BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
SUC – same user credentials icon
Possibly abandoned Tested up to 6.5.13

SUC – same user credentials

The plugin synchronizes users with a main site, allowing you to access all sites where the plugin is installed with the same credentials.

Active installs10+10+ tier
Downloads · 30d44▲ +120% vs prev. 30d
Rating—0 reviews
Health score23/100At risk
All-time downloads1.6KSince May 2024
Support resolved—No recent threads
RequiresWP 6.0PHP 7.4+
Downloads · 7d7▼ -53.3% week over week
Our verdict

Consider an alternative

SUC – same user credentials shows warning signs in 2026 — compare the alternatives below before installing. It runs on 10+ sites and was last updated 2 years ago, and scores 23/100 on our health check.

  • Small user base (10+ active installs)
  • Very few reviews so far
  • No update in 2 years
  • Only tested up to WordPress 6.5 (latest is 7.1)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

123Jul 12Aug 25Oct 9
Yesterday2
Daily average (1y)1
Peak day5Oct 25, 2025
Last 12 months359

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where SUC – same user credentials stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
authentication >100 4,458 Best authentication plugins →
multisite user >100 4,106 Best multisite user plugins →
share login >100 1,450 Best share login plugins →
Users Sync >100 3,579 Best Users Sync plugins →

Version adoption

Share of active sites per release.

  • 1.0100.0%

About SUC – same user credentials

From the official readme · v1.0.0

Description

The plugin synchronizes users with a main site, allowing you to access all sites where the plugin is installed with the same credentials.

  • One website must be configured as a server, while the other sites must be configured as clients.
  • Users registered on the server site can now access client sites using the same login credentials.
  • In the client site, if the user does not exist, a new user is created with the data coming from the server. You can customize the data to be saved on the client site through several hooks described later.
  • If the user already exists (checks the username) then the plugin updates the user information.
  • If the user exists on the client, but not on the server, the plugin blocks access by changing the password to the user saved on the client.

  • For security reasons the plugin does not synchronize administrators.

  • When you click on recover password from a client site you are redirected to the server site to recover your password. Once you have recovered the password you return to the client site login. When you try to register a user from a client site you are redirected to the server site to register the user.
  • If a user has logged in to a client site and logs in again through cookies, then without logging in again the system updates the user data with the server data once a day. If the user no longer exists on the server, he or she is logged out of the client site.
  • Client users are never deleted even if they are no longer present on the server.
  • Be careful if a user already exists on the client with the same email, but different user login, the user is not logged in.

Security

Communications take place via APIs protected through an encrypted token system. Usernames and passwords are never passed in clear text or through a basic authentication system.

Synchronizing administrators is not allowed, administrators must be managed locally.

Some user metadata is not passed because it is specific to the configuration of each individual site.

Logs

All operations are logged both on the client site and on the server.

Customizations

By default the plugin synchronizes all user except administrators. By default The plugin synchronizes all user data, roles, and metadata.

However, you can customize who and what to sync through many specially created filters and hooks.

First you may want to choose which users you want to sync and which you don’t. You can choose which user roles you want to sync. This way if the user has a certain role it will be synchronized, otherwise not. You can do this through the sucw-roles-exclude-all-sync-except filter placed in the client site.

apply_filters(‘sucw-roles-exclude-all-sync-except’, [‘subscriber’]);
(CLIENT) Excludes all roles from synchronization except those specified
This overrides the filter ‘sucw-roles-to-exclude-sync’!
param array $array_exclude the list of default roles [‘subscriber’]
since 1.0.0

Otherwise you can choose to sync all users except those who have a certain role.

apply_filters(‘sucw-roles-to-exclude-sync’, [‘administrator’])
(CLIENT) These are the roles that do not need to synchronize
If active The filter ‘sucw-roles-exclude-all-sync-except’ will be ignored
param array $array_exclude the list of default roles [‘administrator’]
since 1.0.0

The same role configuration entered in the client sites should be placed in the server site.

add_filter(‘sucw-roles-exclude-all-sync-except’, []);
(SERVER) Exclude all roles from synchronization except those specified
If active the ‘sucw-block-user-roles’ filter will be ignored
param array $array_exclude the list of default roles []
since 1.0.0

add_filter(‘sucw-block-user-roles’, [‘administrator’]);
(SERVER) If the user has one of the blocked roles I won’t let them through
var array $block_user_roles
return array
since 1.0.0

Below are the other filters and hooks you can use to customize your plugin configuration.

apply_filters(‘sucw-update-roles’, $roles)
(CLIENT) The list of roles to save in the user profile when creating or updating the user. if it is an empty array it does not update the roles.
since 1.0.0

do_action( ‘sucw-update-user’, $user_id, $user_data )
(CLIENT) It is called after updating or creating a user
param: int $user_id the user id
object $user_data user data
since 1.0.0

apply_filters(‘sucw-remote-args’, $args)
(CLIENT) These are the arguments for the client to call the server
param array $args Default [‘method’:’POST’, ‘timeout’:$timeout, ‘redirection’:2, ‘httpversion’:’1.0′, ‘blocking’:true, ‘headers’:$headers, ‘cookies’:[]]
since 1.0.0

apply_filters(‘sucw-remote-timeout’, 15)
(CLIENT) The server call times out
param int $timeout Default 15
since 1.0.0

apply_filters(‘sucw-allow-metadata’, true)
(CLIENT) Allows you to update metadata
param bool $allow_metadata Allows you to update metadata
if false it does not update the metadata, if it is an array it only updates the metadata present in the array
since 1.0.0

