EgyDevInfo Sign In With Google Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Most “Sign in with Google” setups fail in the Google Cloud console, not in WordPress: a redirect URI pasted slightly wrong, an app left in “Testing” mode so real visitors are blocked, or a site moved to a new domain and login silently breaking. This plugin is built around fixing that.
A setup page that walks you through Google Cloud
- Step-by-step instructions with direct links to the right Google Cloud pages.
- The exact redirect URI and authorized domain for your site, each with a copy button.
- Warnings for the common traps: publishing the app so it is not stuck in “Testing”, and why not to upload a logo (it triggers a brand verification review).
- A Run test sign-in button that performs a real Google sign-in without logging you in, and explains any failure in plain language (wrong Client ID/Secret, redirect URI mismatch, server cannot reach Google).
- If your site address changes (staging copy, new domain, http to https, www change), you get a clear notice with the new redirect URI to add in Google.
A button that keeps working on real sites
- The button is a plain link that runs a server-side sign-in. It needs no JavaScript on your pages and carries no nonce, so full-page caching and JavaScript “delay/defer/combine” optimizers do not break it.
- Works on the WordPress login and registration pages, the WooCommerce My Account login and registration forms, and the WooCommerce checkout for guests — both the classic checkout and the Checkout block.
- A shortcode for anywhere else:
[egydevinfo_siwg_button]. - Light, dark and neutral styles following Google’s sign-in button guidelines. RTL-ready.
Careful account handling
- Accounts are matched on Google’s permanent account ID, not the email address.
- An existing account is linked automatically only when Google is authoritative for the email address (a verified Gmail or Google Workspace address). Anyone else logs in with their password once and clicks “Connect Google account”.
- Administrators, editors and shop managers are never linked automatically unless you allow it.
- ID tokens are checked for signature, issuer, audience, expiry and a one-time nonce; the sign-in uses a one-time state value bound to the visitor’s browser, plus PKCE.
- New accounts follow your site’s registration settings (or your choice), and new users only ever get a role without back-end editing powers (Customer with WooCommerce).
- Optional: restrict sign-in to your company’s Google Workspace domain.
- Users can connect and disconnect Google from their profile or the WooCommerce “Account details” page.
External services
This plugin connects to Google’s sign-in service (Google Identity / OAuth 2.0) so visitors can sign in with their Google account. Nothing is sent to Google until a visitor clicks the button (or an administrator runs the test sign-in).
- When the button is clicked, the visitor’s browser is sent to
accounts.google.comwith your Client ID, the redirect URI, and one-time security values. - After the visitor approves, your server sends the one-time authorization code, your Client ID and Client Secret to
oauth2.googleapis.comand receives the visitor’s Google account ID, name and email address. - Your server downloads Google’s public signing keys from
www.googleapis.comto verify the response (cached).
Google Terms of Service: https://policies.google.com/terms
Google Privacy Policy: https://policies.google.com/privacy
Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy
Privacy
The plugin stores the visitor’s Google account ID and email address as user meta so they can sign in again. It uses their name and email address to create an account when allowed. It does not store Google access tokens and never receives the visitor’s Google password. It adds suggested text to your site’s privacy policy guide. Uninstalling removes the stored Google links; user accounts are kept.





