SessionQuota – Limit Concurrent Logins & Prevent Account Sharing
SessionQuota is a concurrent login limiter for WordPress. Set how many active sessions each user can have, then choose exactly what happens when that limit is reached.
It is a practical way to reduce account sharing on membership sites, online courses, customer portals, private communities, and any WordPress site where one account should not stay active on too many devices.
The free edition gives you a complete global session policy with three enforcement modes. Set it once under Settings → SessionQuota and let WordPress handle the rest.
Free Concurrent Login Controls
- Global session limit – Set the maximum number of active WordPress sessions allowed per user.
- Block new login – Reject a new login when the account has already reached its limit.
- Logout oldest session(s) – Allow the new login and remove only the oldest sessions needed to stay within the limit.
- Single-session mode – Keep the latest login and automatically log out every other session for that account.
- Unlimited mode – Set the limit to
0when you do not want to enforce a global cap. - No external service required – Session enforcement runs on your WordPress site.
Choose the Right Enforcement Mode
Block new login
Use this when you want the clearest deterrent against shared credentials. Existing sessions stay active and the next login is refused.
Logout oldest session(s)
Use this when legitimate users frequently switch devices. The new login succeeds and SessionQuota removes the oldest session or sessions needed to enforce the limit.
Logout all other sessions
Use this for a strict one-device-at-a-time policy. The latest login stays active and every other session for that account is terminated.
Need Granular Rules and Session Visibility?
SessionQuota Pro adds advanced controls for membership sites, stores, communities, and multisite networks:
- Role-based concurrent session limits.
- Membership-level limits for MemberPress and Paid Memberships Pro.
- Per-user session limit overrides.
- Frontend active-session controls for logged-in users.
- Blocked-login recovery through secure one-time email links.
- Force logout and site-wide session management tools.
- Security event logging, optional device and country context, and activity alerts.
- WP-CLI commands and network-managed multisite support.
The free plugin remains fully functional for sites that only need one global limit. Upgrade when you need different rules for different users, self-service session controls, operational tools, or monitoring.
Compare features and get SessionQuota Pro
Privacy
The free edition uses WordPress session data to enforce your configured limit. It does not send session data to HandyPlugins or require an external account.
Support and Development
- Free support: https://wordpress.org/support/plugin/sessionquota/
- Bug reports and contributions: https://github.com/HandyPlugins/sessionquota
- SessionQuota Pro documentation: https://handyplugins.co/docs-category/sessionquota-pro/
More from HandyPlugins
- Magic Login Pro – Passwordless WordPress authentication with magic links and flexible integrations.
- Powered Cache – WordPress caching and optimization for PageSpeed and Core Web Vitals.
- Stream Integration Pro – Upload, sync, restore, and manage Cloudflare Stream videos in WordPress.
- Easy Text-to-Speech – Convert WordPress content into synthesized speech.
- Handywriter – AI-powered writing assistance inside WordPress.
- PaddlePress PRO – Sell digital products and software licenses with Paddle.
- WP Accessibility Toolkit – Add practical accessibility tools to your WordPress site.
