{"id":315026,"date":"2026-06-18T18:11:52","date_gmt":"2026-06-18T18:11:52","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/cs-biologin-seamless-biometric-authentication\/"},"modified":"2026-08-20T11:13:39","modified_gmt":"2026-08-20T11:13:39","slug":"cs-biologin-seamless-biometric-authentication","status":"publish","type":"plugin","link":"https:\/\/vi.wordpress.org\/plugins\/cs-biologin-seamless-biometric-authentication\/","author":23500825,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3.0","stable_tag":"1.3.0","tested":"7.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"CS BioLogin \u2013 Seamless Biometric Authentication","header_author":"Concatstring Solutions","header_description":"Replace passwords with fingerprints, FaceID, and TouchID. Secure your WordPress login using modern WebAuthn standards.","assets_banners_color":"2d3c71","last_updated":"2026-08-20 11:13:39","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/concatstring.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":392,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"concatstring","date":"2026-06-18 18:27:48"},"1.2.1":{"tag":"1.2.1","author":"concatstring","date":"2026-07-30 06:46:00"},"1.3.0":{"tag":"1.3.0","author":"concatstring","date":"2026-08-20 11:13:39"}},"upgrade_notice":{"1.3.0":"<p>Restrict Roles, Force Biometric Login, and Require Re-Authentication now actually enforce their settings. Review the Settings and Security Settings tabs after updating, and register a passkey for your own account before enabling Force Biometric Login.<\/p>","1.2.2":"<p>Improved security log performance, added log search\/filter, and fixed browser detection.<\/p>","1.2.1":"<p>Fixed the minor issue where activating the plugin triggered, fatal error.<\/p>","1.2.0":"<p>Fixed the issue where, the registration working when ZOHO vault is enabled\nAdded i18n support in js files for translation<\/p>","1.0.0":"<p>First WordPress.org release. Use HTTPS in production, configure settings under <strong>Biometric Login<\/strong>, then register a passkey from your profile or WooCommerce account<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3577670,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3577670,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3577670,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3577670,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.2.1","1.3.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3577670,"resolution":"1","location":"assets","locale":"","width":1280,"height":800},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3577670,"resolution":"2","location":"assets","locale":"","width":1280,"height":800},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3577670,"resolution":"3","location":"assets","locale":"","width":1280,"height":800},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3577670,"resolution":"4","location":"assets","locale":"","width":1280,"height":800},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3577670,"resolution":"5","location":"assets","locale":"","width":1280,"height":800}},"screenshots":{"1":"Biometric login popup on the WordPress login page.","2":"Device management in WooCommerce My Account.","3":"Registration flow with browser prompt.","4":"Admin settings page with security options.","5":"Security logs showing login events.","6":"Device already registered warning dialog."}},"plugin_section":[],"plugin_tags":[15783,39810,602,600,183349],"plugin_category":[38,54],"plugin_contributors":[266302,247404,141771,171506,266582,267773],"plugin_business_model":[],"class_list":["post-315026","plugin","type-plugin","status-publish","hentry","plugin_tags-biometric","plugin_tags-fingerprint","plugin_tags-login","plugin_tags-security","plugin_tags-webauthn","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-concatstring","plugin_contributors-hlakkad1998","plugin_contributors-kakshak","plugin_contributors-shobhit2412","plugin_contributors-sumittejani","plugin_contributors-vrutti22","plugin_committers-concatstring"],"banners":{"banner":"https:\/\/ps.w.org\/cs-biologin-seamless-biometric-authentication\/assets\/banner-772x250.png?rev=3577670","banner_2x":"https:\/\/ps.w.org\/cs-biologin-seamless-biometric-authentication\/assets\/banner-1544x500.png?rev=3577670","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/cs-biologin-seamless-biometric-authentication\/assets\/icon-128x128.png?rev=3577670","icon_2x":"https:\/\/ps.w.org\/cs-biologin-seamless-biometric-authentication\/assets\/icon-256x256.png?rev=3577670","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/cs-biologin-seamless-biometric-authentication\/assets\/screenshot-1.png?rev=3577670","caption":"Biometric login popup on the WordPress login page."