UnlockForge helps WordPress site owners protect posts and pages and control how visitors access protected content.
Version 0.1.0 provides social-login-based content unlocking, configurable protection modes, preview controls, Unlock Messages, bulk protection, and analytics.
The plugin separates authentication from content access, providing a foundation for additional access methods in future versions.
Protect WordPress posts and pages using three protection modes:
Preview content can be configured by:
Preview settings can be configured globally, with per-content overrides where supported.
Visitors can unlock protected content using supported social-login providers.
Supported providers:
OAuth credentials are configured from the WordPress admin settings.
UnlockForge establishes the visitor’s external identity and associates it with a WordPress user account.
Multiple external identities can be associated with the same WordPress user.
Create customized messages shown when visitors encounter protected content.
Unlock Messages support:
The plugin automatically selects the applicable Unlock Message for protected content based on its configured categories and schedule.
If no matching Unlock Message exists, the normal content protection flow is used.
The Analytics dashboard provides visibility into content unlocking and social-login activity.
Available analytics include:
Analytics can be viewed using:
Analytics timestamps are handled using the WordPress site timezone for date-range selection.
Apply protection settings to multiple existing posts or pages.
Bulk protection supports:
Bulk operations process content in batches to avoid unnecessarily large requests.
UnlockForge maintains external identity information separately from WordPress user accounts.
This allows a WordPress user to have multiple supported social-login identities while keeping authentication identity data separate from content access decisions.
A simplified protected-content flow:
Authentication and content access are separate concepts in the plugin architecture, allowing future access methods to be added without coupling them directly to authentication.
After activation, open:
**Settings UnlockForge **
The plugin provides settings for:
To use social login:
Keep OAuth client secrets private and do not expose them in client-side code.
Unlock Messages can be targeted to WordPress categories and scheduled for specific periods.
A message can include:
When multiple messages match the same content, UnlockForge uses the applicable message based on its scheduling and matching rules.
Bulk Protection allows administrators to apply protection settings to existing content.
You can select:
Bulk operations are processed in batches and display their progress while running.
Existing protection settings may be overwritten when applying a bulk operation.
Analytics provides aggregated information about authentication and content-unlock activity.
Analytics events include:
Login failures are grouped by failure reason to help administrators identify problems with the authentication flow.
If an OAuth callback does not work after configuring a provider, visit:
Settings Permalinks
and click Save Changes to refresh WordPress rewrite rules.
When testing social login:
UnlockForge may store information required to establish and associate external social-login identities with WordPress user accounts.
The information stored depends on the social-login provider and the configuration of the site.
Site administrators are responsible for configuring their site and privacy policies appropriately for the data collected through enabled authentication providers.
UnlockForge uses third-party OAuth services when a site administrator enables the corresponding social-login provider. These services are used to authenticate visitors and retrieve the identity information required to create or associate an external identity with a WordPress user.
No external service is contacted for social login when its provider is disabled.
UnlockForge uses Google OAuth to authenticate users and retrieve basic account information required for authentication and identity association.
Data sent to Google:
* OAuth authorization requests.
* OAuth authorization code during the authentication flow.
Data received from Google may include:
* Google account identifier.
* Name.
* Email address.
* Profile information made available through the configured Google OAuth scopes.
Google is contacted when a visitor chooses Google as their login provider.
Terms of Service: https://policies.google.com/terms
Privacy Policy: https://policies.google.com/privacy
UnlockForge uses Facebook Login to authenticate users and retrieve account information required for authentication and identity association.
Data sent to Facebook:
* OAuth authorization requests.
* OAuth authorization code during the authentication flow.
Data received from Facebook may include:
* Facebook user identifier.
* Name.
* Email address.
* Profile information made available through the configured permissions.
Facebook is contacted when a visitor chooses Facebook as their login provider.
Terms of Service: https://www.facebook.com/legal/terms
Privacy Policy: https://www.facebook.com/privacy/policy
UnlockForge uses LinkedIn OAuth to authenticate users and retrieve account information required for authentication and identity association.
Data sent to LinkedIn:
* OAuth authorization requests.
* OAuth authorization code during the authentication flow.
Data received from LinkedIn may include:
* LinkedIn member identifier.
* Name.
* Email address.
* Profile information made available through the configured scopes.
LinkedIn is contacted when a visitor chooses LinkedIn as their login provider.
Terms of Service: https://www.linkedin.com/legal/user-agreement
Privacy Policy: https://www.linkedin.com/legal/privacy-policy
UnlockForge uses X OAuth to authenticate users and retrieve account information required for authentication and identity association.
Data sent to X:
* OAuth authorization requests.
* OAuth authorization code during the authentication flow.
Data received from X may include:
* X user identifier.
* Name.
* Username.
* Email address when available through the configured access permissions.
X is contacted when a visitor chooses X as their login provider.
Terms of Service: https://x.com/en/tos
Privacy Policy: https://x.com/en/privacy
UnlockForge uses GitHub OAuth to authenticate users and retrieve account information required for authentication and identity association.
Data sent to GitHub:
* OAuth authorization requests.
* OAuth authorization code during the authentication flow.
Data received from GitHub may include:
* GitHub user identifier.
* Name.
* Username.
* Email address.
GitHub is contacted when a visitor chooses GitHub as their login provider.
Terms of Service: https://docs.github.com/en/site-policy/github-terms/github-terms-of-service
Privacy Statement: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
UnlockForge uses WordPress security mechanisms including:
OAuth client secrets should never be exposed publicly.
Payment-based content unlocking is planned for a future version.
Future development may include:
Payment functionality is intentionally not included in V1.
UnlockForge is being developed as an open-source WordPress plugin.
If you find the project useful, consider supporting its development by contributing feedback, reporting issues, or starring the project on GitHub.