BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
OneCode Login icon
Actively maintained Tested up to 7.0.6 #46 in authentication

OneCode Login

Simple and secure passwordless login using email verification codes. No passwords to remember, just enter your email and verify with a 6-digit code.

Active installs200+100+ tier
Downloads · 30d235▼ -20.3% vs prev. 30d
Rating5/52 reviews
Health score67/100Good
All-time downloads1.5KSince Jan 2026
Support resolved—No recent threads
RequiresWP 5.8PHP 7.4+
Downloads · 7d60▲ +7.1% week over week
Our verdict

Solid choice

OneCode Login is a solid plugin choice in 2026, with a few things worth checking first. It runs on 200+ sites, is rated 5/5 and was last updated 2 months ago, and scores 67/100 on our health check.

  • Small user base (200+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

102132Jul 1Aug 14Sep 28
Yesterday8
Daily average (1y)6
Peak day43Jul 27, 2026
Last 12 months1.5K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where OneCode Login stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
authentication >100 4,290 Best authentication plugins →
email >100 10,000 Best email plugins →
login >100 8,587 Best login plugins →
otp #43 386 Best otp plugins →
passwordless #36 231 Best passwordless plugins →

Version adoption

Share of active sites per release.

  • 1.1100.0%

Rating breakdown

★★★★★★★★★★ 5 from 2 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About OneCode Login

From the official readme · v1.1.1

Description

OneCode Login provides a modern, passwordless authentication experience for your WordPress site. Instead of traditional passwords, users receive a secure 6-digit verification code via email.

Key Features

  • Passwordless Authentication – Users log in with just their email address
  • 6-Digit Verification Codes – Secure, time-limited codes sent via email
  • Rate Limiting – Built-in protection against brute force attacks
  • Request ID Binding – Each code is bound to a specific login session for enhanced security
  • Neutral Feedback – Prevents user enumeration attacks by not revealing if an email exists
  • Customizable – Configure expiry times, cooldowns, and email templates
  • Accessible – Full keyboard navigation and screen reader support
  • Gutenberg Block – Easy to add login forms to any page
  • Shortcode Support – Use [onecode_login] anywhere
  • wp-login.php Integration – Optionally replace the default WordPress login
  • Developer API – Other plugins can use OneCode Login as an email one-time-code (OTP) service to verify a visitor’s email — see the Developer information section

Security Features

  • Cryptographically secure code generation
  • Codes and magic-link tokens are stored HMAC-hashed, never in plain text
  • Configurable code expiry (default: 10 minutes)
  • Resend cooldown to prevent spam
  • IP-based and email-based rate limiting
  • Automatic lockout after failed attempts
  • Codes are single-use and invalidated after successful login

Use Cases

  • Membership sites where password fatigue is an issue
  • Customer portals requiring simple authentication
  • Internal tools where security without complexity is needed
  • Any site wanting to improve user experience

Developer information

Other plugins on the same site can use OneCode Login as a generic email
one-time-code (OTP) service — for example to verify a guest’s email before
letting them act. OneCode emails the code and verifies it; your plugin keeps
full control of its own login/session (OneCode only asserts that the code is
valid for the email — it never logs anyone in). It works for any email
address; the address does not need a WordPress account.

All entry points are plain functions (and matching filters), so you do not need
a hard dependency on any class. The API is gated by the Settings → Advanced →
Enable developer API
toggle.

Detect support (side-effect free — never call the request hook just to probe):

if ( function_exists( 'onecode_login_request_otp' ) && onecode_login_supports( 'otp' ) ) { ... }
  1. Start authentication — email a code and receive a handle:

    $handle = onecode_login_request_otp( $email, array( ‘consumer’ => ‘my_plugin’ ) );
    // $handle = array( ‘request_id’, ‘auth_secret’, ‘expires_in’ (seconds), ‘expires_at’ (UTC), ‘sent’ )
    // On failure: a WP_Error (codes: disabled, invalid_request, rate_limited, cooldown).

Keep request_id and auth_secret server-side (e.g. in a transient tied to the
visitor). The auth_secret is NEVER shown to the customer — it is what stops an
outsider who only knows the email from completing verification by guessing codes.

