{"id":330183,"date":"2026-08-31T15:35:18","date_gmt":"2026-08-31T15:35:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/custom-auth-suite\/"},"modified":"2026-08-31T15:34:42","modified_gmt":"2026-08-31T15:34:42","slug":"custom-auth-suite","status":"publish","type":"plugin","link":"https:\/\/brx.wordpress.org\/plugins\/custom-auth-suite\/","author":23521087,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.9.2","stable_tag":"0.9.2","tested":"7.1","requires":"6.4","requires_php":"8.1","requires_plugins":null,"header_name":"Custom Auth Suite\u2122","header_author":"DevDorado","header_description":"Custom Auth Suite creates custom login, registration, password reset and email verification flows with protected paths and optional assisted support.","assets_banners_color":"874faa","last_updated":"2026-08-31 15:34:42","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/customauthsuite.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":51,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.9.2":{"tag":"0.9.2","author":"devdorado","date":"2026-08-31 15:34:42","revision":3674572}},"upgrade_notice":{"0.9.2":"<p>Security, privacy, multilingual routing and Installation Doctor update. Optional remote services remain off by default. Review authentication pages, protected paths and plugin Warnings after upgrading.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3674572,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3674572,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3674572,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3674572,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.9.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3674572,"resolution":"1","location":"assets","locale":"","width":3258,"height":1880},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3674572,"resolution":"2","location":"assets","locale":"","width":3248,"height":1872},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3674572,"resolution":"3","location":"assets","locale":"","width":3294,"height":1892},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3674572,"resolution":"4","location":"assets","locale":"","width":3262,"height":1884},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3674572,"resolution":"5","location":"assets","locale":"","width":3264,"height":1776}},"screenshots":{"1":"Custom Auth Suite admin dashboard.","2":"Authentication page configuration.","3":"Email customization settings.","4":"Installation Doctor compatibility checks.","5":"Upgrade CAS information cards."}},"plugin_section":[],"plugin_tags":[710,3691,18971,47793,5134],"plugin_category":[38],"plugin_contributors":[278518],"plugin_business_model":[],"class_list":["post-330183","plugin","type-plugin","status-publish","hentry","plugin_tags-authentication","plugin_tags-custom-login","plugin_tags-email-verification","plugin_tags-page-restriction","plugin_tags-user-registration","plugin_category-authentication","plugin_contributors-devdorado","plugin_committers-devdorado"],"banners":{"banner":"https:\/\/ps.w.org\/custom-auth-suite\/assets\/banner-772x250.png?rev=3674572","banner_2x":"https:\/\/ps.w.org\/custom-auth-suite\/assets\/banner-1544x500.png?rev=3674572","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/custom-auth-suite\/assets\/icon-128x128.png?rev=3674572","icon_2x":"https:\/\/ps.w.org\/custom-auth-suite\/assets\/icon-256x256.png?rev=3674572","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/custom-auth-suite\/assets\/screenshot-1.png?rev=3674572","caption":"Custom Auth Suite admin dashboard."},{"src":"https:\/\/ps.w.org\/custom-auth-suite\/assets\/screenshot-2.png?rev=3674572","caption":"Authentication page configuration."},{"src":"https:\/\/ps.w.org\/custom-auth-suite\/assets\/screenshot-3.png?rev=3674572","caption":"Email customization settings."},{"src":"https:\/\/ps.w.org\/custom-auth-suite\/assets\/screenshot-4.png?rev=3674572","caption":"Installation Doctor compatibility checks."},{"src":"https:\/\/ps.w.org\/custom-auth-suite\/assets\/screenshot-5.png?rev=3674572","caption":"Upgrade CAS information cards."}],"raw_content":"<!--section=description-->\n<p>Custom Auth Suite creates custom login, registration, password reset and email verification flows with protected paths and optional assisted support.<\/p>\n\n<p>The Free package includes:<\/p>\n\n<ul>\n<li>Custom login, registration, lost-password and reset-confirmation flows.<\/li>\n<li>Email verification and authentication email templates.<\/li>\n<li>Protected paths, safe redirects and account-access helpers.<\/li>\n<li>Authentication-page creation, assignment and route checks.<\/li>\n<li>A local Installation Doctor with compatibility checks and privacy-limited JSON\/HTML reports.<\/li>\n<\/ul>\n\n<p>No paid license is required for these Free features.<\/p>\n\n<p>The Free interface may show clearly identified, read-only previews of separately distributed Advanced and Premium capabilities. Commercial modules are absent from the WordPress.org package; previews save no commercial settings and do not restrict Free features.<\/p>\n\n<p>In the WordPress.org Free package, Upgrade CAS may show two bundled Advanced\/Premium information cards. Each can be dismissed locally for 20 days and sends no impression, CTA-click or dismiss analytics.