Linux 软件免费装
Banner图

Intranet & Private Site - All-In-One Intranet

开发者 lionsher
nathansingh
chrisakelley
dimensionmedia
slaFFik
jaredatch
smub
更新时间 2026年7月31日 20:28
PHP版本: 7.0 及以上
WordPress版本: 7.0
版权: GPL-3.0-or-later
版权网址: 版权信息

标签

multisite restrict access intranet auto logout private site

下载

1.1 1.7 1.2 1.3 1.4 1.5 1.6 1.6.1 1.7.1 1.8.1 1.8.0 1.9.0 1.9.1 1.9.2

详情介绍:

Plenty of companies run their intranet on WordPress. The problem is that WordPress was built for public-facing sites. Making it work as a private intranet typically requires installing multiple plugins, configuring each one separately, and hoping they all play nicely together. All-In-One Intranet solves this by giving you everything you need in a single plugin to turn your WordPress site into a fully private intranet. Enable privacy with one checkbox, set up auto-logout to protect sensitive information, configure where users land after login, and manage multisite access controls - all from one settings page. Corporate intranet, private knowledge base, restricted client portal, internal comms hub: the privacy and access control are the same job in each case, and this plugin does that part. What is an Intranet? An intranet is a private website or network used internally by an organization. Unlike a public website, an intranet is only accessible to authorized users - typically employees, contractors, or specific team members. Common uses for a WordPress intranet include: WordPress already has the editing interface and the user roles for all of these. What it does not have is the access control layer, which is what All-In-One Intranet adds. Features All-In-One Intranet has five features, covering what most intranets need: One-Click Private Site Enable the "Force site to be entirely private" checkbox, and your entire WordPress site becomes restricted to logged-in users only. Anyone who is not logged in gets redirected to the WordPress login page automatically. This single setting handles multiple layers of privacy at once: The plugin also monitors your WordPress registration settings. If "Anyone can register" is enabled on a single site, or if open registration is allowed on a multisite network, the plugin displays a warning on the settings page so you can fix it before it becomes a problem. Auto-Logout for Inactive Users Shared workstations and forgotten browser tabs are a real security risk for intranets. The auto-logout feature lets you set a maximum idle time - in minutes, hours, or days - after which users are automatically logged out. The plugin tracks each user's last activity timestamp. On every page load, it checks whether the configured idle time has been exceeded. If a user has been inactive for too long, they are logged out immediately and redirected back to the page they were viewing, which triggers the login wall if the site is private. This protects sensitive company information without requiring users to remember to log out manually. Set it to 30 minutes for high-security environments, a few hours for typical office use, or leave it blank to disable the feature entirely. Custom Login Redirect By default, WordPress sends users to the dashboard after they log in. For an intranet, this is not useful - your team is logging in to read content, not to manage the site. The login redirect feature lets you set any URL on your site as the post-login landing page. Point it to your company homepage, a news feed, or a team dashboard so users see relevant content right away. This redirect only applies when users log in directly through the standard WordPress login page. If a user tries to access a specific page and gets redirected to log in first, they will be sent back to that page after authentication, not to the custom redirect URL. Multisite Sub-site Privacy If you run a WordPress multisite network, you can require logged-in users to be members of a specific sub-site before they can view it. This is useful for organizations with multiple departments, teams, or client areas - each with their own sub-site that should only be visible to relevant people. When a user who is logged in but not a member of the current sub-site tries to access it, they see a message listing all the sub-sites they do have access to, with clickable links to navigate there. Access to the Network Admin area is never restricted by this setting. This option works in combination with the main privacy setting. Enable private site first, then add sub-site membership requirements for per-site access control across your network. Multisite Default Role Assignment Managing user access across multiple sub-sites in a WordPress network can be tedious. Every time you add a new user or create a new sub-site, you would need to manually assign roles across all the relevant sites. The default role assignment feature automates this. Choose a role (Subscriber, Editor, Administrator, or any custom role), and the plugin handles the rest: That saves a lot of clicking, especially in an organization where new employees and new sites turn up regularly. How to Make Your WordPress Site Private Setting up a private WordPress site with All-In-One Intranet takes about one minute:
  1. Install and activate the plugin from the WordPress plugin directory
  2. Go to Settings > All-In-One Intranet in your WordPress admin (or Network Admin > Settings > All-In-One Intranet for multisite)
