Product specifications
What Custom Auth Suite™ does and what it does not do
A clear technical reference for supported flows, compatibility requirements, third-party integrations, remote services, privacy-safe analytics, security responsibilities and service boundaries.
Authentication flows
Custom Auth Suite™ centralizes login, registration, lost password recovery, email verification, protected-path redirects and branded access pages into one coherent WordPress layer.
Minimum environment
Designed for modern WordPress installations running a supported PHP version, HTTPS, pretty permalinks and standard WordPress mail delivery through a reliable SMTP/provider setup.
Shared security model
CAS improves authentication UX and control, but it does not replace secure hosting, backups, patching, DNS/email configuration, server hardening or administrative responsibility.
Minimum compatibility
Required baseline
Custom Auth Suite™ is built for professional WordPress environments. The following baseline should be considered the minimum expected configuration before installation or support review.
WordPress
- Modern, maintained WordPress installation.
- Pretty permalinks enabled, not plain permalink mode.
- Standard WordPress hooks, login flow and user system available.
- No aggressive security plugin blocking core REST/admin-post behavior without exceptions.
PHP and server
- Supported PHP runtime suitable for the active WordPress version.
- HTTPS enabled on production domains.
- Reliable filesystem permissions for plugin assets and logs where enabled.
- Stable outbound HTTP requests for license checks, update/package metadata, support flows and remote administrative messages.
- Cache, CDN, firewall and security tools should not block WordPress REST, admin-post, AJAX or plugin update flows without explicit exceptions.
Email delivery
- Transactional email delivery must be configured by the site owner.
- SMTP/provider alignment is recommended for verification and password recovery emails.
- CAS can generate and style emails, but cannot guarantee inbox placement by itself.
Browser and UX
- Modern browsers with JavaScript enabled for enhanced flows.
- Responsive layouts for desktop, tablet and mobile access pages.
- Accessibility-conscious markup and labels where CAS controls the UI.
Yes, this part is boring. Do not worry: Custom Auth Suite™ includes CAS Doctor, a safe and non-aggressive environment check that helps you understand your setup after installation and guides you through the most useful information. You can also start with Custom Auth Suite™ Free, try the plugin, review the comparison matrix and get familiar with Custom Auth Suite™ at your own pace.
Simple. Necessary. Like water.
Supported integrations
Forms, anti-bot and multilingual compatibility
CAS is designed to coexist with selected WordPress plugins and third-party services. These integrations may require their own configuration, accounts, keys or licensing.
| Area | Supported / expected | Important notes |
|---|---|---|
| Form plugin | Contact Form 7 forms with CAS Match Check / anti-spam field support where configured. | CAS can add an additional validation layer, but form logic, notifications and form-specific settings remain controlled by the form plugin/site owner. |
| reCAPTCHA Enterprise | Google reCAPTCHA Enterprise keys configured by the site owner. | CAS supports the Enterprise integration only. CAS does not create a Google Cloud project, does not activate billing and does not issue reCAPTCHA Enterprise keys. The owner must configure the service and paste the required keys/settings into CAS. |
| Multilingual | Polylang-aware routes, labels and language-specific pages where configured. | Translations, page mapping and language switcher behavior depend on the WordPress/Polylang setup and on the configured CAS routes. |
| Remote Admin Messages | Custom Auth Suite™ can receive safe JSON administrative messages such as compatibility notes, license/support reminders, tutorials, product guidance and privacy/cookie notes. | Remote Admin Messages are not analytics. No remote JavaScript and no arbitrary remote HTML are executed. Delivery can be paused service-side or hidden temporarily when a dashboard message appears. |
| Privacy-safe Interaction Analytics | Optional interaction events such as impressions, dismissals and CTA clicks may be shared only if the administrator explicitly opts in. | Analytics are disabled by default. When enabled, collected data is anonymous, aggregated and global: it does not track the website where Custom Auth Suite™ is installed and is not required to receive Remote Admin Messages. |
Edition boundaries
Feature availability depends on the installed package and active license
Some capabilities are edition-specific. The installed package, license status, connected domain, remote entitlement response and server-side package policy determine what is available at runtime. Package installed, license, entitlement and runtime plan are related but separate concepts.
Free
Designed for basic branded authentication flows, setup guidance, email verification, protected paths, CAS Doctor checks and privacy-safe remote administrative messages. Commercial license delivery, advanced protections, passkeys/WebAuthn and premium access layers are not included in the public WordPress.org Free plugin package.
Advanced
Adds commercial licensing context and extended professional features where enabled by the active license, connected domain, package build and server-side entitlement policy.
Premium
Designed for the full premium access layer, including higher-tier authentication capabilities, passkey/WebAuthn-related features and advanced entitlement-gated tools where available.
