Loggedin - Session Manager, Limit Concurrent Logins & Force Logout
by Joel James 4.9 (111 reviews)

Loggedin - Session Manager, Limit Concurrent Logins & Force Logout

WordPress session manager — limit concurrent user logins, stop account sharing, force logout active sessions, and manage every signed-in device.

Loggedin ranks #2,472 among WordPress.org plugins with 8,000+ active installations, is #20 of 622 in the Accessibility category, a 4.9/5 rating from 111 reviews, and was last updated Aug 30, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v3.2.0 Current Version v3.2.0
Updated 2 weeks ago Last Update on 30 Aug, 2026
Refreshed 11 hours ago Last Refreshed on
#20 of 622 in Accessibility Top 5% by installs Downloads -43.1% this week Actively maintained
View on WordPress.org
Rank
#2,472
-2 this week
Active Installs
8K+
-5%
KW Avg Position
6.2
No change
Downloads
116.5K
+68 today
Support Resolved
0%
No change
Rating
98%
Review 4.9 out of 5
4.9 (111 reviews)

Next Milestone 9K

Total Progress 44.1%
8K+ 9K+
143
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 559 more installs to reach 9K+

Rank Changes

2,347 2,410 2,473 2,535 2,598 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
2,347 2,410 2,473 2,536 2,599 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #2,472
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

50 60 70 80 90 100 110 120 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
50 100 150 200 250 300 350 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.9
111 reviews
Overall 98%
5
106 (95%)
4
2 (2%)
3
0 (0%)
2
2 (2%)
1
1 (1%)

Support Threads Overview

Resolved
Unresolved
1
Total Threads
0
Resolved
1
Unresolved
0%
Resolution Rate

Security History

Source: WPVulnerability

1 known vulnerability on record · 1 in the last 24 months · checked 2 days ago

  1. Loggedin – Session Manager, Limit Concurrent Logins & Force Logout [loggedin] < 1.3.2

    CVE-2024-9228 · Fixed in v1.3.2

TL;DR

AI summary of the plugin's readme

This plugin is for membership sites, online courses, subscription stores, corporate portals, and communities that need to control how many devices can log into one account. It solves account sharing by capping concurrent WordPress sessions and letting admins choose whether to log out the oldest device, log out all other devices, or block new logins when the cap is hit.

  • Global concurrent-login limit
  • Logout Oldest mode
  • Logout All mode
  • Block New login mode
  • Admin Force Logout panel
  • Works with WP_Session_Tokens API
  • Customizable error message
  • Translation-ready

Frequently Asked Questions

Common questions about Loggedin - Session Manager, Limit Concurrent Logins & Force Logout

It manages the sessions WordPress already creates, rather than replacing WordPress's session handling. Here's exactly what's in the free plugin: Limit how many sessions an account can hold at once, and choose what happens when the limit is reached. Force logout every session for any user, from the admin or from WP-CLI. Inspect a user's active sessions — login time, expiry, IP and device — via wp loggedin sessions list. For a live, sortable view of every signed-in user across the site, with per-device detail and one-click sign-out, add the Active Sessions add-on. To sign idle users out automatically, add the Auto Logout add-on. Login alerts are on the roadmap as an add-on too. If all you need is to cap concurrent logins and stop account sharing, the free plugin does that on its own — no add-on required.
It stops simultaneous sharing — two people can't be signed in to the same account on different devices at the same time once the cap is set to 1. They can still take turns logging in if you don't want to block the new login outright. Pick Block New mode to refuse the second login entirely and force the password-sharer to also log out the first device, which most people won't do.
Yes. Loggedin hooks into the standard WordPress authentication pipeline (wp_authenticate_user and check_password), so any plugin that logs users in through the normal WordPress flow — which is essentially every membership, LMS, e-commerce, and community plugin — is covered automatically. No integration code required.
Yes, with the official Limit Per Role add-on. It adds a per-role panel to the settings page where you can give each WordPress role its own cap (e.g. administrators: 5, editors: 3, subscribers: 1). Users with multiple roles get the highest configured limit.
Yes, with the official Limit Per User add-on. It adds a field to the WordPress profile screen so you can override the global cap on a per-user basis — useful for shared editorial accounts, executive users, or anyone who legitimately needs more sessions than your default.
Yes, with the official Auto Logout add-on. Set an inactivity timeout and idle users are signed out on their own, with an optional warning shown before the session ends — useful for shared workstations and anywhere an unattended browser shouldn't stay signed in.
No. Loggedin only acts when a new login happens. Existing sessions stay active until they expire, the user logs out, or a future login displaces them under the rule you've configured.
In the WordPress admin, go to Users → Loggedin. You'll see two tabs — Settings for the cap and login logic, and Add-ons for installing and licensing first-party extensions.
The plugin offers three built-in modes: Logout Oldest — When the limit is reached, the user's single oldest active session is terminated to make room for the new login. Closest match to consumer "remember me" UX. Logout All — When the limit is reached, every other active session for the user is terminated and the new login becomes the only active session. Block New — When the limit is reached, the new login attempt is rejected with an error on wp-login. Additional modes can be added via the loggedin_logics filter. See the General Settings docs for details.
The duration of a WordPress login session is controlled by WordPress, not Loggedin. "Remember Me" checked at login → session lasts 14 days. "Remember Me" not checked → session lasts 2 days. Customize the duration with the standard auth_cookie_expiration filter: `php function custom_auth_cookie_expiration( $expire ) { return MONTH_IN_SECONDS; // 30 days for every login. } add_filter( 'auth_cookie_expiration', 'custom_auth_cookie_expiration' ); `

Sign In / Register

You need to sign in or register to use this feature.