BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Sticklight icon
Actively maintained Tested up to 7.0.6 #41 in api

Sticklight

Use WordPress authentication and permissions in external React applications via secure REST API endpoints.

Active installs300+100+ tier
Downloads · 30d278▲ +10.3% vs prev. 30d
Rating—0 reviews
Health score64/100Good
All-time downloads1.3KSince May 2026
Support resolved—No recent threads
RequiresWP 6.8PHP 7.4+
Downloads · 7d60▲ +25% week over week
Our verdict

Solid choice

Sticklight is a solid plugin choice in 2026, with a few things worth checking first. It runs on 300+ sites and was last updated 4 weeks ago, and scores 64/100 on our health check.

  • Actively developed — last update 4 weeks ago
  • Small user base (300+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

61218Jul 4Aug 17Oct 1
Yesterday14
Daily average (1y)9
Peak day34Jun 3, 2026
Last 12 months1.3K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Sticklight stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
api >100 10,000 Best api plugins →
authentication >100 4,337 Best authentication plugins →
headless #59 471 Best headless plugins →
react #96 1,656 Best react plugins →
rest-api >100 7,484 Best rest-api plugins →

Version adoption

Share of active sites per release.

  • 1.1100.0%

About Sticklight

From the official readme · v1.1.0

Description

Sticklight Connector securely connects your WordPress site to Sticklight, an AI app-building platform for creating web applications, dashboards, internal tools, and custom interfaces powered by your existing WordPress data.

The plugin extends the WordPress REST API with additional endpoints that allow authenticated Sticklight projects and external applications to retrieve user context and interact with permitted WordPress data. This allows the Sticklight agent to work with content and functionality exposed through WordPress while continuing to respect WordPress authentication, user roles, and capability checks.

Sticklight does not replace WordPress authentication or bypass WordPress permissions. It relies on WordPress authentication APIs for credential validation, uses WordPress Application Passwords for API access, and applies standard capability checks (current_user_can) to protected requests.

With WordPress connected to Sticklight, you can use natural-language instructions to build applications and tools around the data already stored in your site — without replacing WordPress as your CMS or backend.

For WooCommerce sites, the Sticklight Connector can also provide authenticated access to WooCommerce data and functionality exposed through the WordPress REST API. This allows Sticklight projects to build custom dashboards, internal tools, storefront experiences, and workflows around products, orders, customers, inventory, and other WooCommerce resources, subject to the permissions and capabilities of the connected WordPress user.

For example, Sticklight can be used to create tailored order-management interfaces, product and inventory tools, customer-facing experiences, or operational dashboards that work with the data already managed in WooCommerce.

Typical use cases

  • Build AI-generated applications, dashboards, and internal tools powered by WordPress data
  • Create custom interfaces for managing WordPress content outside wp-admin
  • Build headless or hybrid WordPress frontends
  • Create editorial, content-management, or operational workflows around existing WordPress data
  • Build tools using data exposed by compatible WordPress plugins, including WooCommerce
  • Connect React applications to the WordPress user and permission system
  • Give authenticated applications controlled access to WordPress REST API resources

Features

  • Securely connects WordPress with Sticklight projects
  • Enables the Sticklight agent to work with authorized WordPress data through the REST API
  • Authenticates through WordPress and issues Application Passwords for subsequent API access
  • Adds REST endpoints for login, logout, and retrieving current user context
  • Preserves WordPress roles and capability checks
  • Supports cross-origin and headless WordPress architectures
  • Works with resources exposed through the WordPress REST API
  • Extensible through WordPress hooks and filters

About Sticklight

Sticklight is an AI app-building platform that lets users create production-ready applications and tools through natural-language instructions. The WordPress Connector allows those applications to work with live WordPress content and data while retaining WordPress as the underlying content, user, and permissions system.

Learn more about Sticklight for WordPress.

Read the WordPress Connector documentation.

Usage

Login

Authenticate with username (or email) and password:

POST /wp-json/sticklight/v1/auth/login

On success the response includes an Application Password for subsequent API requests and the authenticated user:

{
  "app_password": "XXXX XXXX XXXX XXXX XXXX XXXX",
  "user": {
    "user_id": 1,
    "username": "admin",
    "display_name": "Admin",
    "email": "admin@example.com",
    "roles": ["administrator"]
  }
}

Use the returned app_password with HTTP Basic Authentication for all further requests.

Current user

Retrieve the current authenticated user:

GET /wp-json/sticklight/v1/auth/me

Logout

Revoke the current Application Password session:

POST /wp-json/sticklight/v1/auth/logout

User registration

User creation is handled through the built-in WordPress REST API (POST /wp-json/wp/v2/users) and requires administrator authentication.

Accessing protected data

Requests to any endpoint must pass standard WordPress permission checks. Sticklight does not bypass or override these checks.