  3. Check the box labeled "Force site to be entirely private"
  4. Click Save Changes
That is all it takes. Your site is now private. Any visitor who is not logged in will be redirected to the WordPress login page. The REST API, XML-RPC, and search engine indexing are all locked down automatically. If you see a warning about registration settings after enabling privacy, follow the link in the warning to disable open registration and close the gap. How to Set Up Auto-Logout for Inactive Users The auto-logout feature protects your intranet from unattended browser sessions:
  1. Go to Settings > All-In-One Intranet
  2. Find the Auto Logout section
  3. Enter a number in the time field (e.g., 30)
  4. Select the time unit from the dropdown: Minutes, Hours, or Days
  5. Click Save Changes
Users who are inactive for longer than the configured period will be logged out on their next page interaction. Their activity timer resets on every page load, so active users are never interrupted. To disable auto-logout, clear the time field and save. How to Configure Login Redirect To send users to a specific page after they log in:
  1. Go to Settings > All-In-One Intranet
  2. Find the Login Redirect section
  3. Enter the full URL of your desired landing page (e.g., https://example.com/welcome)
  4. Click Save Changes
Users who log in via /wp-login.php will now land on that page instead of the WordPress dashboard. Users who were redirected to the login page from a specific URL will still return to that URL after logging in. How to Set Up a WordPress Multisite Intranet For organizations running a WordPress multisite network:
  1. Go to Network Admin > Settings > All-In-One Intranet
  2. Enable "Force site to be entirely private" to restrict the entire network to logged-in users
  3. Optionally enable "Require logged-in users to be members of a sub-site to view it" for per-site access control
  4. Under Sub-site Membership, select a default role to automatically assign users to sub-sites
  5. Click Save Changes
The privacy and membership settings apply network-wide. The default role assignment runs automatically when new users or new sub-sites are created. Existing sub-sites and users are not affected retroactively when you change the role setting. Security Features All-In-One Intranet takes a layered approach to access control: Note that media uploads (images, PDFs, etc.) remain accessible to anyone who knows their direct URL. This is a limitation of how WordPress stores media files and is common to most privacy plugins. If you need to protect individual file downloads, consider a dedicated file protection plugin alongside All-In-One Intranet. For Developers All-In-One Intranet provides the aioi_allow_public_access filter for developers who need to make specific pages or endpoints accessible without authentication. This filter runs during both the template redirect check and the REST API dispatch check. Return true to allow public access for the current request: add_filter( 'aioi_allow_public_access', function( $allow ) { // Allow public access to a specific page if ( is_page( 'public-landing' ) ) { return true; } return $allow; } ); This is useful for exposing specific landing pages, webhook endpoints, or custom API routes while keeping the rest of the site private. Two more filters exist for login-screen plugins. Two-factor, passkey, and login-interstitial plugins finish their authentication exchange while the visitor is still logged out, so those specific requests must not be sent to the login wall. aioi_public_actions controls which admin-ajax.php / admin-post.php actions may still run while the site is private. The bundled list covers Wordfence, WP 2FA passkeys, miniOrange 2-Factor, Solid Security, AIO Login's passwordless codes, Limit Login Attempts Reloaded's email second factor, and Login With Ajax passkey login: add_filter( 'aioi_public_actions', function( $actions ) { $actions[] = 'my_plugin_login_challenge'; return $actions; } ); aioi_public_rest_routes does the same for plugins that verify the second factor over the REST API instead. An entry matches the request route exactly, or as a path segment prefix of it. The bundled list covers WP 2FA's code verification and Limit Login Attempts Reloaded's code delivery: add_filter( 'aioi_public_rest_routes', function( $routes ) { $routes[] = '/my-plugin/v1/login/verify'; return $routes; } ); Every bundled entry is tied to the plugin it belongs to and only applies while that plugin is active, so a private site never leaves an endpoint open for a plugin it does not run. A renamed build, or a copy loaded as a must-use plugin, is not recognized: add its action or route with the filters above. Only add authentication endpoints to either list. Anything on them can be called by logged-out visitors, so it must not return site content, and it must do its own credential or token check. Be careful with plugins that funnel every one of their endpoints through a single generic action or route - allowing that one name reopens all of them, which is why Shield Security's shield_action router is not on the bundled list even though its 2FA uses it. Google Workspace Integration If your organization uses Google Workspace (formerly Google Apps), two companion plugins extend your intranet: Visit wp-glogin.com for more information about these and other plugins.

