When a visitor clicks the button, their browser is sent to https://accounts.google.com/o/oauth2/v2/auth with your client ID, this site's callback address, and a one-time token. Google receives what any page request carries, including the visitor's IP address and user agent, and asks them to choose an account and approve the sign in.
  • When Google sends them back, your server sends one request to https://oauth2.googleapis.com/token containing your client ID, your client secret, and the one-time code Google issued. Google answers with an ID token holding that account's Google identifier, email address, whether Google has confirmed that address, and the display name.

The plugin never sends a password, an existing account's data, or anything a visitor typed into a form to Google. Only the account identifier from that ID token is stored on the WordPress user; the email address is not stored as the connection, and deleting the plugin with data removal on clears the connection.

Service provided by Google. Terms of service: https://policies.google.com/terms Privacy policy: https://policies.google.com/privacy

Frequently Asked Questions

Do the forms work if JavaScript is switched off?

Yes. Every form posts back to its own page and runs the same validation and the same redirect rules. Nothing falls back to wp-login.php.

Can I still use wp-login.php?

Yes, unless you switch it off. There is a setting under Redirects to block wp-login.php, which is off by default.

Does it have a captcha?

Yes, reCAPTCHA v2 checkbox and reCAPTCHA v3, under Security. It is off until you choose a provider and enter both keys, and it does nothing at all until then. Pick which forms it protects; the script loads only on pages that render one of them, and never in wp-admin.

What happens if Google is down?

The form is refused rather than let through, because a captcha you can step past by causing an error is not a captcha. If the outage is real and you need the forms working, add this to wp-config.php:

define( 'LOGINLY_DISABLE_CAPTCHA', true );

Can it limit failed logins?

Yes, under Security, and it is off by default. It counts per address and per username, so one address cannot walk through every account and a botnet cannot walk one account from many addresses. It covers every route into the site, not just this plugin's forms: wp-login.php, XML-RPC and the REST API all count against the same limits.

I locked myself out. How do I get back in?

Add this to wp-config.php:

define( 'LOGINLY_DISABLE_LIMITER', true );

Any administrator can also clear every lockout from the Security screen.

My site is behind Cloudflare or a load balancer.

Add this so the limiter counts the real visitor rather than the proxy:

define( 'LOGINLY_TRUSTED_PROXY', true );

Without it only the connecting address is counted, because the forwarded header can be set by anyone and reading it blindly would make the limiter useless.

I blocked wp-login.php and now I cannot get in. How do I reopen it?

Add this line to wp-config.php:

define( 'LOGINLY_ALLOW_WP_LOGIN', true );

wp-login.php works again immediately, whatever the setting says, so you can log in and switch the setting off. Blocking never applies to logging out or to the password reset links already sitting in people's inboxes, so those keep working too.

Will someone be told if their password changes?

Yes, and it is on by default. It is sent whether the change came from this plugin's reset form, from WordPress's own reset, or from an edit on the profile screen. It is how a person finds out their account was taken.

My emails are not arriving.

Use Send a test email on the Emails screen. It sends the email you choose to your own address with every merge tag filled in. If your host refuses it, the screen shows the reason the mailer gave rather than only reporting a failure, which is usually enough to tell whether the problem is this plugin or your mail setup.

Where do custom field values go?

Into user meta, under the meta key you choose. Keys that WordPress or this plugin already use are refused, so a custom field can never overwrite a role, a capability or a password.

What happens to collected data if I delete a custom field?

You are asked. Keeping what has already been collected is the default; deleting it from every user is a deliberate second choice.

Does the design panel write CSS files?

No. Your choices are stored as options and printed as an inline style block after the stylesheet, so an update never overwrites them and nothing has to be writable.

Can I use my own template?

Yes. Copy a template from templates/ into yourtheme/loginly/ and edit it there. A child theme is checked before the parent, and both before the plugin.

Does this plugin send anything to your servers?

No. The only outbound request it ever makes is to your captcha provider to verify a response, and only once you have configured one.

Will my wording survive if I change template?

Yes. Wording is stored per form type, not per template.

Can another plugin add settings, templates or fields?

Yes. Settings, admin tabs, template directories, emails, redirect destinations, form controls, captcha providers, shortcodes, design tokens and dashboard sections are all filterable.

Screenshots

  1. The login form on the front end, using the Default template, with the show and hide password button.
  2. The Templates screen, showing every template with a live preview of the real form.
  3. The design panel: palettes, one line per control, and a live preview on its own canvas.
  4. The Content tab, editing form wording and reordering fields.
  5. The custom field editor, adding a field to the registration form.
  6. The Security screen, showing the captcha and login attempt limiting settings.
  7. The Redirects settings screen, including a destination per user role.
  8. The Dashboard, showing the required pages and every shortcode with the attributes it accepts.

Changelog

1.0.0

  • First release.
  • Login, registration, forgot password, reset password and logout shortcodes, each with per instance attributes.
  • AJAX submission with a full non-JavaScript path through the same validation.
  • Six templates per form, selectable per form type or per shortcode, overridable from a theme.
  • Design panel with 97 controls in 10 groups, eight contrast checked colour palettes, live preview, and undo and redo.
  • Content editor for 45 visitor facing strings, with field ordering and visibility.
  • Custom registration fields in ten types, mapped to user meta and editable on the profile screen.
  • Redirect control for login, logout, registration and password reset, including per role destinations, and an option to block wp-login.php.
  • reCAPTCHA v2 and v3 on any of the four forms that authenticate or create an account, verified server side.
  • Login attempt limiting per address and per username, covering wp-login.php, XML-RPC and the REST API as well as this plugin's forms.
  • Four editable emails with ten merge tags, and a test send from the Emails screen.
  • Show and hide password button on every password field.
  • Filters for add-ons covering settings, tabs, templates, emails, redirects, form controls, captcha providers, shortcodes, design tokens and dashboard sections.

Upgrade Notice

1.0.0

First release.