Security

Sticklight follows WordPress security practices:

  • Delegates credential validation to WordPress authentication APIs and uses WordPress Application Passwords for subsequent API access
  • Issues Application Passwords scoped to individual sessions
  • Does not provide user registration — accounts must be created by an administrator
  • Applies capability checks (current_user_can) on all endpoints
  • Does not expose private data without proper permissions

For external applications, it is recommended to:

  • Use HTTPS
  • Restrict allowed origins
  • Avoid exposing sensitive endpoints unnecessarily

Installation

  1. Upload the plugin files to the /wp-content/plugins/sticklight-connector directory, or install the plugin through the WordPress plugins screen.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Ensure permalinks are enabled (Settings > Permalinks).

No additional configuration is required for basic usage.

Frequently asked questions

Does this plugin replace WordPress authentication?

No. It delegates credential validation to wp_authenticate and uses WordPress Application Passwords for API access.

Does it allow bypassing permissions?

No. All requests are validated using standard WordPress capability checks.

Can it be used in headless setups?

Yes. It is designed for headless and cross-origin WordPress architectures.

Does it handle user registration?

No. User creation should be done through the built-in WordPress REST API (POST /wp-json/wp/v2/users) with administrator authentication.

Can I extend the endpoints?

Yes. Developers can add or modify behavior using WordPress hooks and filters.

Does the plugin itself use AI?

No. The plugin acts as the secure connection between WordPress and Sticklight. AI functionality is provided by the Sticklight platform, while the connector handles authenticated access to permitted WordPress data and functionality.

Changelog

1.1.0

  • New: Add custom domains to WP REST API cors

1.0.0

  • Initial release.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Sticklight alternatives

All api plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 WP Consent API WP Consent API Simple Consent API to read and register the current consent category. by Rogier Lankhorst 200K+ ★★★★★★★★★★ 5 (2) 2 weeks ago 86
2 Disable REST API Disable REST API Disable the use of the REST API on your website to site users. Now with User Role support! by Dave McHale 80K+ ★★★★★★★★★★ 4.8 (38) 3 years ago 48
3 Mailgun for WordPress Mailgun for WordPress Easily send email from your WordPress site through Mailgun using the HTTP API or SMTP. by Mailgun 80K+ ★★★★★★★★★★ 3.8 (49) 1 week ago 86
4 Make Connector Make Connector Make Connector. Make lets you design, build, and automate by connecting with WordPress in… by Make 70K+ ★★★★★★★★★★ 2.7 (25) 8 months ago 41
5 Disable WP REST API Disable WP REST API Disables the WP REST API for visitors not logged into WordPress. by Jeff Starr 30K+ ★★★★★★★★★★ 4.8 (36) 2 months ago 86
6 WP REST Cache WP REST Cache Enable caching of the WordPress REST API and auto-flush caches upon wp-admin editing. by Acato 10K+ ★★★★★★★★★★ 4.9 (42) 2 months ago 70
7 WPGet API – Connect to any external REST API WPGet API – Connect to any external REST API Connect any REST API to WordPress. WPGet API enables easy API integration, allowing you to… by David Anderson / Team Updraft 10K+ ★★★★★★★★★★ 5 (32) 2 months ago 90
8 WPGraphQL for ACF WPGraphQL for ACF WPGraphQL for ACF seamlessly integrates Advanced Custom Fields with WPGraphQL. by Jason Bahl 10K+ ★★★★★★★★★★ 5 (1) 3 weeks ago 75
9 WordPress REST API (Version 2) WordPress REST API (Version 2) Access your site's data through an easy-to-use HTTP REST API. (Version 2) by Ryan McCue 10K+ ★★★★★★★★★★ 4.2 (34) 9 years ago 43
10 WP REST API Controller WP REST API Controller Enable a UI to toggle visibility and customize properties in WP REST API requests. by Evan Herman 8K+ ★★★★★★★★★★ 4.3 (12) 4 years ago 38

FAQ

Sticklight: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 2, 2026

Is Sticklight free?

Yes. Sticklight is free to download and use from the official WordPress.org plugin directory.

Is Sticklight safe to use in 2026?

Sticklight is a solid plugin choice in 2026, with a few things worth checking first. It runs on 300+ sites and was last updated 4 weeks ago, and scores 64/100 on our health check.

How many websites use Sticklight?

Sticklight is active on 300+ WordPress websites and has been downloaded 1,303 times since it launched in May 2026. It was downloaded 278 times in the last 30 days.

Does Sticklight work with WordPress 7.1?

Sticklight is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does Sticklight need?

Sticklight requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Sticklight last updated?

The latest version, 1.1.0, was released on September 7, 2026 (4 weeks ago).

Who makes Sticklight?

Sticklight is developed and maintained by Elementor.

What are the best alternatives to Sticklight?

The most popular alternatives to Sticklight are WP Consent API (200K+ installs), Disable REST API (80K+ installs) and Mailgun for WordPress (80K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.