FAQ
Common questions, clear answers.
Find practical answers about Custom Auth Suite™ setup, Auth Pages, CAS Doctor, protection features, Passkeys, licenses, privacy-safe messages and support.
Start here
Product, plans and first decisions
Use these answers to understand what CAS is, where to start and how the three editions differ.
What is Custom Auth Suite™?
Custom Auth Suite™ is a WordPress authentication layer. It helps organize login, registration, password recovery, email verification, protected paths, guided setup and diagnostic support. It is not a full membership plugin, a shop system or a complete user-management platform.
Is the Free version a trial?
No. All features available in the Free versions remain available without an expiry date. Advanced and Premium features require the corresponding commercial package and an active license.
Which edition should I choose?
Start with Free if you need branded authentication, Auth Pages and CAS Doctor. Choose Advanced for Polylang/i18n, reCAPTCHA Enterprise, Contact Form 7 Math Check, asset customization and settings import/export. Choose Premium when you need WebAuthn / Passkeys, device intelligence and advanced debug/log export tools.
CAS vs other plugins
2FA, security, membership and where CAS fits
CAS overlaps with some login, security and account features, but its main target is different: a cleaner authentication experience for WordPress.
Is CAS a 2FA plugin?
CAS is not positioned as a pure 2FA method pack. Some CAS features touch the same area, such as Passkeys, protected authentication flows and anti-bot protection, but the core purpose is broader: CAS organizes the WordPress authentication experience, including Auth Pages, guided setup, route consistency, diagnostics, support-ready reports and commercial license-aware features.
How is CAS different from WP 2FA, miniOrange or classic login security plugins?
Plugins focused on 2FA or MFA usually compete on authentication methods, role policies, OTP options, trusted devices, enforcement rules and compliance-oriented access control. CAS should not be evaluated only by the number of 2FA methods it offers. CAS is designed as an authentication experience layer: branded login and registration flows, password recovery consistency, CAS Doctor, support handoff, protected paths, privacy-aware admin guidance, commercial package licensing and, in Premium, passwordless capabilities.
Does CAS replace a firewall or a complete security suite?
No. CAS does not replace a firewall, malware scanner, server hardening tool or complete security suite. CAS focuses on authentication flows, protected access, user-facing login experience, selected anti-bot protections and diagnostics connected to the CAS setup. You can still use a dedicated security plugin or WAF when your site needs broader protection.
Is CAS a membership plugin?
No. CAS is not a membership monetization platform. It does not try to replace systems built for subscriptions, paid content, member directories, course access or complex content restriction. CAS can protect paths and improve authentication, but if your primary need is selling memberships or managing paid content, you may still need a dedicated membership plugin.
Can I use CAS together with another 2FA or security plugin?
Often yes, but avoid overlapping the same responsibility twice. For example, if another plugin already forces 2FA, CAS should not be configured to fight the same login step. Keep one owner for each critical layer: firewall/security, 2FA/MFA, CAS Auth Pages, CAS Doctor, cache exclusions and support diagnostics. Always test login, password recovery and protected paths after enabling multiple security tools.
Auth Pages
Login, registration, password recovery and navigation
CAS keeps the authentication flow clean, but still leaves the site owner in control of pages and slugs.
Why does CAS create Auth Pages?
CAS can create or reconnect the required WordPress pages for login, registration, lost password and reset confirmation. This reduces setup errors because each page needs the correct CAS template and route.
Why are Register and Lost Password hidden from automatic menus?
CAS keeps navigation minimal. The Login page can remain visible, while registration and password recovery stay reachable from the authentication flow. This avoids filling the public menu with technical pages.
Can I use custom slugs for Auth Pages?
Yes. You can use custom paths in Routes & Templates. If a page slug changes later and CAS detects a mismatch, use Fix Now to return to CAS defaults or update the path manually to keep your custom slug.
How does CAS work with Polylang?
CAS can work with translated Auth Pages. The language switcher must remain visible even when technical Auth Pages are hidden from normal navigation. Advanced and Premium packages allow more evolved language-aware mapping.
Is the landing page after direct login required?
No. It is recommended, but not mandatory. If it is empty, CAS can use the homepage as fallback. When the user was trying to access a protected page, CAS still respects that protected destination after login.
CAS Doctor
Guided checks, reports and recovery
The Doctor is designed to guide, not to alarm. It helps before support is needed.
What does CAS Doctor do?
CAS Doctor checks the CAS environment, summarizes readiness, highlights route/cache/support context and helps prepare a cleaner diagnostic report. It is focused on CAS-specific setup and support readiness, not generic WordPress optimization.
Does the Doctor modify my website?
No. The Doctor reads the current state, shows guidance and can generate reports. It does not silently change your configuration.
Does the Doctor Report include secrets?
