{"id":381957,"date":"2026-10-06T21:25:17","date_gmt":"2026-10-06T21:25:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/egydevinfo-sign-in-with-google\/"},"modified":"2026-10-06T21:24:57","modified_gmt":"2026-10-06T21:24:57","slug":"egydevinfo-sign-in-with-google","status":"publish","type":"plugin","link":"https:\/\/vec.wordpress.org\/plugins\/egydevinfo-sign-in-with-google\/","author":23319591,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.2","stable_tag":"1.1.2","tested":"7.1.3","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"EgyDevInfo Sign In with Google","header_author":"EgyDevInfo.com - Egypt Web Developers","header_description":"Add a secure \"Sign in with Google\" button to WordPress and WooCommerce, with a guided setup that shows exactly what to paste into Google Cloud.","assets_banners_color":"64779a","last_updated":"2026-10-06 21:24:57","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/www.egydevinfo.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":136,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.2":{"tag":"1.1.2","author":"egydevinfo","date":"2026-10-06 21:24:57","revision":3731596}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3731595,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3731595,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3731595,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3731595,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.2"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3731595,"resolution":"1","location":"assets","locale":"","width":1416,"height":758},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3731595,"resolution":"2","location":"assets","locale":"","width":814,"height":814},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3731595,"resolution":"3","location":"assets","locale":"","width":1000,"height":900},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3731595,"resolution":"4","location":"assets","locale":"","width":1000,"height":900},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3731595,"resolution":"6","location":"assets","locale":"","width":1920,"height":1778}},"screenshots":[]},"plugin_section":[],"plugin_tags":[3098,602,2061,2056,286],"plugin_category":[38,45],"plugin_contributors":[280526],"plugin_business_model":[],"class_list":["post-381957","plugin","type-plugin","status-publish","hentry","plugin_tags-google-login","plugin_tags-login","plugin_tags-oauth","plugin_tags-social-login","plugin_tags-woocommerce","plugin_category-authentication","plugin_category-ecommerce","plugin_contributors-egydevinfo","plugin_committers-egydevinfo"],"banners":{"banner":"https:\/\/ps.w.org\/egydevinfo-sign-in-with-google\/assets\/banner-772x250.png?rev=3731595","banner_2x":"https:\/\/ps.w.org\/egydevinfo-sign-in-with-google\/assets\/banner-1544x500.png?rev=3731595","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/egydevinfo-sign-in-with-google\/assets\/icon-128x128.png?rev=3731595","icon_2x":"https:\/\/ps.w.org\/egydevinfo-sign-in-with-google\/assets\/icon-256x256.png?rev=3731595","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/egydevinfo-sign-in-with-google\/assets\/screenshot-1.jpg?rev=3731595","caption":""},{"src":"https:\/\/ps.w.org\/egydevinfo-sign-in-with-google\/assets\/screenshot-2.png?rev=3731595","caption":""},{"src":"https:\/\/ps.w.org\/egydevinfo-sign-in-with-google\/assets\/screenshot-3.png?rev=3731595","caption":""},{"src":"https:\/\/ps.w.org\/egydevinfo-sign-in-with-google\/assets\/screenshot-4.png?rev=3731595","caption":""},{"src":"https:\/\/ps.w.org\/egydevinfo-sign-in-with-google\/assets\/screenshot-6.png?rev=3731595","caption":""}],"raw_content":"<!--section=description-->\n<p>Most \"Sign in with Google\" setups fail in the Google Cloud console, not in WordPress: a redirect URI pasted slightly wrong, an app left in \"Testing\" mode so real visitors are blocked, or a site moved to a new domain and login silently breaking. This plugin is built around fixing that.<\/p>\n\n<p><strong>A setup page that walks you through Google Cloud<\/strong><\/p>\n\n<ul>\n<li>Step-by-step instructions with direct links to the right Google Cloud pages.<\/li>\n<li>The exact redirect URI and authorized domain for <em>your<\/em> site, each with a copy button.<\/li>\n<li>Warnings for the common traps: publishing the app so it is not stuck in \"Testing\", and why not to upload a logo (it triggers a brand verification review).<\/li>\n<li>A <strong>Run test sign-in<\/strong> button that performs a real Google sign-in without logging you in, and explains any failure in plain language (wrong Client ID\/Secret, redirect URI mismatch, server cannot reach Google).<\/li>\n<li>If your site address changes (staging copy, new domain, http to https, www change), you get a clear notice with the new redirect URI to add in Google.