<\/p>\n\n<p>The Doctor Compatibility Scan lists plugin name, slug, version and status under \u201cPlugins recognized as CAS-relevant\u201d or \u201cOther unclassified plugins.\u201d Unclassified is not a safety judgment. Acknowledged Warnings remain visible but stop auto-opening until context changes. False diagnostic booleans are shown as <code>no<\/code>.<\/p>\n\n<p>Custom Auth Suite works with WordPress users. It does not create a membership or payment system.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>CAS is local-first. These optional services contact external servers only under the stated conditions.<\/p>\n\n<h4>Remote Admin Messages<\/h4>\n\n<p>Disabled by default. After explicit administrator opt-in, CAS may request operational JSON notices from:<\/p>\n\n<p>https:\/\/customauthsuite.com\/wp-json\/cas-remote-messages\/v1\/messages<\/p>\n\n<p>A request may include CAS version\/package, placement, locale, plan or support status, limited compatibility context and a privacy-preserving site hash. Free notices are limited to security, compatibility, maintenance, documentation and support. A dismissible renewal notice may appear only for support already purchased and validated. Remote commercial upgrade cards are not requested or rendered.<\/p>\n\n<p>CAS normalizes the response and does not execute remote PHP\/JavaScript or render arbitrary remote HTML. Disabling the option stops future requests.<\/p>\n\n<h4>Remote Message Interaction Analytics<\/h4>\n\n<p>Disabled by default and controlled separately. When enabled, CAS may send privacy-safe CTA-click events for remote notices and local review\/Doctor resource links. Data may include action\/message\/placement IDs, CTA label, CAS version\/package, available license context, a privacy-preserving site hash, timestamp and delivery status. Events are sent to:<\/p>\n\n<p>https:\/\/customauthsuite.com\/wp-json\/cas-remote-messages\/v1\/events<\/p>\n\n<p>Local preference actions are not sent.<\/p>\n\n<p>The local Advanced\/Premium cards never send impression, CTA-click or dismiss events to CAS RM.<\/p>\n\n<h4>Assisted Doctor Support<\/h4>\n\n<p>Disabled by default. After explicit opt-in and an administrator click on \u201cOpen support request\u201d, CAS creates one redacted Doctor report behind a random handoff token and opens the support page for retrieval. The handoff normally expires after 30 minutes and is bounded to one hour.<\/p>\n\n<p>Disabling Assisted Doctor Support immediately invalidates existing handoffs, including those created before re-enablement. Reports are designed to exclude passwords, cookies, nonces, authorization headers, complete license keys, API secrets, private keys and diagnostic tokens.<\/p>\n\n<h4>Remote Support Diagnostics<\/h4>\n\n<p>This ticket-based mechanism requires case consent, a temporary signed token, an administrator with <code>manage_options<\/code>, and manual nonce-protected activation. Opening a support link does not activate it.<\/p>\n\n<p>CAS may contact the revocation endpoint embedded in the signed support token to check whether the temporary session has been revoked. For CAS Support Desk tokens, the endpoint is:<\/p>\n\n<p>https:\/\/customauthsuite.com\/wp-json\/cas-support-desk\/v1\/support-diagnostics\/revocation<\/p>\n\n<p>Requests may include a token-identifier hash, case ID, privacy-preserving site hash and timestamp, but not the full signed token, WordPress credentials or private secrets. Local termination is immediate and remains effective if a remote notice fails. This is not a remote login, creates no users and does not automatically upload reports.<\/p>\n\n<h4>Optional manual website resource<\/h4>\n\n<p>A manual link may open:<\/p>\n\n<p>https:\/\/customauthsuite.com\/privacy-cookie-notes\/<\/p>\n\n<p>The plugin opens it only when clicked. The request may include domain, language and selected package mode. Generated notes describe CAS-related data flows and should be reviewed and adapted to the site\u2019s actual configuration before publication.<\/p>\n\n<p>Service information:<\/p>\n\n<ul>\n<li>Website: https:\/\/customauthsuite.com\/<\/li>\n<li>Terms: https:\/\/customauthsuite.com\/terms-of-use\/<\/li>\n<li>Privacy: https:\/\/customauthsuite.com\/privacy-cookie-policy\/<\/li>\n<\/ul>\n\n<p>The Free package does not use commercial license, update or package-download services.<\/p>\n\n<h3>Privacy and Local Data Handling<\/h3>\n\n<p>CAS primarily stores data locally. Depending on enabled features, this may include settings\/routes, authentication account fields, verification and password-reset state, protected paths, Doctor\/report data, warning fingerprints and enabled logs.<\/p>\n\n<p>Doctor inventory entries contain only plugin name, slug, version and status. Reports and logs remain local unless deliberately shared; review them first. Uninstall cleanup follows the CAS retention setting.<\/p>\n\n<h3>Support<\/h3>\n\n<p>Free support is provided through the official WordPress.org support forum after publication. Product information and commercial support options are available at:<\/p>\n\n<p>https:\/\/customauthsuite.com\/<\/p>\n\n<p>Never publish passwords, license keys, diagnostic tokens, cookies, nonces or other secrets in a public forum.