WordSocket
WebSocket relay for WordPress. Realtime events plus a Yjs sync provider for Gutenberg real-time collaboration. No polling, no custom server.
Solid choice
WordSocket is a solid plugin choice in 2026, with a few things worth checking first. Is rated 5/5 and was last updated 1 day ago, and scores 71/100 on our health check.
- Actively developed — last update 1 day ago
- Tested with the latest WordPress (7.1)
- Momentum — downloads up 254.1% vs the previous 30 days
- Small user base (<10 active installs)
- Very few reviews so far
- Needs PHP 8.2 or newer
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where WordSocket stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| events | >100 |
| realtime | #73 |
| server-sent events | >100 |
| Websocket | #10 |
| wordsocket | #1 |
Rating breakdown
★★★★★★★★★★ 5 from 1 reviews
About WordSocket
From the official readme · v0.28.0Description
WordSocket sends realtime events from your WordPress site to connected browsers.
When content changes: a post is published, a comment is approved, an option is updated: the plugin pushes the event to subscribers instantly via WebSocket (with SSE fallback).
When real-time collaboration is available (currently through the Gutenberg plugin), WordSocket also registers as a WebSocket-based Yjs sync provider for realtime collaborative editing in the block editor, replacing the default HTTP polling transport with a low-latency WebSocket connection.
WPSignal is an independent service and is not affiliated with or endorsed by the WordPress project.
Features:
- One-click automatic connection via the WPSignal dashboard (no API key required)
- Manual connection via API key for advanced setups
- Disconnect button with inline confirmation: the site is archived on the server, its usage history is kept, and reconnecting the same URL restores it
- WebSocket-first with automatic SSE fallback
- Per-site JWT signing secrets: each site’s connection tokens are cryptographically isolated
- AES-256-GCM encrypted event payloads: the WPSignal relay never has access to their plaintext
- Admin toggle to disable the collaboration provider and fall back to Gutenberg’s HTTP polling
- Built-in triggers for post updates and custom post types
- Custom trigger builder: map any WordPress action hook to a realtime event
- Public JavaScript API (
window.WPS) for themes and plugins to share the connection - Extensible connection token:
wpsignal_token_channelsandwpsignal_token_channel_prefixesfilters let other plugins add channels and namespace permissions to the JWT without modifying core - Admin explorer page with live event log, publish form, and token inspector
- Short-lived JWTs (5 min) with automatic refresh
How it works:
- Install the plugin and connect to the WPSignal service.
- When content changes in WordPress, the plugin encrypts and publishes an HMAC-signed event to the WPSignal server.
- The server pushes the ciphertext to all browsers subscribed to that channel.
- The browser decrypts the payload and dispatches
wpsignal:*DOM events. The relay never sees the payload’s plaintext. - When real-time collaboration is available on the site, the block editor uses the same WebSocket connection for collaborative editing with no extra configuration.
Real-Time Collaboration
WordSocket ships a WebSocket sync provider for the block editor’s real-time collaboration feature. Three things need to be true for it to activate:
- The Gutenberg plugin is active. Real-time collaboration was removed from WordPress core before the 7.0 release and is only available through the Gutenberg plugin.
- Real-time collaboration is enabled under Gutenberg > Experiments > Enable real-time collaboration (Gutenberg 23.8 and later; earlier versions used Settings > Writing).
- The site is connected to WPSignal, since the provider shares the plugin’s WebSocket connection.
The WordSocket Settings tab shows a “Gutenberg detected” badge when the feature is available on your site. Once active, everything collaboration syncs travels over the WebSocket instead of HTTP polling: document updates, cursors and presence, and collaborative notes. If the connection drops, the provider reconnects with increasing delays; after repeated failures the editor shows its standard “connection lost” dialog, and documents re-sync when the connection returns. If a site’s credentials are revoked, the editor reports an authentication error instead of retrying forever. The site editor does not use sync providers (core disables collaboration there). Disabling the provider from the Settings tab restores Gutenberg’s HTTP polling for all editors.
Third-Party Service
This plugin connects to the WPSignal service at api.wpsignal.io for the following operations:
- Site registration: when you connect in the admin (via the automatic one-click flow or by entering an API key manually), the plugin registers your site with the server and receives credentials.
- Event publishing: when a trigger fires (e.g. a post is saved), the plugin sends an encrypted, HMAC-signed HTTP request to the server.
- Realtime connections: logged-in users’ browsers connect to the server via WebSocket or SSE to receive events.
