WP SAML Auth
by Pantheon Systems 4.5 (8 reviews)

WP SAML Auth

SAML authentication for WordPress.

WP SAML Auth ranks #2,595 among WordPress.org plugins with 7,000+ active installations, is #96 of 1,578 in the Authentication category, a 4.5/5 rating from 8 reviews, and was last updated Aug 12, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7 (Current: 7.1)
v2.3.4 Current Version v2.3.4
Updated 1 month ago Last Update on 12 Aug, 2026
Refreshed 14 hours ago Last Refreshed on
#96 of 1,578 in Authentication Top 5% by installs Downloads -23.6% this week
View on WordPress.org
Rank
#2,595
-1 this week
Active Installs
7K+
-8.5%
KW Avg Position
6
No change
Downloads
200.8K
+22 today
Support Resolved
100%
No change
Rating
90%
Review 4.5 out of 5
4.5 (8 reviews)

Next Milestone 8K

Total Progress 70.2%
7K+ 8K+
98
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 298 more installs to reach 8K+

Rank Changes

2,464 2,530 2,597 2,663 2,729 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
2,589 2,596 2,603 2,609 2,616 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #2,595
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 50 100 150 200 250 300 350 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
0 50 100 150 200 250 300 350 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.5
8 reviews
Overall 90%
5
7 (88%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
1 (13%)

Support Threads Overview

Resolved
Unresolved
2
Total Threads
2
Resolved
0
Unresolved
100%
Resolution Rate

Security History

Source: WPVulnerability

No known vulnerabilities on record for WP SAML Auth. Checked 2 days ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site administrators who need to authenticate users via a SAML identity provider, optionally alongside SimpleSAMLphp's other authentication mechanisms. It solves the problem of connecting WordPress login to an external SAML/SimpleSAMLphp identity provider, automatically provisioning and signing users in and out through that provider.

  • SAML login button on wp-login.php
  • Bundled OneLogin SAML library
  • Optional SimpleSAMLphp integration
  • Automatic new user provisioning
  • Disable auto-provisioning option
  • Bypass wp-login.php option
  • Single logout with identity provider
  • WP-CLI scaffold-config command

Frequently Asked Questions

Common questions about WP SAML Auth

If you'd like to make sure the user's display name, first name, and last name are updated in WordPress when they log back in, you can use the following code snippet: /** * Update user attributes after a user has logged in via SAML. */ add_action( 'wp_saml_auth_existing_user_authenticated', function( $existing_user, $attributes ) { $user_args = array( 'ID' => $existing_user->ID, ); foreach ( array( 'display_name', 'first_name', 'last_name' ) as $type ) { $attribute = \WP_SAML_Auth::get_option( "{$type}_attribute" ); $user_args[ $type ] = ! empty( $attributes[ $attribute ][0] ) ? $attributes[ $attribute ][0] : ''; } wp_update_user( $user_args ); }, 10, 2 ); The wp_saml_auth_existing_user_authenticated action fires after the user has successfully authenticated with the SAML IdP. The code snippet then uses a pattern similar to WP SAML Auth to fetch display name, first name, and last name from the SAML response. Lastly, the code snippet updates the existing WordPress user object.
Because SimpleSAMLphp uses PHP sessions to manage user authentication, it will work unreliably or not at all on a server configuration with multiple web nodes. This is because PHP's default session handler uses the filesystem, and each web node has a different filesystem. Fortunately, there's a way around this. First, install and activate the WP Native PHP Sessions plugin, which registers a database-based PHP session handler for WordPress to use. Next, modify SimpleSAMLphp's www/_include.php file to require wp-load.php. If you installed SimpleSAMLphp within the wp-saml-auth directory, you'd edit wp-saml-auth/simplesamlphp/www/_include.php to include: <?php require_once dirname( dirname( dirname( dirname( dirname( dirname( __FILE__ ) ) ) ) ) ) . '/wp-load.php'; Note: the declaration does need to be at the top of _include.php, to ensure WordPress (and thus the session handling) is loaded before SimpleSAMLphp. There is no third step. Because SimpleSAMLphp loads WordPress, which has WP Native PHP Sessions active, SimpleSAMLphp and WP SAML Auth will be able to communicate to one another on a multi web node environment.
Please report security bugs found in the source code of the WP SAML Auth plugin through the Patchstack Vulnerability Disclosure Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.
If you're using the SimpleSAMLphp connection type: * Critical Security Requirement: Version 2.0.0 or later is required to fix CVE-2023-26881 (XML signature validation bypass vulnerability). * Recommended Security Requirement: Version 2.3.7 or later is recommended for additional security fixes. * Authentication will be blocked for versions below 2.0.0 when "Enforce Security Requirements" is enabled. * It's always recommended to use the latest stable version of SimpleSAMLphp for security and compatibility.

Sign In / Register

You need to sign in or register to use this feature.