Intranet & Private Site - All-In-One Intranet
by Syed Balkhi 5 (11 reviews)

Intranet & Private Site - All-In-One Intranet

Turn WordPress into a private intranet in one click. Restrict access to logged-in members, with auto-logout and login redirect, also on multisite.

Intranet & Private Site ranks #3,673 among WordPress.org plugins with 3,000+ active installations, is #132 of 1,576 in the Authentication category, a 5/5 rating from 11 reviews, and was last updated Aug 3, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7 (Current: 7.1)
v1.10.0 Current Version v1.10.0
Updated 1 month ago Last Update on 03 Aug, 2026
Refreshed 15 hours ago Last Refreshed on
#132 of 1,576 in Authentication Top 5% by installs Downloads -31.3% this week
View on WordPress.org
Rank
#3,673
No change
Active Installs
3K+
-28.3%
KW Avg Position
13
0.2 better
Downloads
127.1K
+28 today
Support Resolved
100%
No change
Rating
100%
Review 5 out of 5
5 (11 reviews)

Next Milestone 4K

Total Progress 99%
3K+ 4K+
23
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 10 more installs to reach 4K+

Rank Changes

3,487 3,580 3,674 3,768 3,862 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
3,665 3,671 3,677 3,682 3,688 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #3,673
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

10 20 30 40 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
10 20 30 40 50 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
11 reviews
Overall 100%
5
11 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Support Threads Overview

Resolved
Unresolved
2
Total Threads
2
Resolved
0
Unresolved
100%
Resolution Rate

Security History

Source: WPVulnerability

1 known vulnerability on record · 1 in the last 24 months · checked 2 days ago

  1. Intranet & Private Site – All-In-One Intranet [all-in-one-intranet] < 1.9.0

    CVE-2026-54837 · Fixed in v1.9.0

TL;DR

AI summary of the plugin's readme

This plugin is for organizations that want to run a private intranet, knowledge base, or client portal on WordPress. It solves the problem of restricting an entire WordPress site to logged-in users, since WordPress is normally built for public-facing sites and doing this otherwise requires multiple separate plugins.

  • One-click private site
  • REST API protection
  • XML-RPC blocking
  • Search engine blocking via robots.txt
  • Auto-logout for inactive users
  • Custom login redirect
  • Multisite sub-site privacy
  • Multisite default role assignment

Frequently Asked Questions

Common questions about Intranet & Private Site - All-In-One Intranet

Install and activate the plugin, then go to Settings > All-In-One Intranet and check "Force site to be entirely private." All pages, posts, and custom content types will require login. The REST API and XML-RPC are also locked down automatically.
No. Media files (images, PDFs, videos, etc.) that are uploaded through WordPress remain accessible to anyone who knows the direct URL. This is because WordPress serves media files directly through your web server, bypassing PHP and plugin logic. This limitation is common to most WordPress privacy plugins. If direct media file protection is a requirement, you would need a server-level solution or a dedicated download protection plugin in addition to All-In-One Intranet.
Yes. When the private site option is enabled, unauthenticated REST API requests receive a 401 error response. This prevents external tools, scripts, or bots from accessing your content through API endpoints like /wp-json/wp/v2/posts. Authenticated requests from logged-in users continue to work normally. Two narrow sets of routes are exempt, and only while the plugin providing them is active: the endpoints two-factor and passkey plugins use to finish a login, and a site management platform's own API namespace for a request presenting that platform's credentials. See "For Developers" in the Description tab for how to adjust either list.
The plugin records a timestamp on the browser session each time a logged-in user loads a page. On the next page load, it compares the current time against that session's timestamp. If the difference exceeds the configured idle time, the user is logged out immediately. The idle timer resets on every page load, so users who are actively browsing are never interrupted, and each browser session keeps its own timer, so staying signed in at your desk does not keep a forgotten login on a shared machine alive. You can set the timeout in minutes, hours, or days. Only browser sessions are subject to it. A request that authenticates without a login cookie (a site management dashboard using its own API, or a script using an application password) has no session to expire, so it is left running and it does not reset anybody's idle timer.
Yes. In the Login Redirect section of the plugin settings, enter the full URL of the page you want users to land on after logging in. This overrides the default WordPress behavior of sending users to the dashboard. If a user was trying to reach a specific page before being asked to log in, they will be redirected back to that page instead of the custom redirect URL.
Yes. The plugin is fully compatible with WordPress multisite. In a multisite network, the settings are managed from the Network Admin area. You can make the entire network private, require users to be members of individual sub-sites before accessing them, and automatically assign roles to users across sub-sites when new users or new sites are created.
Yes, but it requires a small amount of code. Use the aioi_allow_public_access filter in your theme's functions.php file or a custom plugin. For example, to keep a page with the slug "public-info" accessible without login: add_filter( 'aioi_allow_public_access', function( $allow ) { if ( is_page( 'public-landing' ) ) { return true; } return $allow; } );
Yes. When the private site option is enabled, the plugin overrides the robots.txt file to disallow all crawling. It also disables outgoing pingbacks and trackbacks, so your site does not announce new content to external services or ping aggregators.
Generally, yes. Most WordPress caching plugins bypass the cache for logged-in users and do not cache redirects, so the privacy enforcement works as expected. However, aggressive full-page caching at the server level (Varnish, Nginx FastCGI cache) may serve cached pages to unauthenticated users if not configured to respect WordPress login cookies. If you use server-level caching, make sure it bypasses the cache when WordPress login cookies are absent.
On a single-site WordPress installation, users who are logged in but have no assigned role are treated as unauthorized. The plugin logs them out and displays a message explaining that they do not have permission to access the site. This prevents access by accounts that have been deactivated by removing their role rather than deleting them.

Sign In / Register

You need to sign in or register to use this feature.