BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
XMPP Authentication icon
Possibly abandoned Tested up to 4.4.34

XMPP Authentication

Allows users to authenticate without password via XMPP and for visitors to be filtered by XMPP verification.

Active installs10+10+ tier
Downloads · 30d53▲ +43.2% vs prev. 30d
Rating5/51 reviews
Health score30/100At risk
All-time downloads3KSince Aug 2011
Support resolved—No recent threads
RequiresWP 3.2.0PHP any
Downloads · 7d15▲ +50% week over week
Our verdict

Consider an alternative

XMPP Authentication shows warning signs in 2026 — compare the alternatives below before installing. It runs on 10+ sites, is rated 5/5 and was last updated 11 years ago, and scores 30/100 on our health check.

  • Small user base (10+ active installs)
  • Very few reviews so far
  • No update in 10 years
  • Only tested up to WordPress 4.4 (latest is 7.1)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

257Jul 4Aug 17Oct 1
Yesterday2
Daily average (1y)1
Peak day10Sep 10, 2026
Last 12 months376

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where XMPP Authentication stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
authentication >100 4,334 Best authentication plugins →
comments >100 8,837 Best comments plugins →
jabber #16 31 Best jabber plugins →
xep-0070 #1 1 Best xep-0070 plugins →
xmpp #7 16 Best xmpp plugins →

Version adoption

Share of active sites per release.

  • 0.6100.0%

Rating breakdown

★★★★★★★★★★ 5 from 1 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About XMPP Authentication

From the official readme · v0.6

Description

This plugin has two main features:

  • any reader on your website can comment if one has an Instant Messaging
    address (XMPP protocol, otherwise called Jabber. A Gmail or a LiveJournal
    account for instance are such standard IM identifiers as well);
  • a subscribed user (whatever its role) can authenticate with one’s IM
    address if they set their IM address.

This plugin is still in experimental state but is usable.

Detailed Process

The authentication part is something like openID, except that it uses your
existing IM address: you ask for authentication on a website, and it pops-up a
confirmation via IM (that you can accept, or refuse).

Considering that the IM protocol (XMPP) is very secure,
all the infrastructure to securely exchange an authentication request is
there. No need to make any new account, no need a special client, nor a
identity third party provider, and that’s really instantaneous (as instant
messaging) and more secure than HTTP or SMTP protocols.

Spam Protection

It adds an additional layer to protect against Spam by verifying an
identity using a very secure and modern protocol (XMPP), which also is instant,
hence much more reliable in any way than email for instance.

Secure and Easy Login

Many reasons to use such a plugin for login:

  • not to have to remember a new password (password-login can be disabled in
    your profile, on a per-user choice);
  • you are in a very insecure environment (for instance a cybercafe) and consider
    only your IM account to be a minimum securized. Or better, you run an IM
    client on your smartphone (or a similar tool), so you would receive the query
    on this personal item while never typing any kind of password on the insecure
    platform where you log.
  • And so on.

Configuration

Publishing Account

This section contains the connection parameters of the account which will be
used as a wordpress bot. I would personnaly advice to create a dedicated account
just for it (you may also use your personal account of course, as the plugin’s
bot will create a resource identifier unique for every connection) and to
configure it to refuse any contact and communication (as noone will have to
add it to one’s roster, except you maybe for test or debugging purpose?).
The fields are:

  • The bot address (bare jid form: mybotname@myserveraddress);
  • the password.

Advanced Connection Parameters

By default xmpp-auth can use SRV records which is a recommended way to
advertize server and port from a domain name (see for instance
http://dns.vanrein.org/srv/ for details).

This is an advanced section in case your server does not use SRV AND uses a server
which is not the same as the domain from the jid or a port different from the
default one (5222).

Hence there will be very very few cases where you will have to fill this
section and if you don’t understand all what I say here, just don’t fill
anything there (if you fill even only one field, then it will be used instead
of SRV and default values).

The default values will be used if the fields are empty and no SRV is configured on
the Jabber server:

  • the XMPP server (often the same as ‘myseveraddress’ of the jid);
  • the XMPP port (usually 5222).

TODO

Features I am considering:

  • check quickstart (http://xmpp.org/extensions/inbox/quickstart.html). In
    particular, I should at least cache DNS lookups now.
  • deactivate IM features when plugin not configured.
  • For comments, use the IM avatar of the commenter instead of gravatar;
  • Make various notifications usually done by email be done by IM instead (if
    adequate);
  • Display the comment’s JID on the admin page (as we display the email
    address, obviously only for administrators);
  • Add Scram-* to SASL package;
  • Make the generic XMPP part a PEAR package.
  • Subscribe with XMPP JID.
  • Login with JID or username (both possible).
  • If password is disabled, it also cannot be resetted.
  • Make user choose to receive password reset or other notification through IM
    instead of email.