apply_filters(‘sucw_register_url’, $url)
(CLIENT) Manages the registration link
param string $url il link di default
since 1.0.0

apply_filters(‘sucw-lostpassword-url’, url)
(CLIENT) Manages lost password link
param string $url il link di default
since 1.0.0

apply_filters( ‘sucw-htaccess’, true )
(CLIENT) If the server uses htaccess or you need to make the call to the API via /?rest_route (false)
since 1.0.0

apply_filters(‘sucw-api-response’, $response, ‘login|check-user’)
(SERVER) The server’s response to the login client api call
param array $response [‘response_status’=>’ok’, ‘user’=>$user] | [‘response_status’=>’error’, ‘message’=>’…’]
param string $type login | check-user
since 1.0.0

apply_filters(‘sucw-log-limit’, 1000)
(SERVER & CLIENT) The number of logs to keep on both server and client
param int $log_limit Default 1000
since 1.0.0

TIPS & TRICKS

If the user misspells the password, it may appear as an error message that the user does not exist. To make the error messages more generic you can use the following code:

add_filter('login_errors', 'login_message', 10, 1);
function login_message($error ) {
    if ($error != '') {
        $error = "Incorrect username or password";
    }
    return $error;
}

To add a new role you need to create code like this on both the client and server sites

add_role('my_custom_role', 
    __( 'My Custom Role' ), 
    array( 'read' => true, 'read_private_posts' => true, )
);

Credits

Same user credentials as started in 2024 by Giulio Pandolfelli
Thanks to Ekebu for the supports.

Installation

The plugin must be installed on two or more sites. The first site must be configured as a server, while the others as clients. Remember to save your settings once you have configured the plugin.

Server:
Click on the “Server” box and save.

Client:
Copy the token generated by the server and paste it into the client’s “Token” box. Copy the server URL into the URL. Save.

When you save the client settings it tries to connect to the server to verify that everything is working correctly. If the server does not have active htaccess, the API address changes and the following code must be applied to the client’s functions.php:

add_filter( 'sucw-htaccess', 'sucw_htaccess' );
 function sucw_htaccess() {
    return false;
 }

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best SUC – same user credentials alternatives

All authentication plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Limit Login Attempts Limit Login Attempts Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable. by Automattic 300K+ ★★★★★★★★★★ 4.6 (202) 4 years ago 48
2 WPS Limit Login WPS Limit Login WPS Limit login limit connection attempts by IP address by NicolasKulka 100K+ ★★★★★★★★★★ 4.9 (83) 3 weeks ago 81
3 Two Factor Two Factor Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email… by WordPress.org 100K+ ★★★★★★★★★★ 4.8 (208) 2 weeks ago 88
4 WP-Members Membership Plugin WP-Members Membership Plugin The original WordPress membership plugin with content restriction, user login, custom… by Chad Butler 50K+ ★★★★★★★★★★ 4.6 (272) 1 month ago 74
5 Google Authenticator Google Authenticator Google Authenticator for your WordPress blog. by Ivan 20K+ ★★★★★★★★★★ 4.3 (135) 2 months ago 83
6 miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) miniOrange 2FA Free 2FA plugin for unlimited users with Passkey, Google Authenticator, Email/SMS OTP, Push… by miniOrange 10K+ ★★★★★★★★★★ 4.5 (385) 1 week ago 88
7 WP Limit Login Attempts WP Limit Login Attempts Limit rate of login attempts and block IP temporarily. Brute force attack protection. GDPR… by Arshid 10K+ ★★★★★★★★★★ 4.6 (300) 4 weeks ago 88
8 Login for Google Apps by WPAuth Login for Google Apps by WPAuth Simple secure login and user management through your Google Workspace for WordPress (using… by Syed Balkhi 10K+ ★★★★★★★★★★ 4.6 (64) 2 weeks ago 88
9 Login by Auth0 Login by Auth0 Login by Auth0 provides improved username/password login, Passwordless login, Social login… by Auth0 10K+ ★★★★★★★★★★ 3.1 (18) 2 years ago 34
10 Two Factor (2FA) Authentication via Email Two Factor (2FA) Authentication via Email Enable one-click login with this WordPress Two-Factor Authentication (2FA) plugin… by Sully 9K+ ★★★★★★★★★★ 5 (4) 4 weeks ago 83

FAQ

SUC – same user credentials: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 10, 2026

Is SUC – same user credentials free?

Yes. SUC – same user credentials is free to download and use from the official WordPress.org plugin directory.

Is SUC – same user credentials safe to use in 2026?

SUC – same user credentials shows warning signs in 2026 — compare the alternatives below before installing. It runs on 10+ sites and was last updated 2 years ago, and scores 23/100 on our health check.

How many websites use SUC – same user credentials?

SUC – same user credentials is active on 10+ WordPress websites and has been downloaded 1,603 times since it launched in May 2024. It was downloaded 44 times in the last 30 days.

Does SUC – same user credentials work with WordPress 7.1?

SUC – same user credentials is officially tested up to WordPress 6.5.13, while the latest release is 7.1.3. It may still work, but try it on a staging site first.

What PHP version does SUC – same user credentials need?

SUC – same user credentials requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was SUC – same user credentials last updated?

The latest version, 1.0.0, was released on May 24, 2024 (2 years ago).

Who makes SUC – same user credentials?

SUC – same user credentials is developed and maintained by giuliopanda.

What are the best alternatives to SUC – same user credentials?

The most popular alternatives to SUC – same user credentials are Limit Login Attempts (300K+ installs), WPS Limit Login (100K+ installs) and Two Factor (100K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.