- Collaborative editing: when real-time collaboration is enabled through the Gutenberg plugin, editors’ browsers relay Yjs document updates (binary diffs of the post being edited), cursors and presence to each other through the server, over the same WebSocket.
Event payloads are AES-256-GCM encrypted before leaving WordPress, so the WPSignal server relays ciphertext and never has access to their plaintext. Collaborative editing updates are not encrypted: the server could read them, though it only forwards them and never parses or stores them. Data is delivered in realtime and is not persisted on the server.
Setup
Showcase
Below are a few examples showcasing the possibilities with WP Signal + WordSocket. Repository https://github.com/wpsignal/wordsocket-examples
Living Posts – Interactivity API
Source code: https://github.com/wpsignal/wordsocket-examples
Bidirectional Realtime Chat Plugin
Realtime Poker Plugin
Open Source
https://github.com/wpsignal/wordsocket
Third-party libraries
The browser client bundles @noble/ciphers (MIT, audited) for AES-256-GCM decryption on plain HTTP pages, where browsers do not offer SubtleCrypto. It is compiled into build/client.js by npm run build.
Installation
- Upload the
wordsocketfolder to/wp-content/plugins/, or install directly from the WordPress plugin directory. - Activate the plugin through the “Plugins” menu in WordPress.
- Go to WordSocket > Settings and open the Connect tab.
- Choose a connection method:
- Automatic (recommended): Click Connect with WPSignal. You will be redirected to the WPSignal dashboard to authorize the connection. No API key entry required.
- Manual: Switch to the Manual tab, paste your API key, and click Save Settings.
- The plugin registers with the server and saves credentials automatically.
To create an account, visit wpsignal.io.
Frequently asked questions
What is WPSignal?
WPSignal is a realtime event delivery service for WordPress. It pushes events from your site to connected browsers the moment they happen, without polling.
Do I need a wpsignal.io account?
Yes. The plugin requires a WPSignal account to relay events. Create a free account at wpsignal.io.
What data is sent to the WPSignal server?
During registration: your site URL and name. During normal operation: event payloads, AES-256-GCM encrypted on every site including plain HTTP ones, with a key derived from your site’s WordPress salts that the server never receives, so it never sees their contents. Channel names stay readable because the server routes on them. When real-time collaboration is enabled, Yjs document updates (binary diffs of block editor content) are also relayed. These are not encrypted, so the server could read them; it forwards them by channel and never parses or stores them. All data is delivered in realtime…
Are my event payloads private?
Event payloads are encrypted with AES-256-GCM before leaving WordPress. The encryption key is derived from your WordPress salts and site key using HKDF-SHA256, and is never sent to the WPSignal server. This means the relay cannot read your message content. Note: all logged-in users on the same site share the same derived key. Per-user message privacy is out of scope for the current version.
Why is real-time collaboration unavailable on my site?
Real-time collaboration was removed from WordPress core before the 7.0 release and currently ships with the Gutenberg plugin as an experiment. Install and activate Gutenberg, then turn on Gutenberg > Experiments > “Enable real-time collaboration”. The WordSocket Settings tab shows a “Gutenberg detected” badge when the feature is available, and the sync provider activates automatically once collaboration is enabled. Post types without custom-fields support are excluded by Gutenberg itself.
Does this work for logged-out visitors?
The built-in client script and the token endpoint (/wp-json/wpsignal/v1/token) are limited to logged-in users by default. To open them to all visitors, return true from the wpsignal_allow_client filter: add_filter( 'wpsignal_allow_client', '__return_true' ); Tokens minted for visitors carry user ID 0 and are scoped to your site, so keep in mind that anyone can then subscribe to your site’s public channels and publish over the WebSocket.
What happens when I disconnect?
The plugin tells the WPSignal server to archive the site, then deletes the stored credentials (site key, secrets, and the API key if you connected manually). Your usage history stays on the server, and connecting the same site URL again restores the site with fresh secrets. On a manual connection you will need to paste the API key again. If the server cannot be reached, nothing is deleted and you can retry.
Why was my connection refused?
The WPSignal dashboard refuses to authorize a site when your plan’s site limit is reached (the message names the site to disconnect first), when your account email is not yet verified, or when the account has been deactivated. The Connect tab shows the exact reason returned by the server.
How do extensions plug in?
