GSheet Membership
GSheet Membership lets you use a private Google Sheet as your membership database.
Solid choice
GSheet Membership is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 4 days ago, and scores 64/100 on our health check.
- Actively developed — last update 4 days ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where GSheet Membership stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| association | >100 |
| branches | #62 |
| Google Sheets | >100 |
| membership | >100 |
| stripe | >100 |
About GSheet Membership
From the official readme · v4.9.0Description
Access — the login and page gate
GSheet Membership lets you use a private Google Sheet as your membership database.
- Truly private — the sheet is never shared publicly. Access is granted exclusively to a Google Service Account that you control.
- Login gate — only users whose email address appears in the sheet can log in to WordPress.
- Membership codes — each row contains an email address and a membership code (e.g. GOLD, SILVER, PLATINUM).
- Per-page restrictions — set required membership code(s) on any page or post via a sidebar panel.
- Flexible access-denied handling — redirect to a custom URL or show a configurable inline message.
- Encrypted roster cache — the entire fetched roster is encrypted as one authenticated payload before it is cached in a non-autoloaded WordPress option. On a cache hit, the whole payload is decrypted for the existing lookups; it is not encrypted or decrypted one member at a time. The OAuth2 access token is cached separately.
- Site Mode — every site runs as Main (a single roster) or Chapter (its own local roster, alongside or instead of the main one) — Chapter mode is enabled by the separate Chapters add-on.
- Expiration handling — warn members as their membership approaches its end, grant a configurable grace period after it lapses, and show a custom message once access is revoked.
- Extra user-info fields — map any additional sheet columns (address, phone, region, or anything else you track) so members can view and verify them on the front end via
[gsma_user_info]. - Custom login page — host the sign-in form on any WordPress page you choose with the
[gsma_login_form]shortcode, instead of WordPress’s default login screen. - Front-end appearance controls — force the login form and status panel to keep their original colors if your theme recolors them, and scale their text size independently of your theme.
- Two code-matching modes — require an exact membership code, or “letters mode,” where a member’s code must simply contain every letter in the required set (e.g. a required code of “AB” matches any member code containing both A and B).
How it works
The plugin authenticates using a Google Service Account — a special non-human Google account your server uses to read and update the sheet. You share the spreadsheet with it; no one else can access the sheet. With OpenSSL available, the saved service-account JSON is encrypted at rest; the roster cache is only written when it can be encrypted. The two use separate keys derived from this WordPress installation’s security salts. They are not exposed in the browser or source code. The entire cached roster is decrypted in server memory when it is read; this does not encrypt old backups made before the upgrade.
Signing in
There’s no separate account-creation step for members. A member already on the roster enters their email on your sign-in page: the first time, a 6-digit verification code is emailed to them and they’re prompted to create a password after entering it; after that, they sign in with the password directly. See the FAQ entry below for the full flow.
Optional Pro add-on
GSheet Membership Pro adds authenticated mailbox sending, Group Email (including Mailchimp campaign delivery), Email-in, File Delivery links and optional PDF watermarks, PayPal checkout, gift purchases, editable membership levels, and admin tools to retry failed sheet writes and refund supported purchases. Pro can also sync roster contacts to Mailchimp and EmailOctopus without sending a campaign; EmailOctopus is a sync option, not a campaign-delivery gateway. The Access and Sales admin screens show read-only previews of relevant Pro features and a direct upgrade button. After purchasing, install and activate the Pro add-on, then complete its license activation; the free plugin’s existing settings stay in place.
Built for organizations with branches or chapters
Most membership plugins assume one site and one member list. Many real organizations don’t work that way: a national society with local chapters, an alumni association with regional groups, a union with locals. GSheet Membership was designed for exactly that structure:
- One national roster, many chapter rosters — the national organization keeps the master membership sheet; each chapter keeps its own local roster sheet. Both live in ordinary Google Sheets the organization owns.
- Each chapter runs its own WordPress site — with its own pages, branding and admins, while membership checks stay consistent: a chapter site can honour the national roster, its local roster, or both.
- Chapter-local sales and email — in chapter mode, membership sales write to the chapter’s own roster, and group email (Pro add-on) goes to the local chapter list.
- Your organization owns the data — roster sheets stay in your own Google account rather than a hosted membership database. Chapter mode requires the separately licensed Chapters add-on on participating chapter sites.
Chapter mode is provided by the GSheet Membership — Chapters add-on; the free plugin covers everything a single-roster organization needs.
