Linux 软件免费装
Banner图

WindCodex SwitchGuard – WordPress User Switching & Audit Log for WooCommerce

开发者 windcodex
更新时间 2026年7月29日 14:26
PHP版本: 8.1 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

woocommerce login as user user switching login as customer switch user

下载

1.0.1 1.0.0 1.0.2

详情介绍:

WindCodex SwitchGuard is a secure, free user switching plugin for WordPress and WooCommerce. Switch into any lower-privilege user account in one click – no passwords, no account resets, no security risk. Whether you are a support agent reproducing a customer bug, a WooCommerce store owner checking an order as the buyer, or a developer testing member-only content – SwitchGuard gives you instant access to any user account and brings you straight back when you are done. Security-first design. Every switch is nonce-verified, role-hierarchy-enforced, and recorded in a signed session cookie. You cannot accidentally switch into an equal-or-higher privilege account. Everything in the Free Version One-Click User Switching Who Uses SwitchGuard? How SwitchGuard Differs from Other User-Switching Plugins Most user-switching plugins simply swap the WordPress session with no additional safeguards – leaving you exposed to privilege escalation and session fixation. SwitchGuard is built with security as the core requirement: 🚀 Pro Version Need IP allowlists, locked accounts, scheduled switching windows, email alerts, and a full audit log dashboard? SwitchGuard Pro is available at windcodex.com SwitchGuard Pro adds advanced controls for agencies, enterprise teams, and high-security environments: How It Works
  1. Activate SwitchGuard – User Switching is enabled by default.
  2. Go to the SwitchGuard settings page in wp-admin and configure which roles can switch.
  3. Click Switch To next to any user in the Users list, profile screen, or WooCommerce order screen.
  4. Work in the target account – browse the frontend, check orders, test content.
  5. Click Switch Back in the admin bar to return to your original account instantly.
Requirements

安装:

From WordPress Dashboard (Recommended)
  1. Go to Plugins > Add New Plugin.
  2. Search for WindCodex SwitchGuard or SwitchGuard.
  3. Click Install Now, then Activate.
  4. Navigate to SwitchGuard in the left sidebar and configure your settings.
Manual Installation
  1. Download the plugin .zip file.
  2. Go to Plugins > Add New Plugin > Upload Plugin.
  3. Upload the zip and click Install Now, then Activate.
  4. Go to SwitchGuard in the left sidebar to configure.

屏幕截图:

  • **Admin bar** – Quick user search, Switch Back, and Switch Off controls.
  • **Settings page** – Access Control, Integration Points, and session duration settings.
  • **WooCommerce order screen** – Switch to Customer button on order edit pages.

升级注意事项:

1.0.2 Loads plugin translations for full compatibility with translation plugins and language packs. No database changes – safe to update. 1.0.1 Adds inline Pro upsell banner, review request notice, and help button in the settings header. No database changes – safe to update. 1.0.0 Initial release – no upgrade steps required.

常见问题:

Is user switching safe?

Yes – when done correctly. SwitchGuard protects every switch action with WordPress nonces (CSRF protection), enforces role hierarchy so you can only switch into lower-privilege accounts, and stores the session in a signed HTTPOnly cookie that cannot be tampered with or replayed.

Does SwitchGuard store passwords?

Never. SwitchGuard switches your WordPress session without touching the login form. No passwords are read, stored, logged, or transmitted at any point.

Who can switch user accounts?

By default, any user with the edit_users capability (typically Administrators). You can restrict this to specific roles – for example, allowing only Shop Managers to switch – from the Access Control settings.

Can I accidentally switch into an administrator account?

No. SwitchGuard automatically blocks switching into any account with equal or higher privilege than the switcher. The "Block switching into administrators" setting adds an explicit extra layer on top of this rule.

How do I switch back to my original account?

A Switch Back button is always shown in the WordPress admin bar during an active switch session. Click it to return instantly. You can also click Switch Off to end the session entirely.

How is this different from the "User Switching" plugin?

SwitchGuard adds security layers that are not present in most other user-switching plugins: explicit opt-in (on by default), strict role hierarchy enforcement (server-side, not just UI), HMAC-signed session cookies (not plain database rows), nonce protection on every action, and a WooCommerce order-screen integration with an admin-bar quick-search switcher.

Does it work with WooCommerce?

Yes. When WooCommerce is active, a Switch to Customer button appears on order edit screens, letting you jump into the customer's account to reproduce checkout issues, verify order history, or check account details exactly as they see them.

Does the switch session expire automatically?

Yes. The switch session is stored in a cookie with a configurable TTL (default 48 hours, adjustable from 1 to 168 hours). When the cookie expires, the session ends and you are returned to your original login state.

What happens if I close the browser during a switch session?

The switch session is stored in a persistent cookie (not a session cookie), so it survives browser restarts until the configured TTL expires. Once expired, you will need to log in again.

Does SwitchGuard work on WordPress multisite?

Yes. SwitchGuard is fully compatible with WordPress multisite networks.

Is SwitchGuard compatible with 2FA or membership plugins?

SwitchGuard bypasses the login form entirely, so it works alongside most 2FA and membership plugins. If a plugin enforces its own session validation on every page load, there may be edge cases – check the plugin documentation or contact support.

Can I log or audit switch sessions in the free version?

The free version records basic switch activity in signed session cookies but does not include a persistent audit log. A full audit log with actor, target, IP, and timestamp is available in SwitchGuard Pro.

Can I restrict which users can be switched into?

In the free version, you can restrict who can perform switches by role. Per-user target grants – allowing only specific users to be switched into – are available in SwitchGuard Pro.

更新日志:

1.0.2 1.0.1 1.0.0