plugin-icon

Custom Auth Suite™

Custom Auth Suite creates custom login, registration, password reset and email verification flows with protected paths and optional assisted support.
Version
0.9.2
Last updated
Aug 31, 2026
Custom Auth Suite™

Custom Auth Suite creates custom login, registration, password reset and email verification flows with protected paths and optional assisted support.

The Free package includes:

  • Custom login, registration, lost-password and reset-confirmation flows.
  • Email verification and authentication email templates.
  • Protected paths, safe redirects and account-access helpers.
  • Authentication-page creation, assignment and route checks.
  • A local Installation Doctor with compatibility checks and privacy-limited JSON/HTML reports.

No paid license is required for these Free features.

The Free interface may show clearly identified, read-only previews of separately distributed Advanced and Premium capabilities. Commercial modules are absent from the WordPress.org package; previews save no commercial settings and do not restrict Free features.

In the WordPress.org Free package, Upgrade CAS may show two bundled Advanced/Premium information cards. Each can be dismissed locally for 20 days and sends no impression, CTA-click or dismiss analytics.

The Doctor Compatibility Scan lists plugin name, slug, version and status under “Plugins recognized as CAS-relevant” or “Other unclassified plugins.” Unclassified is not a safety judgment. Acknowledged Warnings remain visible but stop auto-opening until context changes. False diagnostic booleans are shown as no.

Custom Auth Suite works with WordPress users. It does not create a membership or payment system.

External Services

CAS is local-first. These optional services contact external servers only under the stated conditions.

Remote Admin Messages

Disabled by default. After explicit administrator opt-in, CAS may request operational JSON notices from:

https://customauthsuite.com/wp-json/cas-remote-messages/v1/messages

A request may include CAS version/package, placement, locale, plan or support status, limited compatibility context and a privacy-preserving site hash. Free notices are limited to security, compatibility, maintenance, documentation and support. A dismissible renewal notice may appear only for support already purchased and validated. Remote commercial upgrade cards are not requested or rendered.

CAS normalizes the response and does not execute remote PHP/JavaScript or render arbitrary remote HTML. Disabling the option stops future requests.

Remote Message Interaction Analytics

Disabled by default and controlled separately. When enabled, CAS may send privacy-safe CTA-click events for remote notices and local review/Doctor resource links. Data may include action/message/placement IDs, CTA label, CAS version/package, available license context, a privacy-preserving site hash, timestamp and delivery status. Events are sent to:

https://customauthsuite.com/wp-json/cas-remote-messages/v1/events

Local preference actions are not sent.

The local Advanced/Premium cards never send impression, CTA-click or dismiss events to CAS RM.

Assisted Doctor Support

Disabled by default. After explicit opt-in and an administrator click on “Open support request”, CAS creates one redacted Doctor report behind a random handoff token and opens the support page for retrieval. The handoff normally expires after 30 minutes and is bounded to one hour.

Disabling Assisted Doctor Support immediately invalidates existing handoffs, including those created before re-enablement. Reports are designed to exclude passwords, cookies, nonces, authorization headers, complete license keys, API secrets, private keys and diagnostic tokens.

Remote Support Diagnostics

This ticket-based mechanism requires case consent, a temporary signed token, an administrator with manage_options, and manual nonce-protected activation. Opening a support link does not activate it.

CAS may contact the revocation endpoint embedded in the signed support token to check whether the temporary session has been revoked. For CAS Support Desk tokens, the endpoint is:

https://customauthsuite.com/wp-json/cas-support-desk/v1/support-diagnostics/revocation

Requests may include a token-identifier hash, case ID, privacy-preserving site hash and timestamp, but not the full signed token, WordPress credentials or private secrets. Local termination is immediate and remains effective if a remote notice fails. This is not a remote login, creates no users and does not automatically upload reports.

Optional manual website resource

A manual link may open:

https://customauthsuite.com/privacy-cookie-notes/

The plugin opens it only when clicked. The request may include domain, language and selected package mode. Generated notes describe CAS-related data flows and should be reviewed and adapted to the site’s actual configuration before publication.

Service information:

  • Website: https://customauthsuite.com/
  • Terms: https://customauthsuite.com/terms-of-use/
  • Privacy: https://customauthsuite.com/privacy-cookie-policy/

The Free package does not use commercial license, update or package-download services.

Privacy and Local Data Handling

CAS primarily stores data locally. Depending on enabled features, this may include settings/routes, authentication account fields, verification and password-reset state, protected paths, Doctor/report data, warning fingerprints and enabled logs.

Doctor inventory entries contain only plugin name, slug, version and status. Reports and logs remain local unless deliberately shared; review them first. Uninstall cleanup follows the CAS retention setting.

Support

Free support is provided through the official WordPress.org support forum after publication. Product information and commercial support options are available at:

https://customauthsuite.com/

Never publish passwords, license keys, diagnostic tokens, cookies, nonces or other secrets in a public forum.

Freeon paid plans
Tested up to
WordPress 7.1
This plugin is available for download for your site.