WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Joel James v3.2.0

Loggedin

WordPress session manager — limit concurrent user logins, stop account sharing, force logout active sessions, and manage every signed-in device.

Loggedin

The facts

Rating
4.9★ from 111
Active installs
8k+
Price
Free
Last updated
29 Aug 2026
Added
Jul 2016
Requires WP
6.0
Tested up to
WP 7.1
Requires PHP
7.4
Downloads
159,415

Our analysis

AI-assisted

Loggedin is a WordPress plugin designed for managing user login sessions. It allows you to set limits on the number of concurrent sessions a user can have, helping to prevent account sharing on membership sites, online courses, and other platforms where user access needs to be controlled.

The plugin integrates with WordPress's authentication system and provides options to log out the oldest session, log out all other sessions, or block new logins when the session limit is reached. It is suitable for various types of sites, including membership platforms, online learning environments, and corporate intranets.

Best for: This plugin is best for membership sites, online courses, and any platform needing to manage user login sessions effectively.

What it does well

  • Controls the number of concurrent user sessions
  • Integrates with WordPress's standard authentication pipeline
  • Offers three modes for handling session limits
  • Includes a one-click Force Logout feature
  • Compatible with various session storage solutions

Where it falls short

  • No additional features beyond session management are mentioned

Verdict

Loggedin provides a straightforward solution for managing user sessions in WordPress, making it a useful tool for sites that require strict access control.

From the developer

Joel James's own description of Loggedin, lightly tidied.

Loggedin is a session manager for WordPress — it gives you control over the login sessions your users hold, and the tools to end them when you need to.

At its core, Loggedin caps the number of simultaneous WordPress sessions a user account is allowed to hold. When the cap is reached, you choose what happens next — log out the oldest device, log out every other device, or block the new login outright. It’s the lightweight, no-bloat way to stop account sharing on membership sites, LMS courses, paid communities, and any WordPress install where one paid account shouldn’t be open on five devices at once.

The plugin hooks straight into WordPress’s standard authentication pipeline and uses the native WP_Session_Tokens API, so it works on every host, with every theme, and alongside every login plugin you might already run. No cron jobs, no background polling, no third-party services.

How it works

A “session” in WordPress is the authenticated token created the moment a user logs in — one per browser, per device. Two browsers on the same laptop count as two sessions; a phone and a desktop count as two. Closing a tab does not end a session — the token lives server-side until the user explicitly signs out or another login displaces it.

Loggedin watches every login attempt:

  1. Counts the user’s current active sessions.
  2. Compares that count to the limit you’ve configured.
  3. Applies the rule you’ve picked — silently make room for the new login, or reject the new login with an error on wp-login.

There’s a one-click Force Logout panel in the admin to clear every session for a specific user when someone’s locked out by the cap and can’t reach their other devices. Identify the user by ID, email, or username — all three work.

Who it’s for

  • Membership sites — MemberPress, Paid Memberships Pro, Restrict Content Pro, WooCommerce Memberships, etc. Stop one paid account from being shared across a household, a classroom, or a Discord server.
  • Online courses & LMS — LearnDash, LifterLMS, TutorLMS, Sensei. Make sure the seat someone paid for is actually used by that someone.
  • Subscription stores — WooCommerce Subscriptions, Easy Digital Downloads recurring. Keep subscriber counts honest.
  • Corporate intranets & client portals — Enforce a one-device-at-a-time policy for staff or client accounts.
  • BuddyPress / BuddyBoss communities — Reduce ban-evasion and duplicate-account abuse.
  • Compliance-driven sites — Healthcare, finance, education installs where audit policy requires a per-account session cap.

Features

  • Session management from the dashboard — Inspect and end user sessions from Users → Loggedin, or from WP-CLI. Add the Active Sessions add-on for a live, sortable view of every signed-in user and device.
  • Global concurrent-login limit — Pick any number from 1 upwards as the per-user cap.
  • Three built-in modes — Logout Oldest (kick the user’s oldest device, keep the rest), Logout All (the new login becomes the only active session), or Block New (reject the login and show an error on wp-login).
  • Admin Force Logout — Type a user ID, email, or username and clear every active session for that user in one click.
  • Works with any session storage — Uses the standard WP_Session_Tokens API. Stock WordPress, Redis, Memcached — all supported (the Logout Oldest mode needs the default user-meta storage; the other modes work everywhere).
  • Customizable error message — Override the message shown when a login is blocked, via a single filter.
  • WP-CLI support — Inspect and destroy user sessions and read or write settings from the command line: wp loggedin sessions list <user>, wp loggedin sessions destroy <user>, wp loggedin settings set maximum 3. Ideal for bulk operations, deploy scripts and headless installs.
  • Built for developers — Every decision passes through documented PHP hooks and filters. Override the cap per user / role / capability, exempt service accounts, audit force-logouts, or splice the plugin into your own auth pipeline. Full hook reference in the developer docs.
  • Lightweight — No cron, no background polling, no remote calls. The whole plugin runs at the moment a login happens.
  • Translation-ready — Loaded with the WordPress i18n APIs; contribute translations on WordPress.org.

📦 Add-ons

Extend Loggedin with these official add-ons:

  • Active Sessions — See exactly who’s signed in right now, drill into each device per user, and sign out a single session — or every session — in one click.
  • Limit Per User — Override the global session cap for an individual user account directly from their WordPress profile. Perfect for tiered access or trusted-staff exemptions.
  • Limit Per Role — Set a different concurrent-session cap per WordPress role. Give administrators more headroom while keeping subscribers tight, or vice versa.
  • Real-time Logout — Detect logouts in near-real-time. When Loggedin terminates a session, the user’s other open tabs reload to wp-login automatically — no waiting for the next page click.

📚 Documentation

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for membership sites.

Members

Members

94

The best WordPress membership and user role editor plugin. User Roles &amp; Capabilities editor helps you rest...

Free 300k+ installs 4.9★ (1,274)
User Registration & Membership

Build membership sites with tiered plans, content restriction, drag-&amp;-drop custom registration &amp; login...

Free 50k+ installs 4.8★ (828)
Ultimate Member

Membership &amp; community plugin with user profiles, registration &amp; login, member directories, content re...

Free 200k+ installs 4.4★ (1,444)
Simple Membership

Simple membership plugin adds membership functionality to your site. Protect members only content using conten...

Free 40k+ installs 4.6★ (475)
wpForo Forum

Number one WordPress forum plugin with AI features. Full-fledged forum solution with modern forum design. Comm...

Free 20k+ installs 4.7★ (390)