Select one or more tags, then press “Search Plugins”

Find Plugin with any / all of the selected criteria
Search Plugin

Fliegerlogin – SSO For Vereinsflieger Wordpress Plugin - Rating, Reviews, Demo & Download

Fliegerlogin – SSO For Vereinsflieger Preview Wordpress Plugin - Rating, Reviews, Demo & Download
No ratings yet
Free
Follow for free plugins, new theme releases and theme news

Plugin Description

This plugin allows users to login with their existing account on Vereinsflieger.de.

Included in this edition

Everything below is part of this download and stays free. Nothing here is a trial, and nothing switches itself off.

  • Login using your Vereinsflieger.de account
  • No extra registration for your members needed
  • Works with enabled 2 factor authentication
  • Keeps your wordpress account up to date (name, email, …)
  • Prevents disabled users from Vereinsflieger.de to login
  • Protects the Vereinsflieger API quota with IP-based rate limiting: configure the threshold, the lockout duration and whether it covers every WordPress login, and unblock addresses again from the Security page
  • Shows how much of the daily Vereinsflieger request quota is left
  • Supports local custom translations that are not overwritten by WordPress.org language packs

To get this plugin to work you have to request an app key from the Vereinsflieger.de support. You also need to know your club’s CID which you can find in the administration area of your Vereinsfieger.de account.

What Fliegerlogin Premium adds

The free edition blocks a single address that guesses passwords. That covers the everyday case and it is the case most clubs ever see.

It does not cover an attack spread across hundreds of addresses, where no single one reaches the threshold. A club in that situation needs to look at the traffic as a whole rather than at one visitor at a time, and it needs a record of what happened. Fliegerlogin Premium is a separate download that adds:

  • A protection overview with a status badge for every safeguard, active failure counters and the most recent rate limit events, all on one page
  • A circuit breaker that pauses all Vereinsflieger calls when the overall traffic spikes or the daily quota runs out — distributed attacks from many addresses never reach a per-address limit
  • Geo blocking by country, with detection via Cloudflare, web server variables, the PHP geoip extension or a MaxMind database, plus automatic GeoLite2 database updates
  • A negative cache so repeated wrong credentials fail instantly instead of spending API requests
  • Guards that skip the Vereinsflieger lookup entirely for XML-RPC requests, for implausible usernames and for attempts a captcha plugin has already rejected
  • Username enumeration protection for ?author=N, author archives, the REST users endpoint and the author sitemap, plus uniform login error messages
  • A debug log covering the whole authentication flow, with viewer, filters and automatic redaction of passwords and tokens

Premium is licensed under the GPLv3 as well: pricing and purchase. Questions about it are welcome in the support forum on this page.

Disclaimer: Vereinsflieger.de was not involved in the development, neither ordered the development of this plugin.

External Services

This plugin connects to two external services.

Vereinsflieger.de — the whole point of the plugin. On every login attempt the entered username and a hash of the password are sent to the Vereinsflieger API at https://www.vereinsflieger.de/interface/rest/ to verify the credentials and read the member’s name, email address and status. Nothing is transmitted unless someone attempts to log in. Terms: https://www.vereinsflieger.de/agb/ — Privacy policy: https://www.vereinsflieger.de/datenschutz/

Freemius — licensing and update handling for the paid edition, and the upgrade prompts in this one. It contacts https://api.freemius.com only after you explicitly opt in, and it never transmits your members’ data. If you skip the opt-in, the plugin sends nothing to Freemius; only anonymous update checks remain. Terms: https://freemius.com/terms/ — Privacy policy: https://freemius.com/privacy/

Credits and License

Fliegerlogin is free software licensed under the GNU General Public License version 3 or later. The full license text is included in the LICENSE file.

Copyright (C) 2020-2022 Diginize (https://www.diginize.de)
Copyright (C) 2025-2026 Simon Kuhn

This plugin is a modified version of the “WP Vereinsflieger” plugin originally developed and published by Diginize (https://github.com/diginize/wp-vereinsflieger), whose last release was version 1.1.2 in May 2022. It has been maintained and substantially extended by Simon Kuhn since 2025; every change is documented in the changelog below.

Screenshots

  1. The configuration page: enter your club's CID and the app key you requested from Vereinsflieger support, pick the role new members receive, and see how much of today's API quota is left.

    The configuration page: enter your club’s CID and the app key you requested from Vereinsflieger support, pick the role new members receive, and see how much of today’s API quota is left.

  2. The security page: decide how many rejected logins from one address trigger a block, how long it lasts, and whether it covers every WordPress login. Blocked addresses are listed here and can be released again.

    The security page: decide how many rejected logins from one address trigger a block, how long it lasts, and whether it covers every WordPress login. Blocked addresses are listed here and can be released again.

  3. Members with two factor authentication enabled are prompted for their one time password, on the normal WordPress login screen.

    Members with two factor authentication enabled are prompted for their one time password, on the normal WordPress login screen.

  4. By default an address is locked out for fifteen minutes after five rejected Vereinsflieger logins, so brute force attacks cannot exhaust the club's daily request quota.

    By default an address is locked out for fifteen minutes after five rejected Vereinsflieger logins, so brute force attacks cannot exhaust the club’s daily request quota.

  5. Password resets are turned off for accounts managed via Vereinsflieger, so a member cannot lock themselves out by changing a password WordPress does not own.

    Password resets are turned off for accounts managed via Vereinsflieger, so a member cannot lock themselves out by changing a password WordPress does not own.


Reviews & Comments