WPIntell

jwt-auth

JWT Auth – WordPress JSON Web Token Authentication

Create JSON Web Token Authentication in WordPress.

6.0K
112.2K
5.0
0
20
15

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

95 / 107 rows with source links

88.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

12 rows with no attached evidence

0 rows have source counts but still need direct links.

Download Momentum

180 days
774 814 -4.9% 10.1K

Source Evidence

Open evidence explorer
complaint support · high severity · relevance 0.85
Website down due to change in plugin’s PHP version requirements

Website down due to change in plugin’s PHP version requirements: users show bugs, compatibility pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
Investigate Pain card complete trust and abuse-prevention operations Evidence linked to opportunity
Website down due to change in plugin’s PHP version requirements Hi, After updating this morning to v2.1.6, our client’s website (hosted on PHP 7.3) was down with the following error: PHP Fatal error: Composer detected issues in your platform: Your Composer dependencies require a PHP version ">= 7.4.0".
mixed support · high severity · relevance 0.83
Special character support

Special character support: users show security, bugs, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
Investigate Pain card complete trust and abuse-prevention operations Evidence linked to opportunity
Special character support A password such as ,;:./?+-_*!ӣ$%^&() works via wordpress login, but fails with JWT Auth.
complaint support · medium severity · relevance 0.88
Token give my a statusCode 500 back

Token give my a statusCode 500 back: users show bugs, compatibility, performance pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
Investigate Pain card complete trust and abuse-prevention operations Evidence linked to opportunity
Token give my a statusCode 500 back After setup the plugin I got this error message { “success”: false , “statusCode”: 500, “code”: “jwt_auth_bad_config”, “message”: “JWT is not configured properly.”, “data”: [] } my .htacess looks like php_value memory_limit 256M php_value max_input_vars 10000 RewriteEngine On RewriteCond %{HTTP:Authorization} ^(.
complaint support · medium severity · relevance 0.87
Translation domain jwt-auth loaded to early (WordPress 6.7.0)

Translation domain jwt-auth loaded to early (WordPress 6.7.0): users show bugs, compatibility, missing feature pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
Investigate Pain card complete trust and abuse-prevention operations Evidence linked to opportunity
Translation domain jwt-auth loaded to early (WordPress 6.7.0) Hi team, Since updating to WordPress core version 6.7.0, I keep getting the following notice when using the plugin: Notice: Function _load_textdomain_just_in_time was called incorrectly.
complaint support · medium severity · relevance 0.87
Conflict with AI Engine

Conflict with AI Engine: users show bugs, compatibility, missing feature pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
Investigate Pain card complete trust and abuse-prevention operations Evidence linked to opportunity
Conflict with AI Engine Hello!
mixed support · medium severity · relevance 0.84
ATTENTION: Version 3.0.2 Released!

ATTENTION: Version 3.0.2 Released!: users show bugs, compatibility, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
Investigate Pain card complete trust and abuse-prevention operations Evidence linked to opportunity
Please check the section titled “Upgrading to v3” on the plugin page before raising new issues: https://wordpress.org/plugins/jwt-auth/ Please note that version 3.0.2 has been released with some major changes.
complaint support · medium severity · relevance 0.81
Having a issue while using endpoints

Having a issue while using endpoints: users show bugs, support, setup pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
Investigate Pain card complete trust and abuse-prevention operations Evidence linked to opportunity
Having a issue while using endpoints Hi, I hope you are doing well.
complaint support · medium severity · relevance 0.81
Plugin Conflict with Elementor 3.8.1

Plugin Conflict with Elementor 3.8.1: users show bugs, compatibility, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
Investigate Pain card complete trust and abuse-prevention operations Evidence linked to opportunity
Plugin Conflict with Elementor 3.8.1 Recent update to Elementor 3.8.1 has caused a conflict with JWT Auth 2.1.3, that is preventing any updates via elementor.
complaint support · medium severity · relevance 0.81
JWT installed – API endpoints still open to public

JWT installed – API endpoints still open to public: users show bugs, compatibility, setup pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
Investigate Pain card complete trust and abuse-prevention operations Evidence linked to opportunity
JWT installed – API endpoints still open to public Plugin installed: JWT Auth – WordPress JSON Web Token Authentication WordPress – 6.11 PHP -7.4.22 we can generate a AUTH Token to the REST api /wp-json/jwt-auth/v1/token | POST and do a API call using POSTMAN JWT Authorisation Bearer | Token this all works!
complaint support · medium severity · relevance 0.81
Cannot modify header information – headers already sent…

Cannot modify header information – headers already sent…: users show compatibility, missing feature, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
Investigate Pain card complete trust and abuse-prevention operations Evidence linked to opportunity
Cannot modify header information – headers already sent… Cannot modify header information – headers already sent by (output started at /var/www/doortodoor/2023/wp-includes/script-loader.php:2838) in /var/www/doortodoor/2023/wp-content/plugins/jwt-auth/class-auth.php on line 98 I looked up the function and it applies to adding CORS support.