},{"src":"https:\/\/ps.w.org\/cs-biologin-seamless-biometric-authentication\/assets\/screenshot-2.png?rev=3577670","caption":"Device management in WooCommerce My Account."},{"src":"https:\/\/ps.w.org\/cs-biologin-seamless-biometric-authentication\/assets\/screenshot-3.png?rev=3577670","caption":"Registration flow with browser prompt."},{"src":"https:\/\/ps.w.org\/cs-biologin-seamless-biometric-authentication\/assets\/screenshot-4.png?rev=3577670","caption":"Admin settings page with security options."},{"src":"https:\/\/ps.w.org\/cs-biologin-seamless-biometric-authentication\/assets\/screenshot-5.png?rev=3577670","caption":"Security logs showing login events."}],"raw_content":"<!--section=description-->\n<p><strong>CS BioLogin<\/strong> adds passwordless sign-in to WordPress using the WebAuthn standard (FIDO2 \/ passkeys). Visitors can authenticate with Face ID, Touch ID, Windows Hello, or a platform fingerprint reader. Biometric templates never leave the user's device; only public key credentials are stored in your WordPress database.<\/p>\n\n<p>\ud83d\udc49 See this plugin in context with our other products: <a href=\"https:\/\/labs.concatstring.com\/products\/cs-biologin-seamless-biometric-authentication\">Concatstring Labs Product Page<\/a><\/p>\n\n<h4>What this plugin does<\/h4>\n\n<ul>\n<li>Adds a <strong>Sign in with Biometrics<\/strong> option on the WordPress login screen, with password login still available unless Force Biometric Login is enabled.<\/li>\n<li>Lets logged-in users <strong>register, rename, update, and remove<\/strong> passkeys from their profile, a front-end shortcode page, or WooCommerce My Account.<\/li>\n<li>Provides an admin screen for <strong>settings, security logs, and per-user device management<\/strong>.<\/li>\n<li>Applies <strong>rate limiting and lockout<\/strong> on authentication attempts.<\/li>\n<\/ul>\n\n<h4>What this plugin does NOT do<\/h4>\n\n<ul>\n<li>It does <strong>not<\/strong> send user data, credentials, or biometrics to third-party servers. All verification runs on your site over HTTPS.<\/li>\n<li>It does <strong>not<\/strong> store fingerprint or face images, only WebAuthn public keys and device metadata you configure.<\/li>\n<\/ul>\n\n<h4>How it works<\/h4>\n\n<ol>\n<li><strong>Administrator<\/strong> enables the plugin under <strong>Biometric Login<\/strong> and, if needed, restricts specific roles from using biometrics.<\/li>\n<li><strong>User<\/strong> opens their profile (WordPress admin profile, <code>[csbisebi_device_manager]<\/code> page, or WooCommerce <strong>My Account \u2192 CS BioLogin<\/strong>) and clicks <strong>Add Biometric Device<\/strong>. The browser shows the OS passkey\/biometric prompt.<\/li>\n<li><strong>Login<\/strong>, on <code>wp-login.php<\/code> (or WooCommerce login), the user chooses biometric sign-in. The plugin issues a WebAuthn challenge via the REST API, verifies the signed response, and creates a normal WordPress session.<\/li>\n<\/ol>\n\n<p>REST routes live under <code>csbisebi-biometric-login\/v1<\/code> on your own site (for example <code>\/wp-json\/csbisebi-biometric-login\/v1\/auth\/options<\/code>). No external API keys are required.<\/p>\n\n<h4>WooCommerce<\/h4>\n\n<p>When WooCommerce is active, CS BioLogin adds a <strong>My Account<\/strong> tab, checkout\/account login prompts, and automatic use of the account area instead of a standalone management page.<\/p>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 6.2 or later<\/li>\n<li>PHP 7.4+ with OpenSSL<\/li>\n<li><strong>HTTPS<\/strong> on production (WebAuthn requires a secure context; <code>localhost<\/code> and <code>*.local<\/code> are allowed for development)<\/li>\n<\/ul>\n\n<h4>Privacy and data storage<\/h4>\n\n<ul>\n<li>Biometric samples stay on the user's device.