xpay✦ Commerce
Directory
WooCommerce plugins
Login as User or Customer — User Switching
Login as User or Customer — User Switching
Instant user switching for WordPress — switch to any user account in one click, with full WooCommerce support for customer service teams.
3.0
(13 ratings)Will this break my store?
What the WordPress.org registry says about keeping Login as User or Customer — User Switching running.
Tested to 6.9.5 — 1 branch behind 7.0
Tested against the WordPress branch in use today.3 months ago
At least 3.2 releases a year since launch. WordPress.org only lists versions still available for download, so the real number may be higher.7.4
Your host must be running at least this version.5.0
3
Maintenance & trust
Scored on how Login as User or Customer — User Switching is looked after — not on how many stores run it.
77
out of 100Maintenance
35 / 35WordPress compatibility
14 / 20Support responsiveness
Not enough dataMerchant satisfaction
6 / 15Listing transparency
7 / 10Ratings
3.0
13 ratingsLogin as User or Customer is a powerful user switching plugin that lets admins and support staff instantly switch into any user account — without knowing their password. It’s the fastest way to see exactly what your customer sees, troubleshoot issues, and provide hands-on support directly from your WordPress dashboard.
WooCommerce store owners: This plugin is purpose-built for you. Switch to a customer from the Orders screen, manage their cart, and create orders on their behalf — ideal for phone orders and assisted sales. WooCommerce features require the Pro version.
Who is this for?
- WooCommerce stores — assist customers with orders, cart issues, and account problems without asking for their password
- Membership sites — verify what members see after logging in
- Agencies & developers — test roles and permissions across any user account instantly
- Support teams — reproduce customer-reported bugs in one click
Free Features
- One-click user switching — switch to any non-admin account from the Users screen
- Switch from user profile — Login As button on the Edit User screen
- Go Back in one click — a persistent bar on the front end returns you to your original account instantly
- No password needed — access any account without exposing credentials
- Role-based access control — choose which roles are allowed to use the switch feature
- 2FA compatible — works alongside most two-factor authentication plugins
- Multisite compatible — works on WordPress network installations
- Nonce-protected — every switch action is verified with a WordPress nonce
- Secure session storage — switch state stored server-side using WordPress transients, not exposed cookies
Pro Features
- ⭐ WooCommerce Orders page — Login As button next to every order
- ⭐ WooCommerce Order detail — switch to the customer from the single order screen
- ⭐ Cart management — add, remove, and edit products in the customer’s cart
- ⭐ Create orders on behalf of customers — perfect for phone and assisted sales
- ⭐ Advanced role management — granular control over who can switch to whom
- ⭐ Custom redirect URL — choose where you land after switching
- ⭐ Activity log — track every switch action for auditing purposes
- ⭐ Shortcode support — place Login As buttons anywhere on your site
How It Works
- Go to Users in your WordPress admin
- Click Login as this user next to any non-admin account
- You are instantly switched into that account — no password required
- Browse the site as that user
- Click Go back in the bar at the bottom of the screen to return to your admin account
Security
Security is the foundation of this plugin. Every action is protected by multiple layers:
- Nonce verification on every switch and return action
- Capability checks — only users with
edit_users,manage_options, ormanage_woocommercecan switch - Admin account protection — switching into administrator accounts is blocked
- Server-side session storage — switch state stored in WordPress transients with a 1-hour TTL that refreshes on every page load
- HttpOnly + SameSite=Lax cookies — session tokens protected against XSS and CSRF
- No data sharing — no data is sent to any external service
Security vulnerabilities are managed through the Patchstack Vulnerability Disclosure Program. All reported issues are reviewed, patched, and disclosed responsibly.
Privacy
This plugin does not send data to any third party, does not include any third-party resources, and never will.
The plugin uses a single browser cookie (loginas_session_token) to identify the current switch session. The cookie stores only a random 64-character token — no user data. The actual session data (user IDs) is stored server-side in WordPress transients.
Compatibility
- WordPress 5.0+
- WordPress Multisite
- WooCommerce (Pro)
- PHP 7.4, 8.0, 8.1, 8.2, 8.3
- Compatible with most 2FA and security plugins
Security
This plugin is enrolled in the Patchstack Vulnerability Disclosure Program.
To report a security vulnerability, please use the Patchstack mVDP link above. Do not report security issues through the WordPress support forum.
Only users with the edit_users, manage_options, or manage_woocommerce capability. You can further restrict this to specific roles in the plugin settings under Login AS → Settings.
No. Switching into any account with administrator-level capabilities (edit_users or manage_options) is blocked for security reasons.
A bar appears at the bottom of the page while you are switched in. Click Go back to return to your original admin account instantly.
Yes — WooCommerce features are available in the Pro version. This includes a Login As button on the orders list, a meta box on the single order screen, cart management, and the ability to create orders on behalf of customers.
Yes. The plugin is compatible with most 2FA solutions. The 2FA prompt is bypassed when switching because you authenticate as the admin, not the target user.
Yes. The plugin works on Multisite installations.
The switch session is stored as a WordPress transient with a 1-hour TTL that refreshes on every page load. If the transient expires or is evicted from the cache, the session ends and you will be returned to a normal logged-out state. Simply log back into your admin account.
No. The plugin does not send data to any third party, does not include any third-party resources, and does not use external APIs.
You can report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team help validate, triage and handle any security vulnerabilities. Report a security vulnerability.
Plugin details
Tags on WordPress.org