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install through Plugins &gt; Add New or upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate Custom Auth Suite and open its settings.<\/li>\n<li>Run the wizard or assign authentication pages manually.<\/li>\n<li>Review login, registration, password recovery, reset-confirmation and landing routes.<\/li>\n<li>Configure protected paths and test direct access and redirects while logged out and logged in.<\/li>\n<li>Configure email verification and templates.<\/li>\n<li>Review the Installation Doctor.<\/li>\n<li>Enable only required optional services and test the complete flow before production use.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20free%20package%20require%20a%20paid%20license%3F\"><h3>Does the Free package require a paid license?<\/h3><\/dt>\n<dd><p>No. All included Free features work without a paid license.<\/p><\/dd>\n<dt id=\"why%20are%20advanced%20or%20premium%20previews%20visible%3F\"><h3>Why are Advanced or Premium previews visible?<\/h3><\/dt>\n<dd><p>They describe separately distributed packages. Commercial modules are absent from the WordPress.org ZIP; previews save no paid settings and do not restrict Free features.<\/p><\/dd>\n<dt id=\"are%20optional%20remote%20services%20enabled%20by%20default%3F\"><h3>Are optional remote services enabled by default?<\/h3><\/dt>\n<dd><p>No. Remote Admin Messages, Interaction Analytics and Assisted Doctor Support are disabled by default and require their applicable administrator actions. Messages and analytics have separate controls.<\/p><\/dd>\n<dt id=\"what%20is%20the%20difference%20between%20the%20doctor%2C%20assisted%20doctor%20support%20and%20remote%20support%20diagnostics%3F\"><h3>What is the difference between the Doctor, Assisted Doctor Support and Remote Support Diagnostics?<\/h3><\/dt>\n<dd><p>The Doctor runs locally. Assisted Doctor Support is an administrator-initiated one-report handoff. Remote Support Diagnostics is a separate temporary ticket session requiring consent, a signed token and manual activation.<\/p><\/dd>\n<dt id=\"what%20does%20%E2%80%9Cother%20unclassified%20plugins%E2%80%9D%20mean%2C%20and%20does%20acknowledgment%20hide%20a%20warning%3F\"><h3>What does \u201cOther unclassified plugins\u201d mean, and does acknowledgment hide a Warning?<\/h3><\/dt>\n<dd><p>\u201cUnclassified\u201d means the plugin did not match the curated CAS compatibility registry; it is not a safety or compatibility judgment. Acknowledgment does not hide a Warning. It stops automatic opening for that item until relevant context changes.<\/p><\/dd>\n<dt id=\"does%20cas%20send%20passwords%20or%20execute%20remote%20code%3F\"><h3>Does CAS send passwords or execute remote code?<\/h3><\/dt>\n<dd><p>Doctor handoffs are designed to redact secrets, and administrators should review reports before sharing. Remote Admin Messages return normalized JSON; CAS does not execute remote PHP\/JavaScript or render arbitrary remote HTML.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.9.2<\/h4>\n\n<ul>\n<li>Kept Free usable without a paid license and physically excluded commercial-only modules.<\/li>\n<li>Added explicit opt-ins for Remote Admin Messages, Interaction Analytics and Assisted Doctor Support; all remain disabled by default.<\/li>\n<li>Limited Free remote messages to operational notices and made Upgrade CAS cards local, dismissible for 20 days and free of commercial analytics.<\/li>\n<li>Added privacy-limited plugin inventory, explicit <code>no<\/code> booleans, Compatibility Scan and review acknowledgment for plugin Warnings.<\/li>\n<li>Added short-lived, redacted, immediately revocable Assisted Doctor Support handoffs and hardened Remote Support Diagnostics.<\/li>\n<li>Moved remaining static CSS\/JavaScript to WordPress enqueue APIs and strengthened nonce, capability, sanitization and escaping controls.<\/li>\n<li>Stabilized CAS-skinned protected-path and profile redirects, invalid\/expired verification feedback, multilingual routes and theme-independent menu pruning.<\/li>\n<li>Restricted Remote Messages to CAS Settings and refined the full-width diagnostics layout for desktop and mobile administration.<\/li>\n<\/ul>","raw_excerpt":"Custom Auth Suite creates custom login, registration, password reset and email verification flows with protected paths and optional assisted support.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/330183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=330183"}],"author":[{"embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/devdorado"}],"wp:attachment":[{"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=330183"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=330183"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=330183"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=330183"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=330183"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/brx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=330183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}