wpCAS
wpCAS integrates WordPress into an established CAS architecture, allowing centralized management and authentication of user credentials in a heterogeneous environment.
Consider an alternative
wpCAS shows warning signs in 2026 — compare the alternatives below before installing. It runs on 100+ sites and was last updated 17 years ago, and scores 25/100 on our health check.
- Small user base (100+ active installs)
- Very few reviews so far
- No update in 16 years
- Only tested up to WordPress 2.7 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where wpCAS stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| authentication | >100 |
| cas | >100 |
| central authentication service | >100 |
| phpCAS | #4 |
| wpCAS | #6 |
Version adoption
Share of active sites per release.
About wpCAS
From the official readme · v1.07Description
wpCAS integrates WordPress into an established CAS architecture, allowing centralized management and authentication of user credentials in a heterogeneous environment.
The Central Authentication Service (CAS) is a single sign-on protocol for the web. Its purpose is to permit a user to log into multiple applications simultaneously and automatically. It also allows untrusted web applications to authenticate users without gaining access to a user’s security credentials, such as a password. The name CAS also refers to a software package that implements this protocol.
Users who attempt to login to WordPress are redirected to the central CAS sign-on screen. After the user’s credentials are verified, s/he is then redirected back to the WordPress site. If the CAS username matches the WordPress username, the user is recognized as valid and allowed access.
Authorization of that user’s capabilities is based on native WordPress settings and functions. CAS only authenticates that the user is who s/he claims to be.
If the CAS user does not have an account in the WordPress site, an administrator defined function can be called to provision the account or do other actions. By default, CAS users without WordPress accounts are simply refused access.
Installation
- Download phpCAS and place it on your webserver so that it can be included by the wpCAS plugin.
- Place the plugin folder in your
wp-content/plugins/directory and activate it. - Set any options you want in Settings -> wpCAS or in the
wpcas-conf.phpfile. - The plugin starts intercepting authentication attempts as soon as you activate it. Use another browser or another computer to test the configuration.
wpcas-conf.php
wpCAS can be configured either via the settings page in the WordPress dashboard, or via a configuration file. See wpcas-conf-sample.php for an example. If a config file is used, it overrides any settings that might have been made via the settings page and that page is hidden.
Use of wpcas-conf.php is recommended for WordPressMU installations, as doing so hides the settings menu from users.
WordPressMU Installation
- Download phpCAS and place it on your webserver so that it can be included by the wpCAS plugin.
- Place the plugin
wpcas.phpin yourwp-content/mu-plugins/directory. - Make a copy of
wpcas-conf-sample.php, rename itwpcas-conf.php, and put it in yourwp-content/mu-plugins/directory. - Set the options in the config file.
- The plugin starts intercepting authentication attempts as soon as you activate it. Use another browser or another computer to test the configuration.
- Consider creating a function to provision user accounts for CAS-authenticated users who do not have WordPress accounts.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best wpCAS alternatives
All authentication plugins →FAQ
wpCAS: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 30, 2026
Is wpCAS free?
Yes. wpCAS is free to download and use from the official WordPress.org plugin directory.
Is wpCAS safe to use in 2026?
wpCAS shows warning signs in 2026 — compare the alternatives below before installing. It runs on 100+ sites and was last updated 17 years ago, and scores 25/100 on our health check.
How many websites use wpCAS?
wpCAS is active on 100+ WordPress websites and has been downloaded 6,879 times since it launched in August 2008. It was downloaded 102 times in the last 30 days.
Does wpCAS work with WordPress 7.1?
wpCAS is officially tested up to WordPress 2.7.1, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
When was wpCAS last updated?
The latest version, 1.07, was released on March 25, 2010 (17 years ago).
Who makes wpCAS?
wpCAS is developed and maintained by Casey Bisson.
What are the best alternatives to wpCAS?
The most popular alternatives to wpCAS are Limit Login Attempts (300K+ installs), WPS Limit Login (100K+ installs) and Two Factor (100K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card