WP OAuth Server (OAuth Authentication) icon

WP OAuth Server (OAuth Authentication)

by Jayson T Cote

View on WordPress.org
74 Quality Score
Active Installs
16/30

At roughly 3,000 active installs the plugin has a modest footprint, well below the 60,000 installs of the leading JWT alternative, indicating a niche but real audience.

Update Freshness
25/25

The maintenance score is perfect, with an update shipped in January 2026 and explicit testing against WordPress 6.9.0, signalling an actively maintained codebase.

User Rating
11/15

The 76 out of 100 rating from 41 reviewers is decent but not outstanding, and the small sample size limits how confidently you can read the signal.

Support Health
8/15

Support health sits at 50 because the public support threads metric shows zero resolved tickets, which raises questions about how the developer handles user issues outside of direct contact.

WP Compatibility
15/15

Compatibility is a full 100, with WordPress 6.9.0 tested and PHP 7.4 as the floor, which is reasonable for a server-side authentication plugin.

Scores higher than 37% of indexed plugins

About

Adds Authentication through OAuth 2. Provides the ability for Single Sign On for websites & Mobile Applications.

Active Installs 3k+
Rating ★★★½ 3.8/5
Last Updated 2026-09-24 5:48pm GMT
Requires WordPress 4.7.2+
Tested Up To 6.9.0
Requires PHP 7.4+

Security History

7 known vulnerabilities, all patched
1 Critical 1 High 5 Medium

Most recent: April 5, 2024

View details ▸

Powered by Wordfence Intelligence

What It Does

WP OAuth Server turns a WordPress site into a functioning OAuth 2.0 provider, letting external clients such as mobile apps, single page applications, and third party services authenticate users against WordPress user accounts. It handles the standard OAuth 2.0 flows including authorization code, implicit, client credentials, and password grants, issuing access tokens that other systems can validate. In practice this means you can use WordPress as the identity backbone for a broader application ecosystem without building a separate auth service.

Who It's For

This plugin fits developers and technical teams who need WordPress to act as the central identity provider for a multi-platform product, whether that is a mobile app, a SaaS offering, or a network of connected sites. It is best suited to shops comfortable working with token lifetimes, scopes, and client credentials at the code level. Small business owners running a brochure site or basic blog will get no value from it.

Who Should Skip It

If you only need to log into WordPress using an external identity provider like Google or Azure AD, you want a client plugin such as OpenID Connect Generic, not this server plugin. Anyone without development resources to configure clients, test grant flows, and handle token storage on the consumer side should also look elsewhere.

The Bottom Line

WP OAuth Server delivers a focused, actively maintained OAuth 2.0 server capability for WordPress, and it scores 74.47 out of 100 on PluginCheck with full marks for maintenance and compatibility. The weak spots are the small install base and the absence of any resolved public support threads, so plan to handle integration testing on your own. If you genuinely need WordPress to be the OAuth provider for an external app or service, it is a solid choice; if not, you are probably looking for the wrong category entirely.

Tags

oauth OAuth provider oauth2 OAuth2 Service Provider