Simple JWT Login – Allows you to use JWT on REST endpoints. icon

Simple JWT Login – Allows you to use JWT on REST endpoints.

by Nicu Micle

View on WordPress.org
79 Quality Score
Active Installs
16/30

With roughly 4,000 active installs it is a niche tool, but adoption is about 13 times what the baseline expectation is for this category, which lifts the popularity score above average.

Update Freshness
25/25

The plugin was updated on 2026-07-07 and is tested against WordPress 7.0, which signals that the author is actively keeping pace with core releases.

User Rating
15/15

All 47 ratings are perfect, giving it a 100/15 user rating score, though the small sample size means the picture could shift with more feedback.

Support Health
8/15

Zero support threads opened and zero resolved means there is no public track record of how the author handles bugs or questions, so the 50/15 score reflects that lack of evidence rather than active help.

WP Compatibility
15/15

It supports WordPress 4.4.0 and PHP 5.5, giving it an unusually wide compatibility window that scores a full 100/15.

Scores higher than 69% of indexed plugins

About

Enhance the WordPress REST API with JWT authentication for secure access by mobile apps, external sites, and third-party services.

Active Installs 4k+
Rating ★★★★★ 5/5
Last Updated 2026-08-09 5:32am GMT
Requires WordPress 4.4.0+
Tested Up To 7.0.4
Requires PHP 5.5+

Security History

5 known vulnerabilities, all patched
4 High 1 Medium

Most recent: August 20, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

Simple JWT Login extends the WordPress REST API with JSON Web Token authentication, letting external clients such as mobile apps, decoupled frontends, and third-party services verify users and access protected endpoints without relying on cookie-based sessions. It also bundles endpoints for auto-login and user registration, so you can issue tokens and create accounts from outside the wp-admin. In practice it acts as a thin authentication layer that sits on top of core WordPress user accounts.

Who It's For

This plugin is a good fit for developers building headless WordPress sites, native mobile apps, or backend integrations that need to authenticate WordPress users programmatically. It also suits shops or agencies that want a quick way to expose login, registration, and authenticated REST endpoints to a separate client without writing custom auth code. Teams comfortable managing JWT secrets and configuring endpoints by hand will get the most out of it.

Who Should Skip It

If you only need cookie-based logins inside a normal WordPress site, this plugin adds unnecessary surface area and risk. Hobby bloggers, content-only sites, and anyone who is not actively building an external client should skip it and use the default WordPress login flow instead.

The Bottom Line

Simple JWT Login is a well-maintained, broadly compatible JWT plugin that earns a 78.63/100 overall score, dragged down mostly by its small install base and a complete absence of public support threads. It is a sensible pick for developers who want login, registration, and auto-login endpoints in one package, but larger teams may prefer the more battle-tested JWT Authentication for WP REST API. Treat the perfect 100/100 rating with mild skepticism given only 47 reviewers.

Tags

api auto login jwt register tokens