External services
This plugin connects to the following third-party services to provide its core functionality:
Google Sheets API and Google OAuth2 (developers.google.com)
Used to read and write membership data to your private Google Sheet, and to authenticate as your Google Service Account. When a page’s access is checked, when a purchase is recorded, or when you save settings and test the connection, the plugin sends: your Service Account’s signed authentication request to https://oauth2.googleapis.com/token, and membership-related row data (emails, membership codes, and — depending on which features you use — names, addresses, and purchase details) to https://sheets.googleapis.com. This only occurs because you have configured a Google Service Account and Spreadsheet ID; no data is sent to Google until you do so.
Google APIs Terms of Service: https://developers.google.com/terms
Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy
Google Privacy Policy: https://policies.google.com/privacy
Stripe (stripe.com)
Used to process membership purchases via Stripe Checkout. Card details are entered on Stripe’s hosted checkout page, not this site. With the free plugin’s Stripe Connect flow, the hosted GSheet Connect service creates the Checkout Session and relays Stripe’s confirmation to the site; Pro can instead use your own Stripe API keys and a direct Stripe webhook. Stripe is contacted only when the gateway is enabled and connected or configured.
Stripe Terms of Service: https://stripe.com/legal/ssa
Stripe Privacy Policy: https://stripe.com/privacy
GSheet Connect (access-manager-pro.replit.app) — Stripe Connect mode
The plugin’s hosted payment service is used for Stripe Connect sales, including on a Pro site until its own Stripe keys are saved for the active mode. It handles “Connect with Stripe” onboarding, creates the Stripe Checkout Session for each purchase (applying the disclosed platform commission), processes refunds you issue from the dashboard, and relays Stripe’s payment confirmations back to your site. The plugin sends: your connected Stripe account ID, the purchase amount, currency and description, the buyer’s email address, and your site’s webhook address to https://access-manager-pro.replit.app. The service does not keep a membership roster; payment processing itself is performed by Stripe. A site using its own Stripe API keys instead of Connect does not use this service for checkout.
Service overview: https://access-manager-pro.replit.app
PayPal (paypal.com) — requires the GSheet Membership Pro add-on
Used to process membership purchases via PayPal Checkout as an alternative to Stripe. Only active if you install the Pro add-on and configure your PayPal credentials; the free plugin does not send any data to PayPal on its own.
PayPal User Agreement: https://www.paypal.com/us/legalhub/paypal/useragreement-full
PayPal Privacy Statement: https://www.paypal.com/us/legalhub/paypal/privacy-full
Mailchimp (mailchimp.com) — requires the GSheet Membership Pro add-on
Optional campaign delivery and roster-sync method in Pro. With an API key and selected audience, classic sends sync the current membership filter; segments-mode sends sync the full roster and target a segment. The optional Sync Roster action updates the audience without sending a campaign. Pro sends member email addresses, names, and optional personalized link fields from the Google Sheet to https://.api.mailchimp.com to add, update, or archive audience contacts as appropriate; it does not override contacts who unsubscribed or were cleaned. Only active when Pro is installed and Mailchimp is configured; the free plugin sends no data to Mailchimp on its own.
Mailchimp Standard Terms of Use: https://mailchimp.com/legal/terms/
Intuit Mailchimp Privacy Statement: https://www.intuit.com/privacy/statement/
EmailOctopus (emailoctopus.com) — requires the GSheet Membership Pro add-on
An optional roster-sync destination, not a Group Email campaign-sending gateway. If configured, Pro sends member email addresses, names, and optionally a personalized attachment-link field to https://api.emailoctopus.com to update the selected list without sending a campaign. The provider-card Sync Roster action syncs the full local recipient roster; Compose’s Sync Roster action uses the selected membership filter. The free plugin sends no data to EmailOctopus on its own.
EmailOctopus Terms of Service: https://emailoctopus.com/legal/terms
EmailOctopus Privacy Policy: https://emailoctopus.com/legal/privacy
Installation
- Upload the
membership-google-sheetsfolder to/wp-content/plugins/(or upload the ZIP under Plugins → Add New → Upload Plugin). - Activate the plugin through the Plugins screen.
- Follow the Google setup steps below.
- Go to Membership Access (top-level menu in the WordPress admin sidebar) and configure the plugin.
- Click Save & Test Main Roster to verify the service account can read your sheet.
Google setup (~5 minutes)
- Go to https://console.cloud.google.com/ and create or select a project.
- Enable the Google Sheets API (APIs & Services → Library → search “Sheets”).
