QRAuth – Passwordless & Social Login
by QRAuth 5 (1 reviews)

QRAuth – Passwordless & Social Login

Passwordless sign-in for WordPress. Users scan a QR code with the QRAuth mobile app — no passwords, no forms, no OAuth apps to register.

QRAuth ranks #25,133 among WordPress.org plugins with 10+ active installations, is #609 of 1,590 in the Authentication category, a 5/5 rating from 1 reviews, and was last updated Jun 3, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7 (Current: 7.1.2)
v0.1.23 Current Version v0.1.23
Updated 3 months ago Last Update on 03 Jun, 2026
Refreshed 9 hours ago Last Refreshed on
#609 of 1,590 in Authentication Top 50% by installs
View on WordPress.org
Rank
#25,133
No change
Active Installs
10+
-60%
KW Avg Position
116.3
0.3 worse
Downloads
363
+1 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (1 reviews)

Next Milestone 20

Total Progress 50%
10+ 20+
23,112
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 5 more installs to reach 20+

Rank Changes

24,591 24,744 24,898 25,051 25,204 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
24,562 24,778 24,995 25,211 25,427 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #25,133
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 20 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
1 reviews
Overall 100%
5
1 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about QRAuth – Passwordless & Social Login

Only if they sign in via QR. They install the free QRAuth mobile app once, scan the code on your login page, and approve on their phone. For social login (Google, GitHub, Microsoft, Apple) the user simply taps the provider on QRAuth's hosted approval page — they don't need a QRAuth account at all.
They aren't. Auto-provisioned accounts get a 32-character random password that nobody (including you) holds or needs. WordPress users who already had a password keep it — QRAuth just becomes an additional sign-in method alongside the usual form.
Yes. If a scanned account's email matches an existing WordPress user, they log into that account — no duplicate is created. The match is remembered via user meta, so subsequent sign-ins skip the email lookup.
Subscriber, hardcoded. The settings UI only offers Subscriber, the sanitiser clamps any other value to Subscriber, and the provisioner ignores the stored option entirely and uses Subscriber unconditionally — this aligns with WordPress.org plugin directory guidelines for sign-in plugins that create users post-external-verification. There is no plugin-provided code path (filter, action, option, or constant) to elevate the auto-provisioning role. If a particular user needs a higher role, change it manually via Users → All Users after their first sign-in.
Yes — from Users → Your Profile there's a QRAuth section with an "Unlink QRAuth" button. Admins can unlink other users from their profiles too. The WordPress account (role, posts, comments, history) is preserved; only the link metadata is removed.
Yes. Deactivate and all your users stay. Uninstall removes the plugin's settings row and its rate-limit transients — it never deletes WordPress user accounts or their content. If you reinstall later, existing users re-link automatically on their next QRAuth sign-in.
No. There's no telemetry, no analytics, no third-party scripts. The only outbound request is from your server to https://qrauth.io/api/v1/auth-sessions/verify-result during a login attempt, carrying only the session ID and the signature the user's phone produced.
The REST verify route caps requests at 10 per 5 minutes per hashed IP. The hash uses wp_salt(), so a database dump can't recover caller IPs. Each verify attempt costs one outbound call to QRAuth's servers, so tight limits protect both your site and ours.
Per-site activation works today. Network-activated multisite is tracked for a future release.

Sign In / Register

You need to sign in or register to use this feature.