  1. Complete authentication — the customer gives your plugin the code from the email:

    $result = onecode_login_verify_otp( array(
    ’email’ => $email,
    ‘request_id’ => $handle[‘request_id’],
    ‘code’ => $code_from_customer,
    ‘auth_secret’ => $handle[‘auth_secret’],
    ‘consumer’ => ‘my_plugin’,
    ) );
    // Success: array( ‘valid’ => true, ’email’ => … ). Failure: WP_Error.

On failure show a generic message to the user (the API intentionally returns a
single verify_failed code so it can’t be used as an oracle).

Filters are also available for loose coupling: onecode_login_request_otp
($pre, $email, $args) and onecode_login_verify_otp ($pre, $args).

Discovery and capabilities:

  • onecode_login_supports( $feature ) — returns true for 'otp',
    ‘identity_assertion’, 'any_email' and 'api_enabled'. It reports whether
    the feature is usable right now: while the developer API toggle is off every
    key returns false, so a gate on supports() keeps you from offering a flow
    the API would refuse. Use your own fallback in that case.
  • onecode_login_api()->is_enabled() — the developer API toggle on its own.
  • onecode_login_api() — returns the OneCode_Login_API service instance.
  • OneCode_Login_API::VERSION — the API contract version (independent of the
    plugin version), so you can feature-gate against the API surface.
  • do_action( 'onecode_login_api_init', $api ) — fires once the API is ready;
    bind to it if you want to wire up as soon as OneCode Login loads.

Reference: $args['consumer'] (a short [a-z0-9_-] label identifying your
integration) is required on both calls — it isolates your codes and rate limits
from the built-in login and from other consumers. Both request and verify are
rate-limited by OneCode, returning rate_limited / cooldown WP_Errors you can
surface to the user.

Installation

  1. Upload the onecode-login folder to /wp-content/plugins/
  2. Activate the plugin through the Plugins menu in WordPress
  3. Go to Settings > OneCode Login to configure options
  4. Add the login form using the [onecode_login] shortcode or Gutenberg block

Shortcode Options

  • redirect_to – URL to redirect after successful login
  • button_text – Custom text for the send code button
  • verify_text – Custom text for the verify button

Example: [onecode_login redirect_to="/dashboard" button_text="Get Code"]

Frequently asked questions

Does this replace password login completely?

By default, no. OneCode Login works alongside traditional password login. However, you can enable the “Replace wp-login.php” option to use OneCode Login as the primary login method.

What happens if the email does not arrive?

Users can request a new code after the cooldown period (default: 60 seconds). Check your server email configuration if emails consistently fail to deliver.

Is this secure?

Yes. The plugin uses cryptographically secure random number generation, time-limited codes, rate limiting, and request binding to prevent various attack vectors.

Can I customize the email template?

Yes. Go to Settings > OneCode Login > Email tab to customize the subject and body of verification emails. You can use placeholders like {code}, {expires}, {site_name}, and {user_email}.

Does it work with multisite?

The plugin is designed for single-site installations. Multisite compatibility may be added in future versions.

What if a user does not have an account?

The plugin only allows existing users to log in. For security reasons, it does not reveal whether an email address has an account – users always see the same “check your email” message.

Changelog

1.1.1

  • Security fix: onecode_login_supports() no longer reports support while the developer API is switched off. Integrating plugins now get the correct answer and can fall back accordingly.
  • Added an api_enabled capability key to onecode_login_supports().

1.1

  • New: developer API — other plugins on the same site can use OneCode Login as a generic email one-time-code (OTP) service. They request a code for any email address, then verify the code together with a server-side secret. Identity assertion only: OneCode confirms the code is valid for the email but never logs anyone in, so the integrating plugin keeps full control of its own session. See the “Developer information” section for the code-level integration.
  • New: api_enabled setting (Advanced tab) to turn the developer API on or off.
  • Security: verification codes and magic-link tokens are now stored HMAC-hashed instead of in plain text.
  • Security: client IP detection no longer trusts spoofable proxy headers by default (opt in via the onecode_login_trust_proxy_headers filter when behind a trusted proxy).
  • Security: magic-link verification is now rate-limited per IP as well as per email.
  • Privacy: debug logging no longer records verification codes or full email addresses (emails are masked).
  • Privacy: added WordPress personal-data exporter and eraser, plus a suggested Privacy Policy snippet.
  • Internal: codes are scoped per channel so the developer API and the built-in login never interfere with each other; verification uses an atomic single-use claim.
  • Note: upgrading from 1.0.2 or earlier clears any pending codes/tokens once (storage-format change); users simply request a new code.

