Skip to content
WordPress.org

Bodo

  • Themes
  • Plugins
  • About
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Custom Auth Suite™

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Custom Auth Suite™

By DevDorado
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Custom Auth Suite creates custom login, registration, password reset and email verification flows with protected paths and optional assisted support.

The Free package includes:

  • Custom login, registration, lost-password and reset-confirmation flows.
  • Email verification and authentication email templates.
  • Protected paths, safe redirects and account-access helpers.
  • Authentication-page creation, assignment and route checks.
  • A local Installation Doctor with compatibility checks and privacy-limited JSON/HTML reports.

No paid license is required for these Free features.

The Free interface may show clearly identified, read-only previews of separately distributed Advanced and Premium capabilities. Commercial modules are absent from the WordPress.org package; previews save no commercial settings and do not restrict Free features.

In the WordPress.org Free package, Upgrade CAS may show two bundled Advanced/Premium information cards. Each can be dismissed locally for 20 days and sends no impression, CTA-click or dismiss analytics.

The Doctor Compatibility Scan lists plugin name, slug, version and status under “Plugins recognized as CAS-relevant” or “Other unclassified plugins.” Unclassified is not a safety judgment. Acknowledged Warnings remain visible but stop auto-opening until context changes. False diagnostic booleans are shown as no.

Custom Auth Suite works with WordPress users. It does not create a membership or payment system.

External Services

CAS is local-first. These optional services contact external servers only under the stated conditions.

Remote Admin Messages

Disabled by default. After explicit administrator opt-in, CAS may request operational JSON notices from:

https://customauthsuite.com/wp-json/cas-remote-messages/v1/messages

A request may include CAS version/package, placement, locale, plan or support status, limited compatibility context and a privacy-preserving site hash. Free notices are limited to security, compatibility, maintenance, documentation and support. A dismissible renewal notice may appear only for support already purchased and validated. Remote commercial upgrade cards are not requested or rendered.

CAS normalizes the response and does not execute remote PHP/JavaScript or render arbitrary remote HTML. Disabling the option stops future requests.

Remote Message Interaction Analytics

Disabled by default and controlled separately. When enabled, CAS may send privacy-safe CTA-click events for remote notices and local review/Doctor resource links. Data may include action/message/placement IDs, CTA label, CAS version/package, available license context, a privacy-preserving site hash, timestamp and delivery status. Events are sent to:

https://customauthsuite.com/wp-json/cas-remote-messages/v1/events

Local preference actions are not sent.

The local Advanced/Premium cards never send impression, CTA-click or dismiss events to CAS RM.

Assisted Doctor Support

Disabled by default. After explicit opt-in and an administrator click on “Open support request”, CAS creates one redacted Doctor report behind a random handoff token and opens the support page for retrieval. The handoff normally expires after 30 minutes and is bounded to one hour.

Disabling Assisted Doctor Support immediately invalidates existing handoffs, including those created before re-enablement. Reports are designed to exclude passwords, cookies, nonces, authorization headers, complete license keys, API secrets, private keys and diagnostic tokens.

Remote Support Diagnostics

This ticket-based mechanism requires case consent, a temporary signed token, an administrator with manage_options, and manual nonce-protected activation. Opening a support link does not activate it.

CAS may contact the revocation endpoint embedded in the signed support token to check whether the temporary session has been revoked. For CAS Support Desk tokens, the endpoint is:

https://customauthsuite.com/wp-json/cas-support-desk/v1/support-diagnostics/revocation

Requests may include a token-identifier hash, case ID, privacy-preserving site hash and timestamp, but not the full signed token, WordPress credentials or private secrets. Local termination is immediate and remains effective if a remote notice fails. This is not a remote login, creates no users and does not automatically upload reports.

Optional manual website resource

A manual link may open:

https://customauthsuite.com/privacy-cookie-notes/

The plugin opens it only when clicked. The request may include domain, language and selected package mode. Generated notes describe CAS-related data flows and should be reviewed and adapted to the site’s actual configuration before publication.

Service information:

  • Website: https://customauthsuite.com/
  • Terms: https://customauthsuite.com/terms-of-use/
  • Privacy: https://customauthsuite.com/privacy-cookie-policy/

The Free package does not use commercial license, update or package-download services.