<\/li>\n<li>The plugin stores passkey public keys, optional device labels, timestamps, and security log entries in your WordPress database.<\/li>\n<li>Uninstalling the plugin (when data removal is enabled via uninstall) drops the custom credentials table and plugin options.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder <code>cs-biologin-seamless-biometric-authentication<\/code> to <code>\/wp-content\/plugins\/<\/code> (the zip must contain <code>readme.txt<\/code> and <code>cs-biologin.php<\/code> at the root of that folder, not inside a <code>trunk\/<\/code> subfolder).<\/li>\n<li>Activate <strong>CS BioLogin \u2013 Seamless Biometric Authentication<\/strong> on the <strong>Plugins<\/strong> screen.<\/li>\n<li>Ensure your site uses <strong>HTTPS<\/strong> in production.<\/li>\n<li>Go to <strong>Biometric Login<\/strong> and save your preferences.<\/li>\n<li>Log in as a test user, open <strong>Users \u2192 Profile<\/strong> (or WooCommerce <strong>My Account \u2192 CS BioLogin<\/strong>), and register a passkey before testing front-end login.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20store%20my%20fingerprint%20or%20face%20on%20the%20server%3F\"><h3>Does this store my fingerprint or face on the server?<\/h3><\/dt>\n<dd><p>No. WebAuthn keeps biometrics on the device. The site only stores a public key used to verify future logins.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20call%20external%20services%3F\"><h3>Does the plugin call external services?<\/h3><\/dt>\n<dd><p>No. Challenges, verification, and credential storage all run on your WordPress installation. JavaScript and CSS are bundled with the plugin (no third-party CDNs).<\/p><\/dd>\n<dt id=\"is%20https%20required%3F\"><h3>Is HTTPS required?<\/h3><\/dt>\n<dd><p>Yes, for production sites. The plugin shows an admin notice if HTTPS is missing (localhost and <code>.local<\/code> hosts are exempt for development).<\/p><\/dd>\n<dt id=\"can%20users%20still%20log%20in%20with%20a%20password%3F\"><h3>Can users still log in with a password?<\/h3><\/dt>\n<dd><p>Yes, unless the administrator enables <strong>Force Biometric Login<\/strong>, which blocks password sign-in for any account that already has a registered passkey. Accounts without one yet can still use their password until they set one up.<\/p><\/dd>\n<dt id=\"is%20woocommerce%20supported%3F\"><h3>Is WooCommerce supported?<\/h3><\/dt>\n<dd><p>Yes. Device management appears under <strong>My Account<\/strong>, and biometric login can appear on WooCommerce login forms when enabled.<\/p><\/dd>\n<dt id=\"password%20managers%20block%20the%20biometric%20prompt.%20what%20should%20i%20do%3F\"><h3>Password managers block the biometric prompt. What should I do?<\/h3><\/dt>\n<dd><p>Extensions such as 1Password, Bitwarden, or LastPass may intercept passkey prompts. Enable passkey support in the manager or disable autofill for your site so the native OS dialog (Touch ID, Face ID, Windows Hello) can appear.<\/p><\/dd>\n<dt id=\"can%20administrators%20manage%20user%20devices%3F\"><h3>Can administrators manage user devices?<\/h3><\/dt>\n<dd><p>Yes. Use <strong>Biometric Login \u2192 User Management<\/strong> to reset devices, view logs, and register passkeys on behalf of users (with appropriate capability checks). To remove every registered device for every user in one action, use the \"Reset All Devices for All Users\" button in the Security Settings tab's Danger Zone: it requires typing a confirmation phrase and is logged to the Security Logs.<\/p><\/dd>\n<dt id=\"what%20shortcodes%20does%20this%20plugin%20provide%3F\"><h3>What shortcodes does this plugin provide?<\/h3><\/dt>\n<dd><p><strong><code>[csbisebi_device_manager]<\/code><\/strong>: Renders the full \"Manage Biometric Devices\" panel: registered device list, add\/rename\/remove controls, and a registration form. Only visible to logged-in users; logged-out visitors see a \"Please log in\" notice instead. The plugin auto-creates a page containing this shortcode on activation.