安装:

Easiest way:
  1. Go to your WordPress admin control panel's plugin page
  2. Search for 'All-In-One Intranet'
  3. Click Install
  4. Click Activate in the plugin card
  5. Go to 'All-In-One Intranet' under Settings in your WordPress admin area to configure the plugin
If you cannot install from the WordPress plugins directory for any reason, and need to install from ZIP file:
  1. Upload all-in-one-intranet directory and contents to the /wp-content/plugins/ directory, or upload the ZIP file directly in the Plugins section of your WordPress admin
  2. Go to Plugins page in your WordPress admin
  3. Click Activate
  4. Go to 'All-In-One Intranet' under Settings in your WordPress admin area to configure the plugin

屏幕截图:

  • Network Admin settings for a multisite intranet: network-wide privacy and per-sub-site membership controls.

常见问题:

How do I make my WordPress site completely private?

Install and activate the plugin, then go to Settings > All-In-One Intranet and check "Force site to be entirely private." All pages, posts, and custom content types will require login. The REST API and XML-RPC are also locked down automatically.

Does the plugin protect uploaded media files?

No. Media files (images, PDFs, videos, etc.) that are uploaded through WordPress remain accessible to anyone who knows the direct URL. This is because WordPress serves media files directly through your web server, bypassing PHP and plugin logic. This limitation is common to most WordPress privacy plugins. If direct media file protection is a requirement, you would need a server-level solution or a dedicated download protection plugin in addition to All-In-One Intranet.

Does it block the WordPress REST API?

Yes. When the private site option is enabled, all unauthenticated REST API requests receive a 401 error response. This prevents external tools, scripts, or bots from accessing your content through API endpoints like /wp-json/wp/v2/posts. Authenticated requests from logged-in users continue to work normally.

How does auto-logout work?

The plugin records a timestamp each time a logged-in user loads a page. On the next page load, it compares the current time against the stored timestamp. If the difference exceeds the configured idle time, the user is logged out immediately. The idle timer resets on every page load, so users who are actively browsing are never interrupted. You can set the timeout in minutes, hours, or days.

Can I set a custom page for users to see after login?

Yes. In the Login Redirect section of the plugin settings, enter the full URL of the page you want users to land on after logging in. This overrides the default WordPress behavior of sending users to the dashboard. Note that if a user was trying to reach a specific page before being asked to log in, they will be redirected back to that page instead of the custom redirect URL.

Does it work with WordPress multisite?

Yes. The plugin is fully compatible with WordPress multisite. In a multisite network, the settings are managed from the Network Admin area. You can make the entire network private, require users to be members of individual sub-sites before accessing them, and automatically assign roles to users across sub-sites when new users or new sites are created.

Can I allow certain pages to remain public while the rest of the site is private?

Yes, but it requires a small amount of code. Use the aioi_allow_public_access filter in your theme's functions.php file or a custom plugin. For example, to keep a page with the slug "public-info" accessible without login: add_filter( 'aioi_allow_public_access', function( $allow ) { if ( is_page( 'public-landing' ) ) { return true; } return $allow; } );

Does it block search engines from indexing my site?

Yes. When the private site option is enabled, the plugin overrides the robots.txt file to disallow all crawling. It also disables outgoing pingbacks and trackbacks, so your site does not announce new content to external services or ping aggregators.

Does it work with caching plugins?

