No Login by Email Address icon

No Login by Email Address

by cubecolour

View on WordPress.org
56 Quality Score
Active Installs
14/30

With only 1,000 active installs, the plugin has a small but steady user base for a very specific niche task, earning a modest popularity score that is boosted by the ratio of installs to scope.

Update Freshness
12/25

The plugin was updated on 2025-06-23 and is tested against WordPress 6.8.5, showing that the author keeps it current with recent core releases despite its small footprint.

User Rating
12/15

A perfect 100/100 from 4 reviews is encouraging but statistically thin, so the rating is taken as a directional signal rather than proof of widespread satisfaction.

Support Health
8/15

Zero support threads opened and zero resolved means there is no public track record of how the author handles troubleshooting, which is a meaningful gap for any production deployment.

WP Compatibility
11/15

Compatibility scores well at 75/100 thanks to a low minimum WordPress version of 4.9 and recent testing on 6.8.5, though the lack of a declared PHP requirement is a minor transparency issue.

Scores higher than 6% of indexed plugins

About

Removes the ability to login using the email address instead of the username.

Active Installs 1k+
Rating ★★★★★ 5/5
Last Updated 2025-06-23 10:03am GMT
Requires WordPress 4.9+
Tested Up To 6.8.8
✓ No known vulnerabilities

What It Does

No Login by Email Address disables WordPress's built-in feature that lets users authenticate by typing their email address, forcing login attempts to use only a username. In practice, anyone visiting /wp-login.php can no longer type an email into the username field; only a matching username will work. It is a narrow, single-purpose security tweak rather than a full login hardening suite.

Who It's For

This plugin fits organizations that mandate username-based authentication for compliance, audit, or policy reasons, such as government portals, financial institutions, healthcare intranets, legal firms, and university staff directories. If your security policy requires that every login attempt be traceable to a known username rather than a personal email, this plugin enforces that at the WordPress layer.

Who Should Skip It

If you run a typical small business blog, membership site, or any site where users expect to log in with the email they registered with, skip this plugin; it will frustrate legitimate users and create avoidable support tickets. You also do not need it if you already enforce single sign-on or a custom login form that controls authentication flow.

The Bottom Line

No Login by Email Address does exactly one thing and does it lightly, which is both its appeal and its limitation for the 1,000 sites using it. With a 59.79/100 quality score, weak support history, and a small install base, it is best suited to organizations with a clear policy reason to disable email login rather than general WordPress users. For most sites, a broader login security plugin will deliver more value.

Tags

email login username