The Doctor Report is designed to be redacted. It should not include passwords, full license keys, raw tokens, cookies, nonces, private keys or authorization headers. It is meant to provide useful context without exposing sensitive data.
What is Safe Mode?
Safe Mode is a recovery layer. When active, CAS bypasses custom CAS redirects and lets the native WordPress login flow be used for recovery. Protected paths are not exposed: non-logged users are sent to wp-login.php with a redirect_to destination.
What should I exclude from page cache?
Exclude CAS login, registration, password recovery, reset confirmation and protected paths from public page cache. Also be careful with aggressive JS optimization when using reCAPTCHA, Passkeys or CAS popups.
Email and users
Verification, templates and delivery
CAS can brand and guide email flows, while delivery still depends on the site’s email stack.
What is email verification used for?
Email verification confirms that the registered address belongs to the user. CAS can manage verification, resend flows and welcome messages according to the configured templates.
Why are CAS emails not arriving?
CAS prepares the message, but delivery depends on WordPress and the configured SMTP/provider. Check your mail plugin, provider logs, OAuth connection, sender reputation and whether transactional emails are allowed by the hosting environment.
Can I customize CAS emails?
Yes. CAS includes email customization for core messages, with subject/body templates, preview/test tools, variables and language-aware content where configured.
Protection
reCAPTCHA Enterprise, Math Check and protected paths
Advanced protection is useful when authentication becomes a stable and important part of the website.
Who configures Google reCAPTCHA Enterprise?
The site owner configures the Google Cloud / reCAPTCHA Enterprise project and keys. CAS can use the configured keys to protect selected flows, but it does not create the Google project, activate billing or issue Google keys.
How do I enable Math Check for Contact Form 7?
Use the CAS Math Check tag inside the Contact Form 7 form: [cas_math* cas_math]. If Contact Form 7 is not active, CAS keeps the feature safely inactive.
What are Protected Paths?
Protected Paths are URL paths that should only be available after authentication. CAS checks access and redirects non-logged users to the configured login flow without making the protected content public.
Passkeys
WebAuthn, devices and browser credentials
Premium adds modern passwordless authentication while keeping biometric data on the user device.
Does CAS store biometric data?
No. With WebAuthn / Passkeys, biometric or device-unlock data stays with the operating system, browser, password manager or security key. CAS stores technical credential information needed to verify authentication, not fingerprints or faces.
Why can one browser not find a passkey created in another browser?
The passkey lives in the credential manager used during creation, such as Google Password Manager, iCloud Keychain, the browser, the OS or a security key. If a browser cannot find it, sign in with password, disable the passkey for that device only, then enable it again from the same browser.
What are the requirements for Passkeys?
Passkeys require the Premium package, an effective Premium license, HTTPS and a compatible PHP/runtime environment. RP ID and Origin should match the real domain served by WordPress.
Licenses and packages
Commercial access, domains, downloads and updates
CAS separates what is installed, what is licensed and what can actually run.
Why do package, license and effective plan matter?
The installed package defines which code is physically present. The license defines the commercial entitlement. The effective runtime plan is the safe intersection between package, license and technical requirements.
Can one license cover multiple domains?
Domain coverage depends on the purchased plan and any extra-domain add-ons. A license can record a primary domain and additional covered domains when allowed by policy.
Do downloads and updates use Custom Auth Suite™ services?
Commercial package delivery and future update checks can communicate with Custom Auth Suite™ services to verify license status, connected domain, package, version and eligibility. Temporary download or update tokens may be used when delivery is available.
Messages, privacy and support
Remote admin messages, analytics, logs and tickets
CAS keeps administrative guidance separate from optional interaction analytics.
What are Remote Admin Messages?
Remote Admin Messages are safe JSON content payloads shown inside selected CAS admin areas. They can include compatibility notes, support reminders, tutorials, renewal notices or product guidance. CAS does not execute arbitrary remote JavaScript or arbitrary remote HTML for these cards.
Are interaction analytics enabled by default?
No. Remote admin messages and interaction analytics are separate. Messages can be delivered as useful administrative content, while privacy-safe interaction analytics such as impressions, CTA clicks and dismissals should be opt-in.
Why should I attach the Doctor Report when asking for support?
The report gives support a cleaner starting point: routes, environment, cache guidance, recent changes and redacted diagnostics. This reduces back-and-forth questions and helps avoid generic “it does not work” tickets.
Does an active license always include active technical support?
No. Product access and technical support coverage are related but separate. Technical tickets may require an active support entitlement, a support extension, a one-shot intervention or manual review depending on the case.
Where are CAS logs stored?
When available, CAS operational logs are stored under wp-content/uploads/cas-logs/. They can be exported from the CAS backend for troubleshooting. Logs are separate from the Doctor Report and should not contain secrets.
Need more context?
Start from the product page, then open the Doctor when CAS is installed.