Sign in to any site without a password.

Press Magic Login and KontrolWP opens that site's admin in a new tab with a one-time link that expires after 60 seconds.

For WordPress sites. Needs the KontrolWP Connect plugin.

A short-lived link, not a stored password.

KontrolWP asks the site for a link for the administrator you chose. The site keeps only a hash of it.

  • On by default for each site
  • The link works once and expires after 60 seconds
  • The plugin checks the user is still an administrator when the link is used
  • Logins are recorded in activity logs like any other

The details

How it works, point by point.

Choosing who signs in

  • A site with no chosen administrator uses its first one, the lowest user id
  • Add site asks you to confirm or change it, and the site's menu changes it later

How it stays safe

  • The plugin stores only a SHA-256 hash of the link's token. The first request to use it signs in, and any other gets an error page
  • Signing in goes through WordPress's normal login, so activity logs record it like any login
  • Two-factor plugins that prompt after login (Two Factor and WP 2FA) are told to skip that one sign-in, for that user and request only
  • Password logins still get their two-factor prompt. Plugins that check at the password step, such as Wordfence, never see this sign-in

Where else it appears

  • Edit buttons on the Links tab and the Posts and pages tab use it to open a post's editor directly

Good to know

  • Anyone who can use the dashboard can open a site as an administrator, so keep the dashboard behind Cloudflare Access and share it only with people you trust with that access.

Take control of every WordPress site you run.

Deploy KontrolWP to your Cloudflare account and connect your first site.