Competitor Context

1 shown
WP Login and Register using JWT praise owner · intel 43.2 · weakness 19.4
praise owner
1 collected complaint signal(s) bugs support 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test login lockouts, bot/spam defenses, risky access changes, and incident alerts

Repeated Themes

0 shown

No repeated plugin-level themes have been generated yet.

Collected Signals

20 shown from 52 collected
mixed Device list missing when login requests send JSON bodies support · 2025-11-24T16:36:04+00:00 · medium severity · json web token

JWT Auth does not record connected devices when login requests send JSON bodies, forcing the user to maintain a brittle workaround.

Evidence: when the body is JSON, no device entry is stored and the “Connected Devices” section stays empty.
compatibility missing feature quality json device tracking API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
question How to remove backend notice for the upgrade? support · 2025-04-29T09:56:36+00:00 · low severity · json web token

How to remove backend notice for the upgrade?: users show migration pain that may indicate a product gap.

Evidence: Ok this was one solution I applied, for whoever is interested in hiding it too: add_action('admin_notices', function() { echo '<style> .notice.notice-warning[data-dismissible="jwt-v3-update-warning-1"] { display: none !important; } </style>'; }, 999); Ok this was one solution I applied, for whoever is interested in hiding it too: add_action('admin_notices',
migration import API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Translation domain jwt-auth loaded to early (WordPress 6.7.0) support · 2025-04-04T12:06:15+00:00 · medium severity · json web token

Translation domain jwt-auth loaded to early (WordPress 6.7.0): users show bugs, compatibility, missing feature pain that may indicate a product gap.

Evidence: Translation domain jwt-auth loaded to early (WordPress 6.7.0) Hi team, Since updating to WordPress core version 6.7.0, I keep getting the following notice when using the plugin: Notice: Function _load_textdomain_just_in_time was called incorrectly.
bugs compatibility missing feature setup API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
neutral Log in Flow – User Credentials, Refresh Token, Access Token support · 2025-03-13T15:32:07+00:00 · medium severity · json web token

Log in Flow – User Credentials, Refresh Token, Access Token: neutral conversation with limited structured signal.

Evidence: Log in Flow – User Credentials, Refresh Token, Access Token Hi, I want to secure API access from an app.
api API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Token give my a statusCode 500 back support · 2024-07-23T18:45:36+00:00 · medium severity · json web token

Token give my a statusCode 500 back: users show bugs, compatibility, performance pain that may indicate a product gap.

Evidence: Token give my a statusCode 500 back After setup the plugin I got this error message { “success”: false , “statusCode”: 500, “code”: “jwt_auth_bad_config”, “message”: “JWT is not configured properly.”, “data”: [] } my .htacess looks like php_value memory_limit 256M php_value max_input_vars 10000 RewriteEngine On RewriteCond %{HTTP:Authorization} ^(.
bugs compatibility performance missing feature API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Generate token and refresh token using user ID support · 2024-07-20T23:40:23+00:00 · medium severity · json web token

Generate token and refresh token using user ID: users show support pain that may indicate a product gap.

Evidence: I’m trying to implement a custom login method and I need to generate token and refresh token using user ID.
support login API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
question Distinguishing between an expired token and invalidated Token support · 2024-06-17T21:05:03+00:00 · medium severity · json web token

Distinguishing between an expired token and invalidated Token: question conversation with limited structured signal.

Evidence: Distinguishing between an expired token and invalidated Token Hi, I was wondering is it possible on a token refresh to determine if a user has been deleted? The scenario I was thinking of is if a user was actively logged in and getting valid token refreshes, but then their account has been deleted – can the token validation or endpoint refresh endpoint detec
API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Continuously getting “Refresh token is obsolete” while generating a new token support · 2024-06-13T06:59:01+00:00 · medium severity · json web token

Continuously getting “Refresh token is obsolete” while generating a new token: users show bugs, support pain that may indicate a product gap.