XMPP Features

Full Secure XML Stream with:

  • TLS (with real certificate verification, so confidentiality and
    authentication);
  • SASL (Digest-MD5, CRAM-MD5 and PLAIN only for now);
  • SRV records “randomization” algorithm.

Contacts

You can have some news about this plugin on my freedom
haven
.
You can also drop me an instant message on “hysseo” at zemarmot.net.

Have a nice life!

Installation

The easy way is via your installed WordPress’s administration pages:

  1. Click Plugins > Add New;
  2. Search for xmpp-auth;
  3. Find it in the displayed list;
  4. Click Install Now.

Alternatively, here is the old “manual” version:

  1. Upload the plugin archive to wp-content/plugins/ directory on your WordPress installation;
  2. Uncompress it by keeping it in its own sub-directory called xmpp-auth/;
  3. Activate the plugin through the ‘Plugins’ menu in WordPress;
  4. Configure the plugin through the appearing sub-menu XMPP Authentication
    under the Plugins menu;
  5. When aknowledging the configuration by pressing the Update button, login
    will be tested (a connection will be attempted). If anything is wrong with
    your configuration, you will be immediately informed.

Once installed, I would suggest to modify the configuration in Settings >
Discussion > uncheck Comment author must fill out name and e-mail as they
will be verified by XMPP (but the fields will stay if the user wants to add
them in).

Also the new comment field (for JID) is automatically displayed if you use a
recent theme (because it uses a function newly added since 3.0). If you don’t
see the new field after activating, don’t panick. 4 solutions:

  1. the simpler: use a more recent theme. The default twentyten and
    twentyeleven will work perfectly without doing anything;
  2. if you don’t want to change your theme, try to contact the theme writers
    and ask them if they could not support the generic (and now “adviced”)
    comment_form() feature (they will understand);
  3. you know PHP/HTML and want to do it fast: simply check the file
    comments.php of your theme. and either replace the whole form by this
    simpler function: <?php comment_form(); ?> yourself;
  4. or if you want to do it manually, add the following code (can be modified,
    but what matters obviously is the id of the input field):

*

My advice is obviously to go for the first and the second solutions. The
third one is really when you want to do this fast (but still you should report
this to the theme writers for them to update upstream) and the fourth is a
last resort if you have some very atypical comment form.

dependencies

  • PHP > 5.1.0 (for function stream_socket_enable_crypto).

  • expat library to parse XML (enabled with the --with-xml
    option of the php compilation).

Note for gentoo users: you must set the ‘xml’ USE flag.

  • OpenSSL (> 0.9.6) must be installed on the server and PHP must be built
    with --with-openssl.

  • OPTIONAL: if the plugin is installed on a BSD (Mac included),
    in order to use the SRV records on the admin JID, which is the correct way of
    resolving the server and port addresses for a domain, the PEAR extension
    NET_DNS must be installed: pear install NET_DNS (Note that it will ask
    to have php compiled with mhash option).
    If it is installed on Windows, it is not anymore useful if you have PHP
    5.3.0 or later installed (under this version of PHP, you should also install
    the NET_DNS extension to benefit SRV records).
    Linux servers do not need this extension to have SRV.

Note for gentoo users: you must set the ‘mhash’ USE flag.

Working Platforms

This script has been tested only currently on WordPress 3.2.1 up to WordPress
3.2.1 with PHP 5.3.5 up to PHP 5.3.8, running on a GNU/Linux 64 bits (Gentoo
Linux).
Hopefully it should work with other software versions (not for PHP4, because
of the TLS feature which is PHP5 specific. Yet if you are really interested
into PHP4 compatibility and if TLS is not required for your connection, just
ask me, I will try to make a compatibility layer), but I cannot guarantee.
Tell me please if you tried this successfully with another configuration so
that I update the known working platforms list.

At the opposite, if you find a bug or encounter an issue on some
configuration, don’t hesitate to tell me, and I will try and fix it.

Changelog

French localization available. DNS cached for improved performance. SCRAM-* support added.

0.6

  • Fix comment validation.
  • Comment validation through XMPP is now marked as “experimental”.
    Though still functional, I find the user experience crappy. I will want to
    review this deeply before considering it in release state.
  • Comment validation times out at 50 sec (was 30).
  • Transaction IDs are 6 characters. This makes them easier to copy, even on
    smaller virtual keyboard (for instance to validate on your personal smartphone
    a login made on a third-party untrusted machine).

0.5

  • Update SASL lib to Auth_SASL2 0.1.0.
  • Fix Cacert root certificate.
  • Add Let’s Encrypt root certificate.
  • Improving/experimenting the protocole from XEP-0070. It should be more
    user-friendly, while still staying secure.