- Create a Service Account (IAM & Admin → Service Accounts → Create).
- Generate a JSON key for the service account (Keys tab → Add Key → JSON). Download the file.
- Open your Google Sheet → Share → add the service account email (looks like
name@project.iam.gserviceaccount.com) as an Editor (required for the Sales feature and the Pro add-on’s Group Email; Viewer is enough if you only use page protection). The sheet stays private to everyone else. - In Membership Access (top-level menu in the WordPress admin sidebar), paste the full contents of the JSON key file and enter your Spreadsheet ID.
When you click Save & Test Main Roster, the result identifies the exact service-account email in use and checks authentication, spreadsheet access, available tabs, the selected tab, row reading, and required column mappings in order. If a check fails, the result names the Main roster and gives a specific correction without displaying the private key, access token, raw JSON, or Google response body.
For the Sheet (Tab) Name, leave the field blank to use the spreadsheet’s first tab automatically. If an explicit tab name is missing, the connection result lists the available tab names and tells you to choose one or clear the field.
Restricting pages
- Edit any page or post in WordPress.
- Find the Membership Access panel in the editor sidebar.
- Enter the required membership code(s), comma-separated (e.g.
GOLD, PLATINUM). - Save the page.
Codes are compared according to the Access Control Match Mode setting (exact match by default, or “letters mode” — see Configuration reference below). Leave the field blank for unrestricted access.
Configuration reference
Setting
Description
Service Account JSON
Full contents of the JSON key file downloaded from Google Cloud Console
Spreadsheet ID
The ID from the spreadsheet URL (between /d/ and /edit)
Sheet (Tab) Name
Optional. Leave blank to use the spreadsheet’s first tab automatically.
Email Column
Column letter containing email addresses (default: A)
Membership Code Column
Column letter containing membership codes (default: B)
Header Row Number
Row number of the header; data starts on the next row (default: 1)
Cache Duration (seconds)
How long to keep the encrypted whole-roster cache in WordPress options (default: 300). Set 0 to disable roster caching.
Expiration Mode
Daily (individual dates), Monthly, or Annual (covered-to year).
Warning Window (days)
Days before expiration to start showing members a renewal warning (default: 14)
Grace Period
Continued access after expiration: days in Daily mode; calendar months in Monthly and Annual modes.
Expired-Access Message
Message shown once a membership has expired and the grace period has passed
Login Redirect URL
Where to send unauthenticated visitors trying to access a restricted page
Access-Denied Redirect URL
Where to redirect logged-in users without the required membership
Access-Denied Message
Message to display instead of redirecting (if no redirect URL is set)
Access Control Match Mode
Exact match, or “letters mode,” where the member’s code must contain every letter in the required set
Custom Login Page
The WordPress page containing [gsma_login_form]; leave on Auto-detect to let the plugin find it, or fall back to WordPress’s default login page
Frequently asked questions
Does the Google Sheet need to be shared publicly?
No — never. You only share it with the service account email address. It remains completely private to all other users.
What PHP extensions are required?
The OpenSSL extension is needed to sign the JWT for authentication. It is enabled by default on virtually all shared and managed WordPress hosts (including WP Engine, Kinsta, SiteGround, Flywheel, and others).
Are administrators ever blocked?
No. Users with the manage_options capability always bypass all membership checks.
Where is the Service Account JSON stored?
It is stored in your WordPress database (the wp_options table). With OpenSSL available, the plugin encrypts it using this installation’s security salts; if encryption is unavailable, the credential-saving routine can retain plaintext rather than replace a working credential with unusable ciphertext. Check the encryption status on the Access settings screen. It is never sent to the browser or written to a file by the plugin. Keep the salts and database backups secure.
How quickly do membership changes take effect?
After the encrypted whole-roster cache expires (default 5 minutes / 300 seconds), the next read fetches fresh data and writes a newly encrypted payload. Reduce the cache duration in settings or click Clear Cache to force the next read to refresh.
What happens if the Sheets API is unreachable?
The plugin logs an error and denies access as a safe default. Use Save & Test Main Roster in settings to verify connectivity.
