AuthLatch
Passwordless login for WordPress with magic links, passkeys, self-service account security, and built-in SMTP settings.
Use with caution
AuthLatch works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where AuthLatch stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| magic link | >100 |
| passkey | #44 |
| passwordless login | >100 |
| smtp | >100 |
| webauthn | #22 |
About AuthLatch
From the official readme · v1.0.2Description
AuthLatch helps site owners replace routine password logins with secure passwordless access.
Key features:
- One-time magic links requested by username or email, with expiry and one-use tokens.
- Passkey login using WebAuthn/FIDO2.
- Self-service AuthLatch sidebar page for selected user roles.
- Users can add, revoke, and name their own passkeys.
- Users can send a magic login link to their own account email.
- Per-role passkey access and per-user passkey limits.
- Branded responsive login screen with method tabs for magic links, passkeys, and password fallback.
- Single active session control.
- Admin-generated login links with optional IP binding and auto logout.
- Admin-scoped login links that can block selected admin menus for that session.
- Built-in SMTP settings for hosts where PHP mail delivery is disabled.
- Audit log for important authentication events.
- RTL-friendly login UI.
AuthLatch stores magic-link validators as hashes, verifies passkeys server-side, and uses WordPress capabilities, nonces, sanitization, and escaping throughout the admin interface.
Setup
Magic links
- Enable Magic links in AuthLatch > Settings.
- Set the default link expiry.
- Configure the email subject and body.
- Configure SMTP if the host disables PHP mail.
- Users can request a login link from the login page with either username or email.
- Enabled self-service roles can also send a login link from AuthLatch in the admin sidebar.
Passkeys
- Enable Passkeys in AuthLatch > Settings.
- Select the roles allowed to use passkeys.
- Set the maximum passkeys per user.
- Use HTTPS on the live site.
- Users with allowed roles can open AuthLatch in the admin sidebar and click Add passkey.
- Users can revoke old passkeys from the same page.
Self-service sidebar page
- Open AuthLatch > Settings.
- Select roles under Self-Service Page > Sidebar access roles.
- Only selected roles will see the AuthLatch sidebar page.
- The self-service page lets users manage their own passkeys and send a magic link to their own email.
Password fallback
- Keep Username/password login enabled if normal WordPress login should remain available.
- Keep admin password fallback enabled if administrators should still be able to log in with a password when password login is otherwise disabled.
SMTP
- Enable Use SMTP for WordPress emails.
- Enter host, port, encryption, username, password, from email, and from name.
- Save settings.
- Send a test email from AuthLatch > Settings.
Privacy
AuthLatch stores authentication-related records in the WordPress database, including hashed magic-link tokens, passkey public-key data, hashed IP values for audit and optional IP binding, and configuration settings. AuthLatch does not store plaintext magic-link validators. SMTP passwords are encrypted with WordPress salts before storage.
Third-Party Libraries
AuthLatch includes the MIT-licensed lbuchs/WebAuthn library for WebAuthn/FIDO2 server-side verification.
Installation
- Upload the plugin ZIP through Plugins > Add New > Upload Plugin.
- Activate AuthLatch.
- Open AuthLatch > Settings from the WordPress admin sidebar.
- Configure magic links, passkeys, self-service roles, branding, and SMTP if needed.
- Save settings.
- Send a test SMTP email before relying on email-only login.
Frequently asked questions
Does AuthLatch require a separate SMTP plugin?
No. AuthLatch includes SMTP settings and uses WordPress PHPMailer.
Does passkey login require HTTPS?
Yes. WebAuthn passkeys require a secure browser context, usually HTTPS. Localhost is generally allowed for development.
Where does a user add a passkey?
Allowed users can open AuthLatch from the WordPress admin sidebar and use Add passkey. Passkeys can also be managed from the WordPress profile page.
Can administrators keep password login as a fallback?
Yes. The settings include an administrator password fallback option.
Can users request magic links for their own account?
Yes. If their role is selected in Self-Service Page settings, users can open AuthLatch in the sidebar and send a login link to their account email.
Does AuthLatch send data to an external service?
AuthLatch does not send authentication data to an AuthLatch service. If SMTP is enabled, email is sent through the SMTP server configured by the site administrator.
Changelog
1.0.2
- Updated compatibility metadata for WordPress 7.1.
1.0.1
- Updated compatibility metadata for WordPress 7.0.
1.0.0
- Initial WordPress submission release.
- Added role-gated self-service AuthLatch sidebar page.
- Added user-managed passkey registration and revocation from the sidebar.
- Added user self-service magic-link email action.
- Added plugin action link for settings.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best AuthLatch alternatives
All magic link plugins →FAQ
AuthLatch: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 29, 2026
Is AuthLatch free?
Yes. AuthLatch is free to download and use from the official WordPress.org plugin directory.
Is AuthLatch safe to use in 2026?
AuthLatch works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.
How many websites use AuthLatch?
AuthLatch is active on <10 WordPress websites and has been downloaded 140 times since it launched in August 2026. It was downloaded 89 times in the last 30 days.
Does AuthLatch work with WordPress 7.1?
Yes. The developer has tested AuthLatch up to WordPress 7.1.2, the latest release. It requires WordPress 6.4 or newer.
What PHP version does AuthLatch need?
AuthLatch requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was AuthLatch last updated?
The latest version, 1.0.2, was released on August 27, 2026 (1 month ago).
Who makes AuthLatch?
AuthLatch is developed and maintained by Rayhan Sardar.
What are the best alternatives to AuthLatch?
The most popular alternatives to AuthLatch are Magic Login (3K+ installs), Social Login, Passkeys, Mag… (90+ installs) and Nextfly Domain Restricted A… (<10 installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card