Beryl Admin Gate

Beryl Admin Gate

Details
View on WordPress

Beryl Admin Gate connects a site to the Beryl Studio WP Admin Gate service. The service supplies user authorization, an authenticated proxy, short-lived signed access assertions and known-vulnerability matching. It is a substantive external service, not a license-validation server.

An account and the companion Chrome extension are required for proxy access. The service is currently available as a free beta; future paid subscriptions require separate agreement. Current availability and pricing: https://auth.beryl-studio.jp/. The plugin contains no subscription checkout, time-limited local functionality, remote PHP/JavaScript loader or private signing key. Local configuration checks and optional XML-RPC authentication control work without a service account.

Activation starts in connection-check mode (access restrictions OFF). Registration alone does not enable restrictions. After confirming a connection through the Chrome extension, an administrator can explicitly enable protection. WordPress’s own login is still required. Normal updates preserve the selected protection state; explicit reactivation/reinstallation resets restrictions to OFF while retaining pairing information.

This plugin limits access to administrative routes, including authenticated AJAX and REST requests. Public pages and unauthenticated AJAX remain available. Compatibility with membership plugins, front-end logged-in functionality, external editors, backup tools and other authentication plugins must be tested before enabling protection. It does not guarantee prevention of intrusion, scan all files, patch vulnerabilities or back up the site.

External services and data

The service provider is Beryl Studio. Service: https://auth.beryl-studio.jp/
Terms: https://auth.beryl-studio.jp/terms/
Privacy policy: https://auth.beryl-studio.jp/privacy-policy/
Setup: https://auth.beryl-studio.jp/gate-setup/
Support: https://beryl-susukino.jp/design/

No WP Admin Gate service request is made merely by activating the plugin. An administrator starts pairing with a registration code and explicitly confirms the external-service disclosure in Settings > WP Admin Gate.

  • Site registration: sends the one-time registration code, a random challenge and Cloudflare-use flag to https://auth.beryl-studio.jp/wp-json/wp-admin-gate/v1/site/register. The service verifies site ownership by retrieving the challenge proof and the WordPress login URL from this site’s temporary proof endpoint. Pairing stores the site’s domain, service public verification key and approved proxy/Cloudflare addresses locally.
  • Extension download: only after an administrator requests it, sends the site domain, random challenge and temporary proof key to https://auth.beryl-studio.jp/wp-json/wp-admin-gate/v1/extension-ticket. The service verifies site registration and returns a short-lived download URL. The plugin redirects to this URL; it never installs or executes extension code in WordPress. The administrator separately installs the companion extension in Chrome.
  • Automated vulnerability matching: after pairing, the service normally requests this site’s inventory daily through signed, expiring, replay-protected HTTPS requests. Responses contain the domain and WordPress/plugin/theme software type, slug, display name, version and active status. The service may request the protection mode and sends vulnerability findings back for local display. This endpoint does not return file contents, WordPress passwords, user lists or the local diagnostic report.
  • Vulnerability intelligence: the service retrieves Wordfence Intelligence data and matches inventory on its VPS. The customer plugin does not call Wordfence or contain a Wordfence API key. Information and attribution are displayed with the findings. Provider: https://www.wordfence.com/threat-intel/ ; terms: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/ ; privacy: https://www.wordfence.com/privacy-policy/ . Unpublished or unlisted issues cannot be detected.
  • Proxy traffic: when the companion extension connects, selected site administration traffic passes through the service VPS. This is separate from the inventory endpoint. The service necessarily processes connection metadata and forwarded requests; consult the service privacy policy before enabling it.
  • Manual local diagnostic: only when an administrator clicks the diagnostic button, WordPress’s own update functions contact api.wordpress.org for core/plugin/theme update checks. The plugin also performs up to five unauthenticated HTTPS GET requests to its own site to inspect public responses. Standard WordPress update requests may include software inventory and site/server details. WordPress.org privacy: https://wordpress.org/about/privacy/ . Results remain on this WordPress site.

Local records and removal

The plugin records login success/failure (submitted username and time) and update events locally, retaining the latest 100 events. These are visible to administrators in the security report and are not included in the service inventory. Stored pairing, settings and reports remain when the plugin is deactivated. Removing the plugin through WordPress deletes its options and temporary challenges from that installation. Deletion does not cancel a service contract or remove the service-side site record; manage those separately in the service account.

Requirements

PHP 8.1 or later with OpenSSL and mbstring; HTTPS and working WordPress REST API for pairing. A single WordPress installation/site is supported; multisite network activation is not supported in this release. Test Cloudflare/WAF rules, custom login URLs and other security plugins before enabling access restrictions.

Details

Plugin code:
beryl-admin-gate
Plugin version:
0.6.1
Outdated:
No
WP version:
6.0 or higher
PHP version:
8.1 or higher
Test up to WP version:
7.1.3
Total installations:
0
Last updated:
2026-10-09
Rating:
Times rated:
0
access-control
login
proxy
security