Signing in: verification code, then password
This works for any member already on the roster, whether they got there through the plugin’s own purchase pathway or not — a name typed in manually, imported from a spreadsheet, added after a mailed-in check, however your roster is maintained. The sign-in flow doesn’t care how someone became a member, only that their email is on the sheet. It’s part of the free plugin. There’s no separate account-creation step. A member enters their email, and what happens next depends on whether they’ve signed in before: First time signing in? A 6-digit verification code is emailed to them. They enter the…
Authenticated mailbox sending (Pro add-on)
With the GSheet Membership Pro add-on, you can connect a real mailbox (Google sign-in or an App Password) on the main settings page and route login verification codes, purchase confirmations and gift notices through it. A rejected verification code falls back to the site’s normal mailer. Group Email can also use the authenticated mailbox for batched sending, or use Mailchimp for campaign delivery. Correctly configured mailbox authentication can improve deliverability; it does not guarantee that messages avoid spam filters.
Group Email: message your roster (Pro add-on)
With the GSheet Membership Pro add-on, the Group Email page in Membership Access lets you compose a message and send it to your roster — everyone, or a subset filtered by membership code. Delivery can use the site’s batched mailer (including an authenticated mailbox) or a connected Mailchimp audience. Mailchimp can sync the filtered audience before a classic-mode send or target a segment of the synced full roster. Chapter sites send Group Email to their local chapter roster only, even if their access checks also include the main roster. Direct delivery and Mailchimp campaigns have different…
Email-in: trigger a group email by forwarding a message (Pro add-on)
Email-in is the second way to send a Group Email: instead of the compose form, you forward a message to a dedicated mailbox (e.g. blast@example.org). The plugin checks that mailbox on a schedule (IMAP); a message from an authorized sender that meets the subject-keyword rule is queued under the same audience rules as the compose form. The configured delivery method determines whether it goes through site mail or Mailchimp.
Setting it up
Create a dedicated mailbox for intake (a Gmail / Google Workspace account works well). Don’t reuse a personal inbox — every unread message is examined. For Gmail / Google Workspace: enable IMAP (Gmail Settings → Forwarding and POP/IMAP), turn on 2-Step Verification for the account, and create an App Password (Google Account → Security → App passwords). The regular account password will NOT work over IMAP. In Membership Access → Group Email, fill in the Email-in card: host imap.gmail.com, port 993, the mailbox address as username, and the App Password. Add the email addresses allowed to…
Why the subject keyword matters (spoofing)
The From: address of an email can be forged (spoofing) — an allowlist alone is not sufficient protection for something that can email your whole membership. The required subject keyword adds a second check; keep it private and choose a non-obvious phrase. The keyword is stripped from the subject before delivery. This does not replace mailbox security or prevent an attacker who learns the keyword from sending a forged message.
Audience & attachments
Embed a code filter in the subject to target membership levels: Meeting notes [codes: GOLD,SILVER]. The tag is removed before delivery. Without a tag, the membership code filter saved on the Group Email page is applied; if that filter is blank, all members receive the message. Works on both main and chapter sites. Chapter sites send to the local chapter roster only — the code filter narrows within that roster, regardless of whether access checks also use the main roster. Email-in attachments are uploaded to the media library. With Pro’s File Delivery link mode, every attachment becomes an…
Sales — sell memberships
The Sales half of GSheet Membership puts a configurable buy-membership picker on any page and, on a successful payment, writes (or updates) the buyer’s row in your private Google Sheet so they can immediately log in on your site. Three-dimensional picker — buyers choose Delivery (Electronic / Print / Both) × Duration (1-Year and Lifetime included by default; the Pro add-on adds custom levels and multi-year durations) × Postage (Regular, First Class, Canada/Mexico, Other International), and the price updates live as they change selections. Discrete pricing matrix — you set the exact price for…
Requirements
PHP 7.4+ with the standard openssl, hash, and mbstring extensions (already enabled on every major WordPress host). WordPress 5.9+. The access features (above) configured with a working Service Account — the sales pipeline reuses the same sheet-writer. A Stripe account for live or test payments (a PayPal developer account too, if you use the Pro add-on’s PayPal checkout).
