Shibboleth With LDAP Authorization
Since this plugin extends the Shibboleth plugin, you must first have the Shibboleth plugin, available from https://wordpress.org/extend/plugins/shibboleth/ installed and activated. Otherwise, the plugin will fail to…
Use with caution
Shibboleth With LDAP Authorizat… works, but test it on a staging site before relying on it in 2026. It runs on 10+ sites and was last updated 2 months ago, and scores 50/100 on our health check.
- Small user base (10+ active installs)
- Very few reviews so far
- Only tested up to WordPress 6.9 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Shibboleth With LDAP Author… stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| login | >100 |
| SAML | #27 |
| shibboleth | #4 |
| UF | #7 |
| UFAD authentication | #1 |
Version adoption
Share of active sites per release.
About Shibboleth With LDAP Authorization
From the official readme · v2.1.1Description
Since this plugin extends the Shibboleth plugin, you must first have the Shibboleth plugin, available from https://wordpress.org/extend/plugins/shibboleth/
installed and activated. Otherwise, the plugin will fail to activate as the shibboleth_user_role filter hook will not be registered.
To use this plugin, you must already have the following setup on your server:
1. The above Shibbleth plugin.
2. A UFAD group created for each of the WordPress roles (administrator, editor, author, contributor, and subscriber).
Installation
- Install, activate, configure and test the Shibbloeth plugin. When it is working, procede.
- Create a UGRM directory in
/wp-content/plugins/directory - Extract the contents of the UGRM.tar.gz plugin archive to the
/wp-content/plugins/UGRMdirectory - Populate UgrmLdapConfig::$configuration attribute located at
/wp-content/plugins/UGRM/ldap-config.php. Options are:
a. binddn – The Distinguished Name (DN) of the user or service account that will query LDAP server for group membership.
b. pw – The password for the user or service account connecting to ldap. (binddn user)
c. basedn – The base DN for the LDAP directory.
d. ldapUri – The URI of the ldap server. - Activate the plugin through the ‘Plugins’ menu in WordPress
- Populate the ‘UFAD Groups to Roles’ options page under the ‘Settings’ menu in WordPress.
Frequently asked questions
It’s not working. What should I check?
Check for typos on the options page and ensure you’ve spelled your UFAD groups correctly. If $_SERVER['glid'] for Apache or `$_SERVER['HTTP_glid']` for IIS is not present, then complete the correct application to have glid included in UF Shibboleth URN. Verify that you can make a connection to the ldap server specified in ldapUri set in the options file. You may do this by launching ldp.ext in Windows and inputting the binddn and password from the options file. You could also use any of the various ldap modules for any programming language to test.
What if I’ve done all that and it still doesn’t work?
Contact the plugin author(s), who will respond in a vague and unspecified amount of time.
Changelog
Important upgrade. Bug fix for "Force return target to HTTPS" feature and adds IIS support.
2.1.1
- Update
nullcheck for optionalqueryLogPathconfig parameter.
2.0.1
- Updates ldap.php with ternary to eliminate options index notice for logpath.
2.0
- Updates UGRM.php to use UgrmLdap class from ldap.php to query UFAD LDAP server to get group membership by shibboleth provided
glidapache server variable. - Adds ldap-config.php containing LDAP connection parameters.
- Corrects bug in options.php where $_SERVER superglobal array keys were not quoted, emitting an error for undeclared constant.
1.7.1
- Corrected typo in code. Minor fix, but very large impact.
1.7
- Discovered that with multisite enabled, the server variables will sometimes present as prepended with REDIRCT_ when in a subsite. E.G. UFADGroupsDN will sometimes appear
REDIRECT_UFADGroupsDN. The code has been extended to accomdate this.
*As a side note, the Shibboleth plugin UGRM extends appears to have been abandoned. As we’ve already made code changes to enable the Shibboleth plugin to work
with the new WordPress enabled for multisite, and we had to graft on further changes for the REDIRECT_ behavior, we plan to release a fork of the Shibboleth plugin.
1.6
- Fixed a glaring bug in when “Force Shibboleth return target to HTTPS” was checked and return target was already https the target would be munged to httpss.
- Discovered Shibboleth on IIS prepends all Shibboleth server variables with a HTTP_ prefix because the variables are populated via CGI as IIS does not support
environment variables (for details, check out: https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPAttributeAccess). Plugin now inspects SERVER_SOFTWARE
variable and adjusts accordingly.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Shibboleth With LDAP Authoriz… alternatives
All login plugins →FAQ
Shibboleth With LDAP Authorization: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 4, 2026
Is Shibboleth With LDAP Authorizat… free?
Yes. Shibboleth With LDAP Authorizat… is free to download and use from the official WordPress.org plugin directory.
Is Shibboleth With LDAP Authorizat… safe to use in 2026?
Shibboleth With LDAP Authorizat… works, but test it on a staging site before relying on it in 2026. It runs on 10+ sites and was last updated 2 months ago, and scores 50/100 on our health check.
How many websites use Shibboleth With LDAP Authorizat…?
Shibboleth With LDAP Authorizat… is active on 10+ WordPress websites and has been downloaded 5,095 times since it launched in September 2011. It was downloaded 97 times in the last 30 days.
Does Shibboleth With LDAP Authorizat… work with WordPress 7.1?
Shibboleth With LDAP Authorizat… is officially tested up to WordPress 6.9.9, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
When was Shibboleth With LDAP Authorizat… last updated?
The latest version, 2.1.1, was released on July 24, 2026 (2 months ago).
Who makes Shibboleth With LDAP Authorizat…?
Shibboleth With LDAP Authorizat… is developed and maintained by warren.brown.
What are the best alternatives to Shibboleth With LDAP Authorizat…?
The most popular alternatives to Shibboleth With LDAP Authorizat… are WPS Hide Login (2M+ installs), Loginizer (1M+ installs) and Security Optimizer (1M+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card