Privacy and Local Data Handling

CAS primarily stores data locally. Depending on enabled features, this may include settings/routes, authentication account fields, verification and password-reset state, protected paths, Doctor/report data, warning fingerprints and enabled logs.

Doctor inventory entries contain only plugin name, slug, version and status. Reports and logs remain local unless deliberately shared; review them first. Uninstall cleanup follows the CAS retention setting.

Support

Free support is provided through the official WordPress.org support forum after publication. Product information and commercial support options are available at:

https://customauthsuite.com/

Never publish passwords, license keys, diagnostic tokens, cookies, nonces or other secrets in a public forum.

Screenshots

Custom Auth Suite admin dashboard.
Custom Auth Suite admin dashboard.
Authentication page configuration.
Authentication page configuration.
Email customization settings.
Email customization settings.
Installation Doctor compatibility checks.
Installation Doctor compatibility checks.
Upgrade CAS information cards.
Upgrade CAS information cards.

Installation

  1. Install through Plugins > Add New or upload the plugin folder to /wp-content/plugins/.
  2. Activate Custom Auth Suite and open its settings.
  3. Run the wizard or assign authentication pages manually.
  4. Review login, registration, password recovery, reset-confirmation and landing routes.
  5. Configure protected paths and test direct access and redirects while logged out and logged in.
  6. Configure email verification and templates.
  7. Review the Installation Doctor.
  8. Enable only required optional services and test the complete flow before production use.

FAQ

Does the Free package require a paid license?

No. All included Free features work without a paid license.

Why are Advanced or Premium previews visible?

They describe separately distributed packages. Commercial modules are absent from the WordPress.org ZIP; previews save no paid settings and do not restrict Free features.

Are optional remote services enabled by default?

No. Remote Admin Messages, Interaction Analytics and Assisted Doctor Support are disabled by default and require their applicable administrator actions. Messages and analytics have separate controls.

What is the difference between the Doctor, Assisted Doctor Support and Remote Support Diagnostics?

The Doctor runs locally. Assisted Doctor Support is an administrator-initiated one-report handoff. Remote Support Diagnostics is a separate temporary ticket session requiring consent, a signed token and manual activation.

What does “Other unclassified plugins” mean, and does acknowledgment hide a Warning?

“Unclassified” means the plugin did not match the curated CAS compatibility registry; it is not a safety or compatibility judgment. Acknowledgment does not hide a Warning. It stops automatic opening for that item until relevant context changes.

Does CAS send passwords or execute remote code?

Doctor handoffs are designed to redact secrets, and administrators should review reports before sharing. Remote Admin Messages return normalized JSON; CAS does not execute remote PHP/JavaScript or render arbitrary remote HTML.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Custom Auth Suite™” is open source software. The following people have contributed to this plugin.

Contributors
  • DevDorado

Translate “Custom Auth Suite™” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

0.9.2

  • Kept Free usable without a paid license and physically excluded commercial-only modules.
  • Added explicit opt-ins for Remote Admin Messages, Interaction Analytics and Assisted Doctor Support; all remain disabled by default.
  • Limited Free remote messages to operational notices and made Upgrade CAS cards local, dismissible for 20 days and free of commercial analytics.
  • Added privacy-limited plugin inventory, explicit no booleans, Compatibility Scan and review acknowledgment for plugin Warnings.
  • Added short-lived, redacted, immediately revocable Assisted Doctor Support handoffs and hardened Remote Support Diagnostics.
  • Moved remaining static CSS/JavaScript to WordPress enqueue APIs and strengthened nonce, capability, sanitization and escaping controls.
  • Stabilized CAS-skinned protected-path and profile redirects, invalid/expired verification feedback, multilingual routes and theme-independent menu pruning.
  • Restricted Remote Messages to CAS Settings and refined the full-width diagnostics layout for desktop and mobile administration.

Meta

  • Version 0.9.2
  • Last updated 24 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.4 or higher
  • Tested up to 7.1
  • PHP version 8.1 or higher
  • Language
    English (US)
  • Tags
    authenticationcustom loginemail verificationpage restrictionUser Registration
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • DevDorado

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Support
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Bodo

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry.
The WordPress® trademark is the intellectual property of the WordPress Foundation.