Selling setup
Configure the Access settings first (see Installation above) and confirm the Save & Test Main Roster button succeeds. Go to Membership Sales in the WordPress admin sidebar. Every sub-page shows a “Setup” notice at the top reminding you which shortcode to put on which page. Fill in the Pricing Matrix, Code Matrix, and Payments sub-pages (see Configuration below). Create a page containing only the shortcode [gsma_membership_purchase] — that is the buy page. Create (or pick) a thank-you page and put [gsma_user_info] on it (that shortcode shows the buyer’s status with an inline login form when…
Shortcodes
[gsma_login_form] — renders the sign-in form (email, then a first-time verification code or a returning password) on the page you choose as the Custom Login Page. Independent of the Sales feature — every site can use it. [gsma_membership_purchase] — renders the full picker (Delivery × Duration × Postage) with live total and the Buy membership button. Place this on the page where you want to take payments. [gsms_admin_picker] — admin-only variant of the picker that applies a membership directly to the sheet without any payment. Only site administrators (manage_options) see it; everyone else…
Admin sub-pages
Pricing Matrix — one row per Delivery, one column per Postage, repeated for each Duration. Type a price into a cell to make it saleable, including 0 for a free membership; leave it blank to make that combination unavailable. The Membership Levels block above the grid lets you choose which levels are currently offered for purchase. Code Matrix — the membership code written into the buyer’s sheet row for each combination. Every membership level gets its own row of codes. Levels beyond the built-in 1-Year and Lifetime, including multi-year durations, can be added with the Pro add-on; each new…
Configuration: webhooks
Stripe Connect (free plugin): On the Payments page, click Connect with Stripe and complete Stripe’s hosted onboarding. No Stripe API keys or direct webhook signing secret are entered in the free plugin; payment confirmations are relayed through the hosted Connect service. Direct Stripe API keys (Pro add-on only): If you choose Pro’s own-key mode instead of Connect, configure separate Test/Live keys on the Payments page and register its direct webhook: Developers → Webhooks → Add endpoint. Paste the Stripe Webhook URL shown on the Pro Payments page (ends in…
How to test without real money
The picker can be exercised without a payment gateway. A price of 0 also completes a free membership without sending the buyer to Stripe or PayPal.
Changelog
The plugin folder and text domain changed to membership-google-sheets. Deactivate and delete the old copy after installing this one; settings and data are preserved automatically.
4.9.0
- Encrypt each cached main or chapter roster as a single payload in the WordPress database using a separate key derived from this site’s security salts.
- Encrypt existing plaintext cache entries on first read without extending their expiry; discard cache entries if encryption fails.
4.8.1
- Existing Annual-mode sites now migrate their day-based grace setting to a calendar-month value that never shortens previously granted access.
- The settings page warns before leaving with unsaved edits and shows a fixed Save Settings bar after a field changes.
4.8.0
- Annual expiration mode now uses the same month-based Grace Period field as Monthly mode. Daily mode continues to use days.
- The single Grace Period control switches immediately between days and months when the expiration mode changes.
4.7.0
- Replaced the separate annual-mode checkbox and Sales month-alignment controls with one roster-aware Daily, Monthly, or Annual expiration mode.
- Monthly mode keeps active and recently lapsed renewals anchored to their prior expiration, limits deep-lapse backdating to half the configured grace window, and moves calculated dates forward to the first day of a month.
- Existing sites using annual calendar-year memberships migrate automatically to Annual mode.
4.6.13
- Added an optional Sales expiration rule that extends new date-based memberships to the start of the next even-numbered or odd-numbered month.
- The same adjustment can optionally apply to expired renewals after a configurable number of completed months past their prior expiration. Active renewals, lifetime memberships, annual calendar-year memberships, and rows without an expiration date are unchanged.
4.6.12
- Service-account JSON credentials are now encrypted at rest with authenticated encryption derived from this WordPress installation’s security salts. Existing plaintext credentials migrate automatically, and the Access settings screen reports their encryption status.
- The credential-bearing settings option no longer autoloads on every WordPress request.
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best GSheet Membership alternatives
All association plugins →FAQ
GSheet Membership: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 30, 2026
Is GSheet Membership free?
Yes. GSheet Membership is free to download and use from the official WordPress.org plugin directory.
Is GSheet Membership safe to use in 2026?
GSheet Membership is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 4 days ago, and scores 64/100 on our health check.
How many websites use GSheet Membership?
GSheet Membership is active on <10 WordPress websites and has been downloaded 545 times since it launched in August 2026. It was downloaded 319 times in the last 30 days.
Does GSheet Membership work with WordPress 7.1?
Yes. The developer has tested GSheet Membership up to WordPress 7.1.2, the latest release. It requires WordPress 5.9 or newer.
What PHP version does GSheet Membership need?
GSheet Membership requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was GSheet Membership last updated?
The latest version, 4.9.0, was released on September 25, 2026 (4 days ago).
Who makes GSheet Membership?
GSheet Membership is developed and maintained by gsheetplugins.
What are the best alternatives to GSheet Membership?
The most popular alternatives to GSheet Membership are HelloAsso (4K+ installs), HelloAsso Payments for WooC… (300+ installs) and WP-AMMS (WordPress Plugin:… (20+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card