This plugin will immediately invalidate your auth cookies when you manually log out.
As of April 2026, Invalidate Logged Out Cookies is a WordPress login plugin with 10 active installations and a 0/5 rating0. It has been downloaded 2.2K+ times in total. Requires WordPress 2.9+ and PHP false+. Available on WordPress.org since 2009. Last updated 15 years ago — may have compatibility concerns. Top alternative: WPS Hide Login.
Due to lack of interest (both my own and based on the number of downloads) this plugin will not be updated for WP 3.0
WordPress’ auth cookies include a built-in expiration date (either 2 or 14 days depending on if the ‘Remember Me’ option is checked). Even if you remove the client-side cookie (by manually logging out or just closing your browser if ‘Remember Me’ wasn’t checked when logging in) the data that was stored within the cookie is still valid until the expiration date is reached.
This could be an issue if someone managed to “steal” your cookie(s). They would still be able to access your website for some time into the future.
This plugin will immediately invalidate your auth cookies when you manually log out. This, of course, also mea…
| WordPress | 2.9+ requiredTested up to 2.9.2 |
| PHP | false+ required |
auth_cookie_invalidated_cookie actionPlugin data sourced from WordPress.org. Analysis and metrics by PluginSift.