<\/p>\n\n<p><strong><code>[csbisebi_login_button]<\/code><\/strong>: Renders only a \"Login with Biometrics\" trigger button, safe to place inside a normal page, a widget, or a page-builder popup (e.g. Elementor). It prints nothing at all for a visitor who is already logged in. What happens on click is controlled by <strong>Biometric Login \u2192 Implementation \u2192 Popup Behavior<\/strong>:<\/p>\n\n<ul>\n<li><strong>Show the sign-in popup<\/strong> (default): opens a popup with the biometric prompt plus optional password\/register buttons.<\/li>\n<li><strong>Authenticate directly<\/strong>: skips the popup and triggers the biometric prompt immediately.<\/li>\n<\/ul><\/dd>\n<dt id=\"what%20filter%20hooks%20does%20this%20plugin%20provide%20for%20developers%3F\"><h3>What filter hooks does this plugin provide for developers?<\/h3><\/dt>\n<dd><p>All filters below can be added to your theme's <code>functions.php<\/code> or a site-specific plugin.<\/p>\n\n<p><strong><code>csbisebi_button_text<\/code><\/strong>: Change the biometric login button's text everywhere it appears (login screen, <code>[csbisebi_login_button]<\/code> shortcode, WooCommerce account button), overriding the \"Button Text\" UI setting.<\/p>\n\n<pre><code>add_filter( 'csbisebi_button_text', function ( $text ) {\n    return 'Sign in with Face ID';\n} );\n<\/code><\/pre>\n\n<p><strong><code>csbisebi_popup_header_icon<\/code><\/strong>: Replace the fingerprint icon shown in the sign-in popup's header. Return raw HTML\/SVG markup; return an empty string (the default) to keep the built-in, theme-colored fingerprint icon.<\/p>\n\n<pre><code>add_filter( 'csbisebi_popup_header_icon', function ( $icon_html ) {\n    return '&lt;img src=\"https:\/\/example.com\/my-icon.svg\" width=\"32\" height=\"32\" alt=\"\" \/&gt;';\n} );\n<\/code><\/pre>\n\n<p><strong><code>csbisebi_popup_heading_title<\/code><\/strong>: Change the heading title in the sign-in popup's header (defaults to the site name).<\/p>\n\n<pre><code>add_filter( 'csbisebi_popup_heading_title', function ( $title ) {\n    return 'Welcome back!';\n} );\n<\/code><\/pre>\n\n<p><strong><code>csbisebi_popup_guest_notice<\/code><\/strong>: Change the helper text shown under the popup header about guest\/private browsing windows.<\/p>\n\n<pre><code>add_filter( 'csbisebi_popup_guest_notice', function ( $text ) {\n    return 'Using a private window? You may need your phone or a security key instead.';\n} );\n<\/code><\/pre>\n\n<p><strong><code>csbisebi_popup_footer_text<\/code><\/strong>: Change the privacy note shown at the bottom of the sign-in popup (next to the green checkmark icon).<\/p>\n\n<pre><code>add_filter( 'csbisebi_popup_footer_text', function ( $text ) {\n    return 'Your biometric data stays on your device.';\n} );\n<\/code><\/pre>\n\n<p><strong><code>csbisebi_force_biometric_enabled<\/code><\/strong>: Override whether \"Force Biometric Login\" is enforced, independent of the saved setting. Return <code>false<\/code> to force it off (e.g. from a must-use plugin or an emergency break-glass hook) without touching the database.<\/p>\n\n<pre><code>add_filter( 'csbisebi_force_biometric_enabled', function ( $enabled ) {\n    return false;\n} );\n<\/code><\/pre>\n\n<p><strong><code>csbisebi_plugin_name<\/code><\/strong>: Change the plugin's display name shown in menus, headings, and the WooCommerce account tab.<\/p>\n\n<pre><code>add_filter( 'csbisebi_plugin_name', function ( $name ) {\n    return 'ABCD Passkey Login';\n} );\n<\/code><\/pre><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Added a \"Restrict Roles\" switch, replacing the old Allowed Roles list, enforced at both passkey registration and login.<\/li>\n<li>Added a working \"Force Biometric Login\" setting that blocks password login for accounts with a registered passkey, exempting accounts that have not registered one yet, plus a <code>csbisebi_force_biometric_enabled<\/code> filter for developers.<\/li>\n<li>Added \"Require Re-Authentication\" enforcement for adding and removing a device, confirmed with your account password.<\/li>\n<li>Added the <code>[csbisebi_login_button]<\/code> shortcode, a login button safe to use inside Elementor popups and other page builders, replacing the old custom CSS selector setting. It now prints nothing for a visitor who is already logged in.<\/li>\n<li>Added a \"Popup Behavior\" setting (Implementation tab) so the <code>[csbisebi_login_button]<\/code> shortcode can either open the sign-in popup (default) or authenticate directly on click.