With a password
- Username, email or mobile number with a password
- Remember me, with the session length in days
- Your own login address, with wp-login.php hidden
- The login screen styled from the same settings
Everything a user does, before and after they log in.
Registration, login by password, one-time code or passkey, mobile and email verification, the profile they edit, the dashboard they land on, and the WooCommerce account pages they buy from. One plugin, one settings panel and one set of templates, so the user journey stops being five plugins arguing with each other.
Built by Pigment Dev, where I am a co-founder and lead developer. The core is free under the GPL; paid plans for teams and agencies are planned on top of it.
Profile
Orders
Read through wc_get_orders(), the same with HPOS on or off.
Security
Recent sign-ins
What is behind that screen
// why
A new plugin, a new team at Pigment Dev, and years of learning exactly where profile plugins break.
Before
I built a profile plugin on my own, Ultimate Profile Solutions: a private release in 2019, and on WordPress.org since 2021. It came with a support inbox, and the inbox was an education. One-time codes failing on an unreliable SMS route. A store that needed a national ID field on registration, but only for one role. A client who wanted vendors to land somewhere different from customers. A checkout that had to read the same field the profile writes.
Every one of those requests was answered. Most of them by bolting something onto a structure designed in 2019 for a much smaller idea of what the plugin should do. After enough years, the shape of a codebase decides what you are allowed to build next.
Years of support tickets were a specification: which flows real stores need, and where the old assumptions hurt.
Changing the internals of a plugin that live sites depend on, under their feet, was not an option. So in June 2026 the work moved to a new plugin at Pigment Dev, with its own name, settings and tables. It migrates the old settings once, and it can run side by side with Ultimate Profile Solutions, which is still maintained for the sites that use it.
Since then it has been reworked release by release: a rebuilt settings panel, international mobile numbers, a template kit, a setup wizard, content restriction, privacy tools, and a test suite that runs in CI.
// sign-in
Turn on the methods your audience actually uses, in any combination, from one screen.
A popup, an inline form, a block or a shortcode, all from one configuration, so the popup in the header and the form at checkout cannot drift apart.
// profiles
A dashboard, not a wall of inputs. What a section shows, and who sees it, are settings rather than code.
Rename, re-icon or switch off the built-in sections, and add your own. A section can hold shortcodes, so anything on the site can live inside the profile.
CSS and JavaScript for each section, kept out of the rest of the page.
Show a section by role, or by access to a LearnDash course.
Text, number, email, mobile, select, multiple choice, rich text and WooCommerce fields, and your own through a hook.
Material, Glass, Neo-Brutalism and more, each covering login, registration, reset, one-time code and the whole dashboard, right to left, from 390px up.
Searchable, with a role filter. Members opt in or out, and a card never shows an email or phone number.
An access box on posts and pages: signed-in users, roles, or a verified mobile, email or national ID, enforced on the page, the REST API and feeds.
A ticketing module inside the dashboard, so support lives where the customer already is.
// woocommerce
The account area is where a customer comes back to. It should not feel like a different product from the profile.
Orders, downloads and order stats sit in the profile as sections, styled with everything else.
Compatible with WooCommerce's order storage. Orders are read through wc_get_orders() with paginated counts, so a customer with fifteen orders sees fifteen.
WooCommerce billing fields can be part of registration, so what a customer enters once is there at checkout.
Courses in the dashboard and sections gated by course access, and a Bookly integration for sites that take bookings.
// codes
A one-time code is only as good as the route it takes. Each gateway is its own class, and the ones Iranian stores use ship with the plugin, alongside Twilio.
Gateways included
One country, a list of countries, or any. Iranian numbers keep their stored form, the rest are stored in E.164, and numbers outside Iran can go through a second gateway.
Per-flow limits on sending codes, so a sign-up form cannot be turned into someone else's SMS bill.
When a gateway rejects a message, the user is told and the failure is logged, rather than a code being reported as sent.
Send a test SMS or a test email from the verification screen before any customer has to.
// security
This plugin owns the login form, the password reset and the session. That is the part of a site attackers go for first.
// developers
Everything the settings panel can do, your code can reach, and the tests say when something breaks.
More than 160 actions and filters. Register a captcha provider, alter the registration fields, change how codes are made, or add a profile template.
REST routes for the signed-in user and their notifications. WP-CLI commands to export and import the configuration, and to re-run the migration from the old plugin.
PHPUnit, Playwright end-to-end specs and security regression specs, run in CI on PHP 7.4 to 8.4, including a test that both plugins can be active at once.
Checked against WCAG 2.2 AA: axe reports no violations on any settings screen or setup wizard step.
A new template is a manifest, two HTML views and one stylesheet, with an authoring guide that explains the contract.
The Persian translation covers every string, English ships as its own file, and text an admin types is registered with WPML and Polylang.
// Sign-in and registration pigment_aps_reglogin_get_register_fields pigment_aps_reglogin_make_otp pigment_aps_reglogin_mobile_is_valid // Captcha, verification and templates pigment_aps_captcha_providers pigment_aps_captcha_verify pigment_aps_kyc_verify pigment_aps_profile_templates // WP-CLI wp pigment-aps export <file> wp pigment-aps import <file> wp pigment-aps migrate
// questions
The ones that come up first.
Yes. It grew out of it. I wrote Ultimate Profile Solutions, and the years of support behind it became the brief for this plugin. Since June 2026 it has been its own plugin at Pigment Dev, with its own settings and tables and a one-time migration from the old ones.
Yes, and a coexistence test checks it. Day to day, one sign-in flow per site is simpler, so the usual path is to migrate and then switch the old plugin off.
Yes. It declares compatibility with WooCommerce's order storage and reads orders through wc_get_orders(), so it behaves the same with HPOS on or off.
Kavenegar, SMS.ir, IPPanel, FarazSMS, ParsGreen, API.ir, Twilio and WP SMS ship with it, plus email. Numbers outside Iran can go through a second gateway, such as Twilio.
Every template covers login, registration and the full dashboard in right to left, the Persian translation covers all of the plugin's strings, and English ships as its own file.
Nothing is deleted unless you turn on the setting that removes data on uninstall, which sits in its own Danger Zone under Developer and Tools.
// products/
Plugins, apps and internal systems. Each one is shipped, documented, and still looked after.