<\/li>\n<\/ul>\n\n<p><strong>A button that keeps working on real sites<\/strong><\/p>\n\n<ul>\n<li>The button is a plain link that runs a server-side sign-in. It needs no JavaScript on your pages and carries no nonce, so full-page caching and JavaScript \"delay\/defer\/combine\" optimizers do not break it.<\/li>\n<li>Works on the WordPress login and registration pages, the WooCommerce My Account login and registration forms, and the WooCommerce checkout for guests \u2014 both the classic checkout and the Checkout block.<\/li>\n<li>A shortcode for anywhere else: <code>[egydevinfo_siwg_button]<\/code>.<\/li>\n<li>Light, dark and neutral styles following Google's sign-in button guidelines. RTL-ready.<\/li>\n<\/ul>\n\n<p><strong>Careful account handling<\/strong><\/p>\n\n<ul>\n<li>Accounts are matched on Google's permanent account ID, not the email address.<\/li>\n<li>An existing account is linked automatically only when Google is authoritative for the email address (a verified Gmail or Google Workspace address). Anyone else logs in with their password once and clicks \"Connect Google account\".<\/li>\n<li>Administrators, editors and shop managers are never linked automatically unless you allow it.<\/li>\n<li>ID tokens are checked for signature, issuer, audience, expiry and a one-time nonce; the sign-in uses a one-time state value bound to the visitor's browser, plus PKCE.<\/li>\n<li>New accounts follow your site's registration settings (or your choice), and new users only ever get a role without back-end editing powers (Customer with WooCommerce).<\/li>\n<li>Optional: restrict sign-in to your company's Google Workspace domain.<\/li>\n<li>Users can connect and disconnect Google from their profile or the WooCommerce \"Account details\" page.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to Google's sign-in service (Google Identity \/ OAuth 2.0) so visitors can sign in with their Google account. Nothing is sent to Google until a visitor clicks the button (or an administrator runs the test sign-in).<\/p>\n\n<ul>\n<li>When the button is clicked, the visitor's browser is sent to <code>accounts.google.com<\/code> with your Client ID, the redirect URI, and one-time security values.<\/li>\n<li>After the visitor approves, your server sends the one-time authorization code, your Client ID and Client Secret to <code>oauth2.googleapis.com<\/code> and receives the visitor's Google account ID, name and email address.<\/li>\n<li>Your server downloads Google's public signing keys from <code>www.googleapis.com<\/code> to verify the response (cached).<\/li>\n<\/ul>\n\n<p>Google Terms of Service: https:\/\/policies.google.com\/terms\nGoogle Privacy Policy: https:\/\/policies.google.com\/privacy\nGoogle API Services User Data Policy: https:\/\/developers.google.com\/terms\/api-services-user-data-policy<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>The plugin stores the visitor's Google account ID and email address as user meta so they can sign in again. It uses their name and email address to create an account when allowed. It does not store Google access tokens and never receives the visitor's Google password. It adds suggested text to your site's privacy policy guide. Uninstalling removes the stored Google links; user accounts are kept.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate the plugin. You are taken straight to the setup wizard.<\/li>\n<li>Follow the wizard (about five minutes). Your site must use HTTPS \u2014 Google requires it.<\/li>\n<li>Afterwards, find the wizard again any time from <strong>Settings \u2192 Sign In with Google \u2192 Change credentials<\/strong>.<\/li>\n<\/ol>\n\n<p>For agencies: you can define the credentials in <code>wp-config.php<\/code> instead of the database:<\/p>\n\n<pre><code>define( 'EGYDEVINFO_SIWG_CLIENT_ID', '...' );\ndefine( 'EGYDEVINFO_SIWG_CLIENT_SECRET', '...' );\n<\/code><\/pre>\n\n<!--section=faq-->\n<dl>\n<dt id=\"google%20says%20%22error%20400%3A%20redirect_uri_mismatch%22\"><h3>Google says \"Error 400: redirect_uri_mismatch\"<\/h3><\/dt>\n<dd><p>The redirect URI in your Google OAuth client does not match your site. Reopen the setup wizard (Settings \u2192 Sign In with Google \u2192 Change credentials \u2192 Back to the OAuth client step), copy the redirect URI again, and paste it into \"Authorized redirect URIs\" exactly. It can take a few minutes for Google to apply the change.<\/p><\/dd>\n<dt id=\"visitors%20see%20%22access%20blocked%22%20but%20it%20works%20for%20me\"><h3>Visitors see \"Access blocked\" but it works for me<\/h3><\/dt>\n<dd><p>Your Google app is still in \"Testing\" mode, where only listed test users can sign in. Open Google Auth Platform \u2192 Audience and click \"Publish app\".