<\/li>\n<li>Added \"Show 'Use Password Instead' Button\" and \"Show 'Register a New Account' Button\" toggles (UI Settings tab) to hide either option from the sign-in popup.<\/li>\n<li>Removed the \"Show Icon on Button\" setting: it had no effect. Added the <code>csbisebi_button_text<\/code> filter for developers who want to override the button label in code instead.<\/li>\n<li>Removed the \"Hide Button on Unsupported Browsers\" setting: it had no effect. Unsupported browsers now log a console warning instead.<\/li>\n<li>Added <code>csbisebi_popup_header_icon<\/code>, <code>csbisebi_popup_heading_title<\/code>, <code>csbisebi_popup_guest_notice<\/code>, and <code>csbisebi_popup_footer_text<\/code> filters to let developers override the sign-in popup's header icon, heading, guest-window notice, and footer text.<\/li>\n<li>Documented all shortcodes and developer filter hooks in the FAQ.<\/li>\n<li>Renamed the Security Settings tab's URL slug from <code>tab=advanced<\/code> to <code>tab=security-settings<\/code>.<\/li>\n<li>Added a \"Danger Zone\" section on the Security Settings tab with a \"Reset All Devices for All Users\" action (admin-only, phrase-confirmed), which removes every registered biometric device site-wide and records a <code>global_reset<\/code> entry in the security logs.<\/li>\n<li>Added Role and Last Activity columns to the User Management table, sourced from the security logs.<\/li>\n<li>Added a dismissible WordPress.org review notice on the settings page.<\/li>\n<li>Fixed the device name entered during registration not being used as the passkey's name in the browser or OS passkey picker.<\/li>\n<li>Renamed \"Advanced Settings\" to \"Security Settings\" and moved related settings into it.<\/li>\n<li>Redesigned the settings screens with toggle switches and CS BioLogin brand colors.<\/li>\n<li>Removed unused legacy settings, Allow Password Fallback and Allow REST Account Registration, that had no effect.<\/li>\n<li>General code cleanup for WordPress and VIP coding standards.<\/li>\n<\/ul>\n\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Moved security log storage from option table to custom table <\/li>\n<li>Filter\/search logs logs<\/li>\n<li>Fixed the issue where logs was not showing correct browser.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Fixed the minor issue where activating the plugin triggered, fatal error.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Fixed the issue where, the registration working when ZOHO vault is enabled<\/li>\n<li>Added i18n support in js files for translation<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release on the WordPress Plugin Directory.<\/li>\n<li>WebAuthn \/ FIDO2 \/ Passkeys registration and authentication (ES256 and RS256).<\/li>\n<li>Passwordless login on the WordPress login screen with optional password fallback.<\/li>\n<li>WooCommerce: My Account endpoint, checkout and account login popups, and device management UI.<\/li>\n<li>Multi-device support with rename, update passkey, remove, and duplicate-device handling.<\/li>\n<li>Admin settings (roles, force biometric, rate limits, lockout, UI options) plus security event logs and user device management.<\/li>\n<li>Passkey setup reminder banner for users without a registered device.<\/li>\n<li>No external services or CDNs; credentials stored locally in the database.<\/li>\n<\/ul>","raw_excerpt":"Secure biometric login (WebAuthn \/ FIDO2 \/ Passkeys) for WordPress and WooCommerce using Face ID, Touch ID, or fingerprint.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/315026","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=315026"}],"author":[{"embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/concatstring"}],"wp:attachment":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=315026"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=315026"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=315026"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=315026"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=315026"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=315026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}