Evidence: Continuously getting “Refresh token is obsolete” while generating a new token Hello @dominic I have set the token expiration time to two days.
bugs support easy reliable API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Getting error rest_no_route support · 2024-05-20T12:09:00+00:00 · medium severity · json web token

Getting error rest_no_route: users show bugs, support pain that may indicate a product gap.

Evidence: Getting error rest_no_route I am trying to login autheticate and creating token but i am getting error “rest_no_route”.
bugs support login API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed ATTENTION: Version 3.0.2 Released! support · 2024-05-07T21:17:57+00:00 · medium severity · json web token

ATTENTION: Version 3.0.2 Released!: users show bugs, compatibility, support pain that may indicate a product gap.

Evidence: Please check the section titled “Upgrading to v3” on the plugin page before raising new issues: https://wordpress.org/plugins/jwt-auth/ Please note that version 3.0.2 has been released with some major changes.
bugs compatibility support setup API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Conflict with AutomateWoo support · 2024-03-13T18:52:45+00:00 · medium severity · json web token

Conflict with AutomateWoo: users show compatibility pain that may indicate a product gap.

Evidence: Conflict with AutomateWoo There seems to be a conflict between JWT Auth and AutomateWoo.
compatibility API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint nginx support · 2024-02-28T10:42:57+00:00 · medium severity · json web token

nginx: users show setup pain that may indicate a product gap.

Evidence: nginx How to configure this plugin on nginx server?
setup API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
praise It simply works! (5 stars) review · 2024-01-31T16:37:41+00:00 · medium severity · json web token

It simply works!: users praise reliable, which suggests what competitors already do well.

Evidence: It simply works!
reliable API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
neutral Quotation character in password results in failed login support · 2023-12-22T12:31:42+00:00 · medium severity · json web token

Quotation character in password results in failed login: neutral conversation with limited structured signal.

Evidence: Quotation character in password results in failed login If a password contains a quotation mark it will pass when logging in via the webpage but fails with JWT.
login API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Website down due to change in plugin’s PHP version requirements support · 2023-11-06T14:20:32+00:00 · high severity · json web token

Website down due to change in plugin’s PHP version requirements: users show bugs, compatibility pain that may indicate a product gap.

Evidence: Website down due to change in plugin’s PHP version requirements Hi, After updating this morning to v2.1.6, our client’s website (hosted on PHP 7.3) was down with the following error: PHP Fatal error: Composer detected issues in your platform: Your Composer dependencies require a PHP version ">= 7.4.0".
bugs compatibility form API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Having a issue while using endpoints support · 2023-10-23T13:47:39+00:00 · medium severity · json web token

Having a issue while using endpoints: users show bugs, support, setup pain that may indicate a product gap.

Evidence: Having a issue while using endpoints Hi, I hope you are doing well.
bugs support setup login API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Cannot modify header information – headers already sent… support · 2023-10-22T15:23:42+00:00 · medium severity · json web token

Cannot modify header information – headers already sent…: users show compatibility, missing feature, support pain that may indicate a product gap.

Evidence: Cannot modify header information – headers already sent… Cannot modify header information – headers already sent by (output started at /var/www/doortodoor/2023/wp-includes/script-loader.php:2838) in /var/www/doortodoor/2023/wp-content/plugins/jwt-auth/class-auth.php on line 98 I looked up the function and it applies to adding CORS support.
compatibility missing feature support API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Javascript conflict when saving widgets support · 2023-09-26T17:23:48+00:00 · medium severity · json web token

Javascript conflict when saving widgets: users show bugs, compatibility pain that may indicate a product gap.

Evidence: Javascript conflict when saving widgets The plugins are conflicting when saving the widgets, with WordPress returning the following error: ‘An error has occurred.
bugs compatibility API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Good Work (5 stars) review · 2023-09-13T00:10:00+00:00 · medium severity · json web token

Good Work: users praise easy, which suggests what competitors already do well.

Evidence: Good Work The simplest and most useful plugin The simplest and most useful plugin
easy API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint JWT upgrade to -php 8 & 8+ support · 2023-09-07T23:44:45+00:00 · medium severity · json web token

JWT upgrade to -php 8 & 8+: users show compatibility pain that may indicate a product gap.

Evidence: JWT upgrade to -php 8 & 8+ JWT upgrade to -php 8 & 8+ as having conflict with elementor .
compatibility elementor API and integration reliability operations Investigate Pain card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test jwt lockouts, bot/spam defenses, risky access changes, and incident alerts