<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20page%20caching%20%28litespeed%20cache%2C%20wp%20rocket%2C%20etc.%29%3F\"><h3>Does it work with page caching (LiteSpeed Cache, WP Rocket, etc.)?<\/h3><\/dt>\n<dd><p>The button is a plain link with no nonce and no JavaScript, so cached pages keep working. The sign-in endpoints themselves send no-cache headers. Please still test once on your live site after setup.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20the%20woocommerce%20checkout%20block%3F\"><h3>Does it work with the WooCommerce Checkout block?<\/h3><\/dt>\n<dd><p>Yes. The button is added above the Checkout block for guests, and above the classic checkout form on shortcode-based checkouts.<\/p><\/dd>\n<dt id=\"a%20customer%20already%20has%20an%20account%20with%20the%20same%20email.%20what%20happens%3F\"><h3>A customer already has an account with the same email. What happens?<\/h3><\/dt>\n<dd><p>If the address is a verified Gmail or Google Workspace address, the accounts are linked automatically and the customer is signed in. Otherwise, for safety, they are asked to log in with their password once and connect Google from their account page.<\/p><\/dd>\n<dt id=\"can%20i%20use%20it%20for%20staff%20only%20%2F%20my%20company%20domain%20only%3F\"><h3>Can I use it for staff only \/ my company domain only?<\/h3><\/dt>\n<dd><p>Yes. Set \"Allowed email domains\" to your Google Workspace domain, and set \"New accounts\" to \"Never\" if staff accounts are created manually.<\/p><\/dd>\n<dt id=\"does%20it%20support%20facebook%20or%20x%3F\"><h3>Does it support Facebook or X?<\/h3><\/dt>\n<dd><p>Not at the moment. This plugin focuses on Google only.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Enhancement: redesigned the setup wizard \u2014 a connected step indicator (numbered circles, checkmarks for completed steps), a clearer required\/optional badge on the Google Cloud field table, and a more polished card layout, shared with the simplified settings page.<\/li>\n<li>Plugin Check: addressed all warnings\/errors from a Plugin Check run (nonce-verification and input-sanitization notes on the credentials save handler, false-positive \"offloaded content\" flags on Google-domain placeholder\/help text, and a false-positive unprefixed-constant flag on the required <code>DONOTCACHEPAGE<\/code> constant name).<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Fix: a \"Passing null to strip_tags()\" PHP deprecation notice on activation\/wp-admin, caused by hiding the setup wizard's Dashboard menu entry with <code>remove_submenu_page()<\/code> \u2014 that also broke WordPress's own page-title lookup for that page. The entry is now hidden with CSS instead, so the page stays properly registered.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: a guided setup wizard opens automatically right after activation (also reachable any time from Settings \u2192 \"Change credentials\"), replacing the old numbered steps on the settings page.<\/li>\n<li>Fix: Google Cloud's client-creation page now shown with both fields in Google's own order \u2014 \"Authorized JavaScript origins\" before \"Authorized redirect URIs\" \u2014 with a warning against pasting the redirect URI into the origins box, the single most common setup mistake.<\/li>\n<li>Fix: the wizard's first step now asks whether you already have a Google Cloud project for this site and skips straight to the OAuth client step if so, instead of assuming a blank-slate Google account.<\/li>\n<li>Fix: \"Run test sign-in\" now returns to wherever it was launched from (the wizard or the settings page) instead of always landing on the settings page.<\/li>\n<li>The settings page is now settings only (placement, accounts, button style); Client ID\/Secret are managed from the wizard.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release.<\/li>\n<\/ul>","raw_excerpt":"Google sign-in for WordPress and WooCommerce, with a guided setup that shows exactly what to paste into Google and a cache-proof button.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/381957","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=381957"}],"author":[{"embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/egydevinfo"}],"wp:attachment":[{"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=381957"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=381957"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=381957"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=381957"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=381957"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/vec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=381957"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}