1.0.2

  • Fix: assets are now loaded reliably when the shortcode/block is present on the page (prevents first-submit failure under aggressive page caching or JS optimization).
  • Fix: clear leftover code/rate-limit rows from earlier versions whose timestamps were stored in the local PHP timezone instead of UTC.

1.0.1

  • Small bug fixes

1.0.0

  • Initial release
  • Passwordless login with 6-digit verification codes
  • Rate limiting and brute force protection
  • Customizable email templates
  • Gutenberg block and shortcode support
  • wp-login.php integration option
  • Full accessibility support

Full changelog on WordPress.org →

Screenshots

Admin settings page with all configuration options
Admin settings page with all configuration options
Email input form for passwordless login
Email input form for passwordless login
6-digit verification code entry screen
6-digit verification code entry screen

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best OneCode Login alternatives

All authentication plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Limit Login Attempts Limit Login Attempts Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable. by Automattic 300K+ ★★★★★★★★★★ 4.6 (202) 3 years ago 48
2 WPS Limit Login WPS Limit Login WPS Limit login limit connection attempts by IP address by NicolasKulka 100K+ ★★★★★★★★★★ 4.9 (83) 2 weeks ago 81
3 Two Factor Two Factor Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email… by WordPress.org 100K+ ★★★★★★★★★★ 4.8 (208) 2 days ago 88
4 WP-Members Membership Plugin WP-Members Membership Plugin The original WordPress membership plugin with content restriction, user login, custom… by Chad Butler 50K+ ★★★★★★★★★★ 4.6 (273) 3 weeks ago 89
5 Google Authenticator Google Authenticator Google Authenticator for your WordPress blog. by Ivan 20K+ ★★★★★★★★★★ 4.3 (135) 1 month ago 83
6 miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) miniOrange 2FA Free 2FA plugin for unlimited users with Passkey, Google Authenticator, Email/SMS OTP, Push… by miniOrange 10K+ ★★★★★★★★★★ 4.5 (385) 1 week ago 88
7 WP Limit Login Attempts WP Limit Login Attempts Limit rate of login attempts and block IP temporarily. Brute force attack protection. GDPR… by Arshid 10K+ ★★★★★★★★★★ 4.6 (300) 2 weeks ago 88
8 Login for Google Apps by WPAuth Login for Google Apps by WPAuth Simple secure login and user management through your Google Workspace for WordPress (using… by Syed Balkhi 10K+ ★★★★★★★★★★ 4.6 (64) 8 hours ago 88
9 Login by Auth0 Login by Auth0 Login by Auth0 provides improved username/password login, Passwordless login, Social login… by Auth0 10K+ ★★★★★★★★★★ 3.1 (18) 2 years ago 34
10 Two Factor (2FA) Authentication via Email Two Factor (2FA) Authentication via Email Enable one-click login with this WordPress Two-Factor Authentication (2FA) plugin… by Sully 9K+ ★★★★★★★★★★ 5 (4) 3 weeks ago 83

FAQ

OneCode Login: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 29, 2026

Is OneCode Login free?

Yes. OneCode Login is free to download and use from the official WordPress.org plugin directory.

Is OneCode Login safe to use in 2026?

OneCode Login is a solid plugin choice in 2026, with a few things worth checking first. It runs on 200+ sites, is rated 5/5 and was last updated 2 months ago, and scores 67/100 on our health check.

How many websites use OneCode Login?

OneCode Login is active on 200+ WordPress websites and has been downloaded 1,535 times since it launched in January 2026. It was downloaded 235 times in the last 30 days.

Does OneCode Login work with WordPress 7.1?

OneCode Login is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does OneCode Login need?

OneCode Login requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was OneCode Login last updated?

The latest version, 1.1.1, was released on July 26, 2026 (2 months ago).

Who makes OneCode Login?

OneCode Login is developed and maintained by oaron.

What are the best alternatives to OneCode Login?

The most popular alternatives to OneCode Login are Limit Login Attempts (300K+ installs), WPS Limit Login (100K+ installs) and Two Factor (100K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.