An extension is a separate plugin built on WordSocket (WooCommerce, Live Blog, and Chat are on the way). Its settings appear on the WordSocket settings page under the Extensions tab, which also lists what is available. Developers: register on wpsignal_loaded with WPS::instance()->extensions()->register(), enqueue a settings script on the wordsocket_settings_enqueue action with wpsignal-settings as a dependency, and render window.wordsocket.ExtensionPanel from a plugin registered with wp.plugins.registerPlugin( slug, { scope: 'wordsocket', render } ). An extension with settings of its own adds…
Can I make a channel private?
Yes. Reserve a namespace on wpsignal_loaded: WPS::instance()->channels()->reserve( 'orders', 'manage_woocommerce' ) (a capability, or a callable receiving the user ID). The relay then refuses subscribe and publish frames on that namespace from anyone else. Once any namespace is reserved, tokens list channels explicitly instead of allowing every channel of the site, so register each channel you subscribe to through the wpsignal_token_channels filter. Payload encryption is site-wide and is not a privacy boundary between users; the channel gate is.
Why did events stop?
Each plan has a monthly message quota. When it is reached the server answers publishes with “quota exceeded” and the plugin pauses publishing until the first day of the next month (UTC). The Connect tab on the WordSocket settings page shows this, as well as rejected credentials (disconnect and connect again) and an unreachable server, and clears the warning as soon as the server answers again. There is no admin notice.
What happens if WebSocket is unavailable?
The client falls back to SSE for receiving events. window.WPS.subscribe() and window.WPS.unsubscribe() work on SSE connections: channel changes are tracked and applied immediately via a lightweight SSE reconnect (50 ms debounce). Collaborative editing needs WebSocket, because SSE is receive-only: if the editor opens while the client is on SSE, collaboration stays off for that editor until the page is reloaded with WebSocket available. You can also disable the collaboration provider from the WordSocket Settings tab to use Gutenberg’s HTTP polling for all editors instead.
Changelog
Adds the settings tab slot extensions use. Update WordSocket before ShopSocket 0.5.
0.28.0
- New: extensions can add their own tab to the WordSocket settings page (
window.wordsocket.registerTab()); ShopSocket’s settings live there
0.27.0
- The browser client closes its connection when a page is left and opens a new one when a page comes back from the browser’s back/forward cache, so a site’s connection count follows open tabs rather than pages visited
- The client waits for a prerendered page to be shown before connecting
- The Extensions tab offers ShopSocket, now on WordPress.org, with a button that opens the plugin installer in place
0.26.0
- Keeps collaboration working when Gutenberg stops exposing the
wp.syncglobal. The provider now takes the editor’s Yjs instance from theYoption Gutenberg passes it, and still reads the global on older versions
0.25.0
- Events are now encrypted on plain HTTP sites too. The browser client decrypts with a bundled AES-256-GCM implementation where SubtleCrypto is unavailable, so the relay reads ciphertext on every site, not only HTTPS ones
- Fixed: the Explorer tab could not connect on a plain HTTP site. It chose
ws://from the page’s scheme instead of the relay’s, so the TLS handshake failed (close 1006) - Fixed: extension rows on the Plugins screen sorted to the top of the list instead of under WordSocket
0.24.1
- Hide future slot fill
0.24.0
- New: extensions are listed with WordSocket on the Plugins screen, renamed “WordSocket: ” (the name that screen sorts by) and indented under it, so the family stays together;
wordsocket_nested_plugin_rowsfilters the rows and an empty array switches it off
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best WordSocket alternatives
All events plugins →FAQ
WordSocket: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 2, 2026
Is WordSocket free?
Yes. WordSocket is free to download and use from the official WordPress.org plugin directory.
Is WordSocket safe to use in 2026?
WordSocket is a solid plugin choice in 2026, with a few things worth checking first. Is rated 5/5 and was last updated 1 day ago, and scores 71/100 on our health check.
How many websites use WordSocket?
WordSocket is active on <10 WordPress websites and has been downloaded 1,362 times since it launched in March 2026. It was downloaded 517 times in the last 30 days.
Does WordSocket work with WordPress 7.1?
Yes. The developer has tested WordSocket up to WordPress 7.1.2, the latest release. It requires WordPress 6.7 or newer.
What PHP version does WordSocket need?
WordSocket requires PHP 8.2 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was WordSocket last updated?
The latest version, 0.28.0, was released on September 30, 2026 (1 day ago).
Who makes WordSocket?
WordSocket is developed and maintained by wpsignal.
What are the best alternatives to WordSocket?
The most popular alternatives to WordSocket are The Events Calendar (600K+ installs), Events Manager (60K+ installs) and Simple Calendar (50K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card