Tame Session Defaults is a small WordPress plugin that reduces authentication session lifetimes. Shorter sessions reduce the window of opportunity for session hijacking.
It also includes controls for:
- Shortening session lengths by default.
- Fine-tuning session lengths with filters, including per user or role.
- Validating selected logged-in request areas against the stored session IP address and user agent.
- Limiting users to one active session by destroying other sessions on login.
- Requiring re-authentication before configured sensitive admin operations.
This is probably best used as an MU plugin. You can also copy the plugin code into your own starter or skeleton projects.
By default, the plugin reduces the normal logged-in session lifetime from 2 days to 2 hours. If "Remember Me" is checked, it reduces the session lifetime from 2 weeks to 24 hours.
Filters the default session length. The value is an integer expiry length in seconds. The logged-in user ID is passed as the second argument.
add_filter(
'tn_tame_session_default',
function ( int $seconds, int $user_id ): int {
if ( user_can( $user_id, 'manage_options' ) ) {
return 30 * MINUTE_IN_SECONDS;
}
return 2 * HOUR_IN_SECONDS;
},
10,
2
);Filters the session length when "Remember Me" is checked. The value is an integer expiry length in seconds. The logged-in user ID is passed as the second argument.
add_filter(
'tn_tame_session_default_remember',
function ( int $seconds, int $user_id ): int {
return DAY_IN_SECONDS;
},
10,
2
);By default, other sessions are destroyed on login. This filter currently acts as an opt-out: returning true skips wp_destroy_other_sessions().
add_filter(
'tn_tame_session_limit',
function ( bool $skip_limit, WP_User $user ): bool {
return user_can( $user, 'manage_options' );
},
10,
2
);Controls whether IP address and user-agent validation runs for logged-in admin-area requests.
This runs on admin_init, so it covers wp-admin screens, admin-ajax.php, and admin-post.php. Validation is enabled by default for this existing wp-admin area.
add_filter( 'tn_tame_session_validate_session', '__return_false' );Controls which logged-in request areas should run IP address and user-agent validation.
The default policy matches the original behaviour: wp-admin validation is enabled, front-end and REST API validation are disabled.
Area values can be:
trueto validate all logged-in requests in that area.falseto skip validation for that area.- An array of path or route prefixes to validate only matching requests.
add_filter(
'tn_tame_session_validate_session_areas',
function ( array $areas ): array {
$areas['front_end'] = array( '/account/', '/checkout/' );
$areas['rest_api'] = array( '/wp/v2/users', '/my-plugin/v1/' );
return $areas;
}
);Available areas are:
wp_adminfor wp-admin screens,admin-ajax.php, andadmin-post.php.front_endfor front-end requests.rest_apifor REST API requests.
Prefix matching is segment-aware. For example, /account/ matches /account and /account/profile/, but not /accounting/ or /my-account/.
Registers sensitive admin operations that should require a fresh session. Each operation can define a maximum session age, capability, admin page, request action, and request method.
If a matching session is stale, GET and HEAD requests redirect to the login form. AJAX, JSON, and unsafe methods receive a 401 response instead.
add_filter(
'tn_tame_session_reauth_operations',
function ( array $operations, int $user_id ): array {
$operations['delete-users'] = array(
'max_age' => 15 * MINUTE_IN_SECONDS,
'capability' => 'delete_users',
'pages' => array( 'users.php' ),
'actions' => array( 'delete', 'delete-selected' ),
'methods' => array( 'GET', 'POST' ),
);
return $operations;
},
10,
2
);Filters the URL passed to wp_login_url() when a stale session needs to re-authenticate.
add_filter(
'tn_tame_session_reauth_redirect_url',
function ( string $redirect_url, array $operation ): string {
return admin_url( 'users.php' );
},
10,
2
);Runs when a session fails IP address or user-agent validation. This is useful for logging or notifications.
add_action(
'tn_tame_session_non_valid',
function ( ?string $ip, ?string $user_agent, array $session_data ): void {
error_log( 'Invalid WordPress session detected.' );
},
10,
3
);Runs when a configured sensitive operation requires re-authentication.
add_action(
'tn_tame_session_reauth_required',
function ( array $operation, int $user_id ): void {
error_log( 'Re-authentication required for user ' . $user_id );
},
10,
2
);Please see SECURITY.md for vulnerability reporting instructions.
See CHANGELOG.md for recent changes.