wpCAS Server
Turns WordPress or WordPress MU into a CAS single sign-on authenticator.
Consider an alternative
wpCAS Server shows warning signs in 2026 — compare the alternatives below before installing. It runs on 10+ sites and was last updated 14 years ago, and scores 23/100 on our health check.
- Small user base (10+ active installs)
- Very few reviews so far
- No update in 14 years
- Only tested up to WordPress 2.9 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where wpCAS Server stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| auth | >100 |
| authentication | >100 |
| central authentication service | >100 |
| wpCAS | #5 |
| wpcas-server | #5 |
Version adoption
Share of active sites per release.
About wpCAS Server
From the official readme · v1.0Description
This plugin reserves a collection of URIs that create, validate, and destroy CAS tickets.
-
/cas/login :: If user is not authenticated he/she is redirected to the login page. Otherwise the user is redirected to the service specified as a GET variable in the URL – or if service is not provided, the user is redirected to the WordPress instance’s home.
-
/cas/logout :: The user’s session is destroyed, user is logged out of the WordPress instance, and redirected to $_GET[‘service’] (or the blog home if service isn’t provided)
-
/cas/proxyValidate and /cas/validate :: The CAS ticket must be passed as a GET parameter in the URL when calling /cas/validate. The ticket is validated and XML is output with either cas:authenticationSuccess or cas:authenticationFailure
Hooks & Filters
wpcas_server_login Hook
This hook allows for the insertion of code after login has successfully completed and just before the ticket creation. One common use of this hook is to fill out the $_SESSION variable with site/user specific information.
wpcas_server_auth_value Filter
This filter (executed in a successful ticket validation in /cas/validate) is used to override the user identifier returned in the cas:authenticationSuccess XML response. By default, the value returned is the $user_ID of the authenticated user. Using this filter, that value can be altered to whatever suits your implementation.
Installation
- Upload
wpcas-serverdirectory to the/wp-content/plugins/directory - Activate the plugin through the ‘Plugins’ menu in WordPress
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best wpCAS Server alternatives
All auth plugins →FAQ
wpCAS Server: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 30, 2026
Is wpCAS Server free?
Yes. wpCAS Server is free to download and use from the official WordPress.org plugin directory.
Is wpCAS Server safe to use in 2026?
wpCAS Server shows warning signs in 2026 — compare the alternatives below before installing. It runs on 10+ sites and was last updated 14 years ago, and scores 23/100 on our health check.
How many websites use wpCAS Server?
wpCAS Server is active on 10+ WordPress websites and has been downloaded 2,933 times since it launched in March 2009. It was downloaded 70 times in the last 30 days.
Does wpCAS Server work with WordPress 7.1?
wpCAS Server is officially tested up to WordPress 2.9.2, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
When was wpCAS Server last updated?
The latest version, 1.0, was released on July 12, 2012 (14 years ago).
Who makes wpCAS Server?
wpCAS Server is developed and maintained by Adam Backstrom.
What are the best alternatives to wpCAS Server?
The most popular alternatives to wpCAS Server are authLdap (4K+ installs), WP BASIC Auth (3K+ installs) and WP Cron HTTP Auth (1K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card