Authorizer
View on WordPress.orgScores higher than 75% of indexed plugins
About
Authorizer limits login attempts, restricts access to specific users, and authenticates against external sources (OAuth2, Google, LDAP, or CAS).
Security History
What It Does
Authorizer limits login attempts, restricts site access to specific users or groups, and lets WordPress authenticate logins against external sources such as LDAP, CAS, Google Workspace, or any OAuth2 provider. It functions as a centralized gatekeeper for both front-end content and the wp-login screen, including per-page or per-post access rules.
Who It's For
This plugin is built for organizations that already manage users in an external directory and want WordPress to defer to that source of truth, including universities running LDAP or CAS, companies using Google Workspace or Okta for SSO, and regulated teams that need both brute-force protection and granular content restrictions. It is overkill for small brochure sites or personal blogs.
Who Should Skip It
Anyone running a public-facing blog, small business site, or WooCommerce store that does not need SSO, LDAP, or CAS will find this plugin far heavier than necessary. If you only want to rename your login URL or lock out brute-force bots, a lighter alternative such as WPS Hide Login or a dedicated security suite is a better fit.
The Bottom Line
Authorizer earns its 79.07/100 overall score by being one of the few plugins that genuinely unifies brute-force limiting, content restriction, and enterprise SSO in a single, recently maintained package. The biggest question mark is the zero support threads, but with perfect ratings and current compatibility, it is a credible choice for organizations that already live inside LDAP, CAS, or an OAuth2 identity provider. If you fall outside that group, the alternatives above will serve you better.
Related Plugins
Pick WPS Hide Login if your only goal is to obscure the default wp-login URL from automated scanners, with none of the SSO or LDAP overhead Authorizer brings.
Choose Loginizer when brute-force protection is the priority and you do not need to authenticate against an external directory.
Reach for this when you want login hardening bundled into a broader firewall, malware scanner, and cleanup toolkit rather than focused directory integration.
Select SiteGround Security if you want login limits, IP blocking, and activity logs in one general-purpose hardening suite without configuring LDAP or OAuth2.
Choose LoginPress when your interest is in redesigning the wp-login screen with branding and custom fields, not in locking down authentication.