[WordPress] 外掛分享: WebPlatform Social Login

首頁外掛目錄 › WebPlatform Social Login
全新外掛
安裝啟用
尚無評分
2 天前
最後更新
問題解決
WordPress 6.5+ PHP 8.0+ v1.4.4 上架:2026-07-27

內容簡介

WebPlatform Social Login 外掛為 WordPress 提供安全的社交登入按鈕,支援多種社交平台的身份驗證,讓使用者能夠輕鬆登入網站,提升用戶體驗與安全性。

【主要功能】
• 驗證 Google ID 令牌簽名
• 支援 Facebook、LinkedIn 和 Microsoft 的 OAuth
• 支援 Apple 登入及動態 ES256 客戶端聲明
• 連接現有用戶並可選擇創建新用戶
• 在 WooCommerce 和標準登入表單中顯示
• 提供 Google One Tap 功能給登出訪客

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.4.4) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「WebPlatform Social Login」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

WebPlatform Social Login adds secure social sign-in buttons to WordPress.
Features:

Verifies Google ID token signatures using Google’s published public keys.
Supports Facebook OAuth, LinkedIn OpenID Connect and Microsoft OpenID Connect.
Supports Sign in with Apple, including dynamic ES256 client assertions.
Validates token audience, issuer, expiry, email verification and nonce.
Protects login requests with short-lived, HttpOnly state cookies.
Encrypts provider secrets and Apple private keys at rest using WordPress authentication salts.
Connects existing users by verified email.
Optionally creates new WordPress users.
Displays on WooCommerce login and registration forms.
Displays on standard WordPress login and registration forms.
Optionally offers Google One Tap to logged-out visitors using the Google account active in their browser.
Includes [webplatform_social_login] for custom pages.
Supports local post-login redirects and optional email-domain restrictions.
Integrates with WordPress personal-data export and erasure tools.

No Google Client Secret is stored or required. Other providers require their standard application credentials.
External services
This plugin connects to external identity services only when the site owner enables them. When Google One Tap is enabled, Google Identity Services may be loaded for logged-out visitors before they choose to sign in.

The browser downloads the Google Identity Services library from https://accounts.google.com/gsi/client when a login button is displayed. The site’s OAuth Client ID and standard browser request information are sent to Google.
After the visitor chooses a Google account, Google returns a signed identity token to the website. The token contains the account identifier and basic profile fields approved by the visitor.
The server periodically downloads public signing keys from https://www.googleapis.com/oauth2/v3/certs to verify tokens. No visitor identity data is sent when public keys are downloaded.

This service is provided by Google under the Google APIs Terms of Service and Google Privacy Policy.
For enabled OAuth providers, the visitor is sent to the provider’s authorization page. The plugin sends the application Client ID, callback URL, requested basic-profile/email scopes, and a random state value. The provider sends an authorization code back to the website. The server exchanges that code and requests the visitor’s identifier, name, verified email and optional profile image.

Facebook endpoints use facebook.com and graph.facebook.com. Meta Platform Terms and Meta Privacy Policy.
LinkedIn endpoints use linkedin.com and api.linkedin.com. LinkedIn API Terms and LinkedIn Privacy Policy.
Microsoft endpoints use login.microsoftonline.com and graph.microsoft.com. Microsoft APIs Terms and Microsoft Privacy Statement.
Apple endpoints use appleid.apple.com. The plugin also downloads Apple’s public signing keys to validate ID tokens. Sign in with Apple terms and Apple Privacy Policy.

Privacy
When a visitor uses a social provider, that provider returns an account identifier and basic profile fields such as name, verified email address and profile image. The plugin stores the provider account identifier and profile image URL in WordPress user metadata. WordPress core stores the user’s name and email as part of the user account.
The browser loads Google’s Identity Services JavaScript from accounts.google.com when Google login is configured. Other providers are contacted only when their button is selected. Site owners should disclose enabled external services in their privacy policy and obtain any consent required in their jurisdiction.
Plugin metadata is available through WordPress personal-data export and erasure tools.

延伸相關外掛

文章
Filter
Apply Filters
Mastodon