0.4

  • When login is disabled, login page look is not modified.
  • When comments is disabled, I still display the JID field, but simply don’t
    process anything and without the ‘*’ of mandatory fields.
  • Localization prepared and French localization available.
  • DNS results are now cached. I use the ttl of records (maximum 1 week, as
    proposed in RFC-1035) and reorder cached data using failure and success
    knowledge.
  • PEAR Auth_SASL coded is included in the plugin, hence the dependency is no more.
  • A patch has been sent upstream for SCRAM support.

  • After many years of inactivity, I fixed all the code and tested it against
    Wordpress 4.4.1.

  • Root certificates were also updated.

0.3

  • Profile page configuration: per-user choice to disable password, IM
    authentication, or use both.
  • IPv6 support and better DNS integration.
  • The core XMPP library has been rewritten in a much more robust, hence secure
    API. The current version had been started in 2008. My first XMPP experiment
    that I used for the plugin Jabber Feed (that I will probably soon merge with
    the current plugin) and the API was not very nice and could break more
    easily on some unexpected outputs.

0.2

  • Admins have now possibility to deactivate the plugin on a per-feature basis.
  • Experimental component support.
  • “Jabber / Google Talk” in profile renamed to “Standard IM”.

0.1.5

  • TLS certificates were not properly configured.
  • Various fixes.

Full changelog on WordPress.org →

Screenshots

Visitor posts a comment and receive a confirmation request by pop-up through
one's IM client (here Psi+).
Visitor posts a comment and receive a confirmation request by pop-up through one's IM…
Configuration page.
Configuration page.

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best XMPP Authentication alternatives

All authentication plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Limit Login Attempts Limit Login Attempts Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable. by Automattic 300K+ ★★★★★★★★★★ 4.6 (202) 3 years ago 48
2 WPS Limit Login WPS Limit Login WPS Limit login limit connection attempts by IP address by NicolasKulka 100K+ ★★★★★★★★★★ 4.9 (83) 2 weeks ago 81
3 Two Factor Two Factor Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email… by WordPress.org 100K+ ★★★★★★★★★★ 4.8 (208) 4 days ago 88
4 WP-Members Membership Plugin WP-Members Membership Plugin The original WordPress membership plugin with content restriction, user login, custom… by Chad Butler 50K+ ★★★★★★★★★★ 4.6 (273) 3 weeks ago 89
5 Google Authenticator Google Authenticator Google Authenticator for your WordPress blog. by Ivan 20K+ ★★★★★★★★★★ 4.3 (135) 1 month ago 83
6 miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) miniOrange 2FA Free 2FA plugin for unlimited users with Passkey, Google Authenticator, Email/SMS OTP, Push… by miniOrange 10K+ ★★★★★★★★★★ 4.5 (385) 18 hours ago 88
7 WP Limit Login Attempts WP Limit Login Attempts Limit rate of login attempts and block IP temporarily. Brute force attack protection. GDPR… by Arshid 10K+ ★★★★★★★★★★ 4.6 (300) 2 weeks ago 88
8 Login for Google Apps by WPAuth Login for Google Apps by WPAuth Simple secure login and user management through your Google Workspace for WordPress (using… by Syed Balkhi 10K+ ★★★★★★★★★★ 4.6 (64) 3 days ago 88
9 Login by Auth0 Login by Auth0 Login by Auth0 provides improved username/password login, Passwordless login, Social login… by Auth0 10K+ ★★★★★★★★★★ 3.1 (18) 2 years ago 34
10 Two Factor (2FA) Authentication via Email Two Factor (2FA) Authentication via Email Enable one-click login with this WordPress Two-Factor Authentication (2FA) plugin… by Sully 9K+ ★★★★★★★★★★ 5 (4) 3 weeks ago 83

FAQ

XMPP Authentication: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 2, 2026

Is XMPP Authentication free?

Yes. XMPP Authentication is free to download and use from the official WordPress.org plugin directory.

Is XMPP Authentication safe to use in 2026?

XMPP Authentication shows warning signs in 2026 — compare the alternatives below before installing. It runs on 10+ sites, is rated 5/5 and was last updated 11 years ago, and scores 30/100 on our health check.

How many websites use XMPP Authentication?

XMPP Authentication is active on 10+ WordPress websites and has been downloaded 3,037 times since it launched in August 2011. It was downloaded 53 times in the last 30 days.

Does XMPP Authentication work with WordPress 7.1?

XMPP Authentication is officially tested up to WordPress 4.4.34, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

When was XMPP Authentication last updated?

The latest version, 0.6, was released on January 15, 2016 (11 years ago).

Who makes XMPP Authentication?

XMPP Authentication is developed and maintained by Jehan.

What are the best alternatives to XMPP Authentication?

The most popular alternatives to XMPP Authentication are Limit Login Attempts (300K+ installs), WPS Limit Login (100K+ installs) and Two Factor (100K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.