79 Quality Score
Active Installs
17/30

With roughly 5,000 active installs, Authorizer is a niche tool rather than a mainstream pick, but its audience is exactly the kind of organizations that need its SSO features.

Update Freshness
25/25

A perfect maintenance score is backed by a recent update on 2026-05-27 and confirmed compatibility with WordPress 7.0, which signals an actively maintained codebase.

User Rating
15/15

Every reviewer gave it a perfect 100, and with 20 ratings the sample is small but uniformly positive, suggesting users who install it tend to be the ones who needed exactly what it offers.

Support Health
8/15

Zero support threads on record is a double-edged signal: it either means the plugin rarely breaks or it means the maintainer is unresponsive, and with no resolved tickets there is no way to confirm which.

WP Compatibility
15/15

Full marks here reflect that it requires only WordPress 5.5 and PHP 8.1, runs against the latest 7.0 release, and does not appear to have any open compatibility conflicts.

Scores higher than 75% of indexed plugins

About

Authorizer limits login attempts, restricts access to specific users, and authenticates against external sources (OAuth2, Google, LDAP, or CAS).

Active Installs 6k+
Rating ★★★★★ 5/5
Last Updated 2026-09-21 9:50pm GMT
Requires WordPress 5.9+
Tested Up To 7.1.2
Requires PHP 8.1+

Security History

2 known vulnerabilities, all patched
1 Critical 1 High

Most recent: September 1, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

Authorizer limits login attempts, restricts site access to specific users or groups, and lets WordPress authenticate logins against external sources such as LDAP, CAS, Google Workspace, or any OAuth2 provider. It functions as a centralized gatekeeper for both front-end content and the wp-login screen, including per-page or per-post access rules.

Who It's For

This plugin is built for organizations that already manage users in an external directory and want WordPress to defer to that source of truth, including universities running LDAP or CAS, companies using Google Workspace or Okta for SSO, and regulated teams that need both brute-force protection and granular content restrictions. It is overkill for small brochure sites or personal blogs.

Who Should Skip It

Anyone running a public-facing blog, small business site, or WooCommerce store that does not need SSO, LDAP, or CAS will find this plugin far heavier than necessary. If you only want to rename your login URL or lock out brute-force bots, a lighter alternative such as WPS Hide Login or a dedicated security suite is a better fit.

The Bottom Line

Authorizer earns its 79.07/100 overall score by being one of the few plugins that genuinely unifies brute-force limiting, content restriction, and enterprise SSO in a single, recently maintained package. The biggest question mark is the zero support threads, but with perfect ratings and current compatibility, it is a credible choice for organizations that already live inside LDAP, CAS, or an OAuth2 identity provider. If you fall outside that group, the alternatives above will serve you better.

Tags

authentication cas ldap login oauth