Generally, yes. Most WordPress caching plugins bypass the cache for logged-in users and do not cache redirects, so the privacy enforcement works as expected. However, aggressive full-page caching at the server level (Varnish, Nginx FastCGI cache) may serve cached pages to unauthenticated users if not configured to respect WordPress login cookies. If you use server-level caching, make sure it bypasses the cache when WordPress login cookies are absent.

What happens to users with no role on my site?

On a single-site WordPress installation, users who are logged in but have no assigned role are treated as unauthorized. The plugin logs them out and displays a message explaining that they do not have permission to access the site. This prevents access by accounts that have been deactivated by removing their role rather than deleting them.

Does it block XML-RPC access?

Yes. When the private site option is active, the plugin completely disables XML-RPC. This prevents any remote access through the XML-RPC protocol, including third-party apps and services that use it to interact with WordPress.

Is it compatible with custom login page plugins?

The plugin uses WordPress's built-in auth_redirect() function to send unauthenticated users to the login page. Most custom login page plugins work by intercepting the standard login URL and redirecting to a custom page. Because All-In-One Intranet relies on standard WordPress authentication functions, it is generally compatible with custom login page plugins. The login redirect feature also works regardless of whether the user logs in through the default or a custom login page.

Is it compatible with two-factor authentication plugins?

Yes. Some 2FA plugins complete part of the login exchange with a background request from the login screen, which happens before the visitor is logged in. Those requests are recognized and let through, so the second-factor prompt appears and login can finish. Wordfence, WP 2FA, miniOrange 2-Factor, Solid Security, AIO Login, Limit Login Attempts Reloaded and Login With Ajax passkey login are covered out of the box. Login With Ajax's own AJAX login form is not - that form lives on a front-end page, which is behind the login wall on a private site anyway. Plugins that keep the whole flow on the login page itself, such as Two-Factor, CleanTalk Security and Google Authenticator, need nothing special. Account recovery links are treated differently from login. A link that switches off a user's second factor is not needed to finish a login, so it stays behind the login wall even when the rest of that plugin is supported - miniOrange's emailed 2FA reset link is the current example. Ask an administrator to clear the second factor, or open that one endpoint yourself with the aioi_allow_public_access filter. Shield Security is the exception: its 2FA step shares one general-purpose endpoint with the rest of the plugin, so opening it would also open everything else behind that endpoint. If you use Shield's 2FA on a private site, add shield_action yourself with the aioi_public_actions filter described in the Description tab. If any other 2FA plugin reports a generic authentication error at login on a private site, its background request is being sent to the login wall. Developers can allow it with the aioi_public_actions or aioi_public_rest_routes filter, also in the Description tab.

How is this different from a membership plugin?

Membership plugins are built to sell access - they manage subscription levels, process payments, and drip-feed content to paying customers. All-In-One Intranet is built for internal, private sites where everyone who logs in is already a trusted member of your organization. It locks the entire site down to logged-in users in one click instead of gating individual posts behind a purchase or subscription tier. If you need to charge for access, use a membership plugin; if you need a private company intranet, this is the simpler fit.

Does it work with page builders like Elementor, Beaver Builder, or Divi?

Yes. All-In-One Intranet works at the authentication layer and does not change how your pages are built or rendered, so you can design your intranet with any page builder and the privacy enforcement still applies to the finished pages. If a builder's live preview appears to redirect to the login screen, that is expected for a logged-out request - edit while logged in and the builder behaves normally.

Will it slow down my site?

No noticeable impact. The privacy check runs early on each request and is a simple logged-in or logged-out test, and the auto-logout feature reads and writes a single user meta value per page load. There are no external calls and no heavy database queries involved.

Can I keep my custom-branded login page?

Yes. The plugin relies on WordPress's standard authentication, so it does not replace or restyle your login screen. If you use a custom login page plugin, unauthenticated visitors are sent to whatever login URL WordPress is configured to use, and your branding is preserved.

更新日志:

1.9.2 1.9.1 1.9.0 1.8.1 1.8.0 1.7.1 1.7 1.6 1.5 1.4 1.3 1.2 1.1