Responsibility disclaimer
What CAS does not replace
Custom Auth Suite™ is best understood as a WordPress authentication experience layer. It improves login, registration, recovery, protected access, diagnostics and support readiness, but it is not meant to replace every security, membership, compliance or infrastructure tool around a website.
| Area | What CAS does | Best for | What CAS does not replace |
|---|---|---|---|
| Authentication UX | Organizes branded login, registration, password recovery, email verification, protected-path redirects and cleaner access pages. | WordPress sites that need a more coherent and professional authentication flow. | A page builder, a complete user-management platform or a membership monetization system. |
| Login protection and anti-bot | Adds selected protection layers such as Protected Paths, Contact Form 7 Math Check support and reCAPTCHA Enterprise integration where configured. | Sites where authentication and public forms need extra friction against spam, bots and broken access flows. | A full firewall, malware scanner, WAF, server hardening service or dedicated MFA-only product. |
| Passkeys and passwordless access | Premium capabilities may add WebAuthn / Passkeys and device-aware authentication features where package, license and environment allow it. | Sites that want a modern passwordless experience connected to the WordPress account layer. | An enterprise identity provider, SSO platform, corporate IAM suite or universal MFA method marketplace. |
| CAS Doctor and diagnostics | Checks CAS-specific setup, routes, cache-sensitive flows, environment context and support-report readiness. | Site owners and support teams that need faster context before opening or handling a technical request. | A complete server monitor, performance audit platform, uptime monitor or generic WordPress health scanner. |
| License and package services | Commercial CAS packages can use license checks, connected-domain policy, package metadata, support status and protected delivery services. | Customers using Advanced or Premium packages and commercial support/update flows. | WooCommerce checkout, tax calculation, payment processing, accounting or customer relationship management. |
| Privacy-aware admin guidance | Remote Admin Messages can deliver safe JSON administrative notices, product guidance, compatibility notes and support reminders. Optional interaction analytics are separate and opt-in. | Administrators who want contextual guidance without arbitrary remote JavaScript or arbitrary remote HTML. | A legal compliance platform, cookie consent manager, ad network, tracking platform or analytics suite. |
Not a hosting security service
CAS does not replace secure hosting, malware scanning, server hardening, firewall policies, backup strategy, DNS configuration, uptime monitoring or emergency incident response.
Not a pure 2FA / MFA method pack
CAS may include passwordless and protection-related features, but it is not positioned as a standalone 2FA/MFA catalogue. If the primary requirement is the largest possible number of OTP channels, authenticator methods, YubiKey-style policies, enterprise enforcement rules or compliance-only 2FA flows, a dedicated MFA plugin may still be appropriate.
Not a membership or paid-content platform
CAS can protect paths and improve authentication, but it does not replace subscription billing, paid-content restriction, course access, member directories, community features or advanced membership workflows.
Not a legal/privacy compliance tool
CAS can support authentication flows, remote administrative notices and privacy-oriented technical guidance, but legal bases, privacy notices, cookie disclosures, consent requirements and data-processing obligations remain the responsibility of the site owner.
CAS may provide technical notes and descriptive copy that can be adapted for a privacy/cookie policy, but it does not replace legal advice, privacy drafting, cookie disclosure, consent requirements or data-processing obligations. Remote Admin Messages are JSON-only administrative/product messages and are separate from Privacy-safe Interaction Analytics, which are optional, disabled by default and based on anonymous aggregated global interaction events. Final compliance decisions remain the responsibility of the site owner. See also the Custom Auth Suite™ privacy and cookie notes.
Not an account provider for third-party services
External services such as Google reCAPTCHA Enterprise, SMTP providers, WooCommerce payment gateways, multilingual plugins, hosting panels, DNS services and external identity providers must be configured and maintained by the customer or site administrator.
Not an enterprise IAM / SSO platform
CAS is designed for WordPress authentication experience, account flow quality and CAS ecosystem support readiness. It does not replace enterprise IAM, SAML/OIDC SSO, directory federation, corporate device management or organization-wide access governance.
Third-party marks and services. WordPress, WooCommerce, Polylang, Contact Form 7, Google and reCAPTCHA Enterprise are trademarks, product names or services of their respective owners. Custom Auth Suite™ is not affiliated with, endorsed by or sponsored by those third-party owners unless explicitly stated. Integrations are provided for compatibility and operational convenience.
reCAPTCHA Enterprise note. CAS supports Google reCAPTCHA Enterprise only. To use this feature, the site owner must activate and configure Google reCAPTCHA Enterprise, obtain the required keys and comply with Google’s applicable terms, privacy requirements and branding/disclosure rules. CAS does not create, manage or bill the Google Cloud/reCAPTCHA Enterprise service on behalf of the customer.
Remote services and analytics note. Custom Auth Suite™ may contact Custom Auth Suite™ services for license checks, support status, package/update metadata and Remote Admin Messages. Remote Admin Messages are safe JSON administrative/product messages and do not require interaction analytics. Privacy-safe Interaction Analytics, when explicitly enabled by the administrator, are anonymous, aggregated and global and are used only to understand message relevance and interaction patterns.