HMDIA Login & Registration Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
HMDIA Login & Registration provides a configurable authentication experience while keeping WordPress users and authentication APIs underneath.
Free/Core highlights:
- Login, Registration, Password Reset and Account pages
- Email & Password login and registration
- Registration verification with None, Email Code or Magic Link
- Built-in honeypot spam protection
- Google reCAPTCHA v3 and Cloudflare Turnstile integration
- Password policy and code-delivery controls
- Redirect and page setup controls
- Server-side Account and selected-page access control
- Email design/customization engine
- Setup Wizard
- WooCommerce authentication-surface support
- Diagnostics, privacy integration and WP-CLI recovery/status tools
- Extension/module APIs for add-ons
- Contact Form with configurable fields, submissions and emails
HMDIA Login & Registration Pro is a separate optional add-on that supplies advanced authentication/security modules such as 2FA/passkeys, Temporary Login Access, advanced sessions, role redirects and other premium services. HMDIA Traffic & IP Security owns Sign-in Activity UI, storage, retention and reporting. The Free/Core plugin works without these add-ons and does not contain the Pro license/update client.
External services
The local honeypot needs no external account. CAPTCHA services are optional: the administrator chooses a provider, supplies its keys, and selects the forms where it runs. The selected vendor’s browser script is loaded only for that configured service. Test-connection actions also contact the selected provider. When enabled in Traffic & IP Security, suspicious sign-in checks also use that provider, including on sign-in forms whose normal CAPTCHA toggle is off.
Google reCAPTCHA v3
Purpose: assess spam/automation on enabled authentication and contact forms. The browser contacts Google when the configured widget runs, exposing its IP address and browser/request information to Google. On submission, WordPress sends the service secret key, challenge-response token, and visitor IP to Google’s Siteverify API. Account passwords and registration-document contents are not included in this API request.
Service: https://www.google.com/recaptcha/about/
Verification documentation: https://developers.google.com/recaptcha/docs/verify
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy
Cloudflare Turnstile
Purpose: validate human interactions on enabled forms. The browser contacts challenges.cloudflare.com for the configured widget; Cloudflare receives the browser’s IP address and browser/request information. On submission, WordPress sends the widget secret key, challenge token, and visitor IP to the Turnstile Siteverify API. Account passwords and registration-document contents are not included.
Service and verification documentation: https://developers.cloudflare.com/turnstile/
Terms: https://www.cloudflare.com/website-terms/
Privacy: https://www.cloudflare.com/privacypolicy/
Turnstile privacy addendum: https://www.cloudflare.com/turnstile-privacy-policy/
Twilio SMS through the optional Pro add-on
The free plugin contains the shared phone helpers and transport interface. The separately installed Pro add-on supplies Twilio delivery. After an administrator configures Twilio and enables an SMS method, the add-on sends the recipient number, configured sender, security-code message, and account credentials to api.twilio.com over HTTPS. The connection test sends account credentials to check the account without sending an SMS. SMS delivery may incur Twilio charges.
Service/API: https://www.twilio.com/docs/messaging/api/message-resource
Terms: https://www.twilio.com/en-us/legal/tos
Privacy: https://www.twilio.com/en-us/legal/privacy
Administrator-supplied media
If an administrator configures an externally hosted logo or background image, the viewer’s browser or email client requests that chosen URL. Use locally hosted images when external image requests are not wanted. Core does not send licensing or telemetry requests to HMDIA.
Security and upgrade notes
From 2.0.63, Forms CSS and Account CSS editors are removed and their saved CSS is no longer applied. Before updating a site that uses either field, copy the rules to WordPress’s Additional CSS and check the form and account appearance. Historical values remain in the saved plugin option for recovery. Built-in design controls continue to work.
Core 2.0.73 supports Registration Pro 2.0.23 during the upgrade to Pro 2.0.24. For installations already using Core 2.0.67+ and the previous compatible add-ons (Pro 2.0.23, Traffic & IP Security 1.0.36, Post Submission 0.3.15, Support 1.0.7), update Core first, then Pro, then the other add-ons. The new add-on releases require Core 2.0.73+. Older integrations must first reach those compatible baseline versions. Saved settings, shortcodes, request actions, nonce purposes, cookies and CSS selectors remain supported. Core does not define deprecated code aliases; it can read the previous Pro provider interfaces during sequential updates.
For a new installation without older HMDIA plugins, install Core first, then add the current optional integrations.
Trusted proxies are configured in Tools > Diagnostics and shared with Traffic & IP Security. Direct connections ignore forwarded IP headers. Select Cloudflare only for a direct Cloudflare peer; list all trusted intermediaries for custom X-Forwarded-For chains. Existing Traffic & IP Security proxy choices are preserved. Check the detected visitor IP on the actual hosting configuration before reopening registration.
Registration documents are encrypted with AES-256-GCM and available only to their owner and administrators through an authenticated download endpoint. Post Submission listing media remains public. Encryption requires working OpenSSL. Keep the WordPress authentication salts with backups: changing them prevents decryption of existing documents and secrets.
Existing public registration documents are not silently moved during activation. Use Tools > Diagnostics > Private registration documents to review and migrate them. The migration verifies encrypted original/thumbnail copies, retains attachment IDs and account associations, then removes the corresponding public local files. Failed cleanup remains visible for retry. Purge the previous public URLs from any external CDN, cache, or offload storage separately; copies already downloaded cannot be revoked.
Compatibility
Core 2.0.73 supports Registration Pro 2.0.23 during the upgrade to Pro 2.0.24. For installations already using Core 2.0.67+ and the previous compatible add-ons (Pro 2.0.23, Traffic & IP Security 1.0.36, Post Submission 0.3.15, Support 1.0.7), update Core first, then Pro, then the other add-ons. The new add-on releases require Core 2.0.73+. Older integrations must first reach those compatible baseline versions. Saved settings, shortcodes, request actions, nonce purposes, cookies and CSS selectors remain supported. Core does not define deprecated code aliases; it can read the previous Pro provider interfaces during sequential updates.
Source code
The editable JavaScript and CSS source files are included in assets/js/ and assets/css/. The plugin loads these files directly; no compilation, bundling, or minification step is required. PHP source is included in the plugin folder and includes/.
The bundled Lucide SVG subset is pinned to version 0.468.0, revision f12b0de177fbc2a6795e99be065887e72b237123: https://github.com/lucide-icons/lucide/tree/0.468.0/icons. The 32 original SVG sources, source notes, and ISC license (including Feather attribution) are in assets/vendor/lucide/. The static PHP allowlist is in includes/class-sav-account-icons.php. No Lucide JavaScript package or build step is used.
Compatibility
Existing page content that still contains [sav_login], [sav_register], [sav_reset_password] or [sav_account] is translated to the corresponding current HMDIA shortcode before page rendering. New integrations should use [hmdia_registration_login], [hmdia_registration_register], [hmdia_registration_reset_password] and [hmdia_registration_account].
The compatibility module retains historical API aliases, admin routes, selectors and pending-request formats for installed integrations. New Core registrations use HMDIA names. Existing inbox tables remain in place to preserve submissions; new installations use the HMDIA table name. HMDIA Pro 2.0.21 also recognizes the current account shortcode names during security setup.
Screenshots
No screenshots provided

