Skip to content
Branch: master
Go to file

Latest commit

ericmann committed b5cafd9 Mar 31, 2019
Squashed commit of the following:
commit 79a174e
Author: Eric Mann <>
Date:   Sat Mar 30 20:31:50 2019 -0700

    Better cron avoidance that will still enable cleanup routines.

commit 58da8e9
Author: Eric Mann <>
Date:   Sat Mar 30 20:22:42 2019 -0700

    Disable the initialization routine for cron runs.

    Fixes #81

commit 9bd1c67
Author: Eric Mann <>
Date:   Sat Mar 30 20:18:48 2019 -0700

    Update donation link and bump to 4.2


Failed to load latest commit information.

WP Session Manager Build Status Coverage Status

Session management for WordPress.


Adds $_SESSION functionality to WordPress, leveraging the database where needed to power multi-server installations.

Every visitor, logged in or not, will be issued a session. Session data will be stored in the WordPress database by default to deal with load balancing issues if multiple application servers are being used. In addition, the session collection will also be stored in memory for rapid use within WordPress.

Session data stored in the database can be encrypted at rest for better security.


Manual Installation

  1. Upload the entire /wp-session-manager folder to the /wp-content/plugins/ directory.
  2. Activate the plugin through the 'Plugins' menu in WordPress.
  3. Use $_SESSION in your code.

Frequently Asked Questions

How do I add session variables?

Merely use the superglobal $_SESSION array:

$_SESSION['user_name'] = 'User Name';                            // A string
$_SESSION['user_contact'] = array( 'email' => '' ); // An array
$_SESSION['user_obj'] = new WP_User( 1 );                        // An object

How long do session variables live?

This depends on your PHP installation's configuration. Please read the PHP manual for more details on configuration.

Can I use this plugin without creating new tables?

Absolutely! As of version 2.0, this plugin will create a new table for WordPress to store session data. In general, this is more efficient long-term than using options for data storage. However, if your system does not allow creating a table, add the following to wp-config.php to use the options table instead:

define( 'WP_SESSION_USE_OPTIONS', true );

I get an error saying my PHP version is out of date. Why?

PHP 5.6 was designated end-of-life and stopped receiving security patches in December 2018. PHP 7.0 was also marked end-of-life in December 2018. The minimum version of PHP supported by WP Session Manager is now PHP 7.1.

If your server is running an older version of PHP, the session system will not work! To avoid triggering a PHP error, the plugin will instead output this notice to upgrade and disable itself silently. You won't see a PHP error, but you also won't get session support.

Reach out to your hosting provider or system administrator to upgrade your server.

I get an error saying another plugin is setting up a session. What can I do?

WP Session Manager overrides PHP's default session implementation with its own custom handler. Unfortunately, we can't swap in a new handler if a session is already active. This plugin hooks into the plugins_loaded hook to set things up as early as possible, but if you have code in another plugin (or your theme) that attempts to invoke session_start() before WP Session Manager loads, then the custom handler won't work at all.

Inspect your other plugins and try to find the one that's interfering. Then, reach out to the developer to explain the conflict and see if they have a fix.





  • Update: Change donate link to Patreon vs PayPal.
  • Fix: Disable the initialization routine for cron runs.


  • Fix: Defensively protect deprecated functions with function_exists() checks to avoid conflicts with other systems.
  • Fix: Disable the initialization routine if sessions are disabled.


  • Fix: Add some defense to ensure end users are running the correct version of PHP before loading the system.
  • Fix: Eliminate a race condition where another plugin or the theme created the session first.
  • Fix: Schedule a cron to auto-delete expired sessions.


  • New: Add an object cache based handler to leverage Redis or Memcached if available for faster queries.
  • New: Adopt the Contributor Covenant (v1.4) as the project's official code of conduct.
  • Update: Bump minimum PHP requirements due to out-of-date version deprecations.
  • Fix: Correct a race condition where a session was created before the database table existed.
  • Fix: Correct a race condition where the $wpdb global is not yet set when a session is deleted from the database.
  • Fix: Remove unnecessary integer session ID from the stored data table.


  • Update: Add support for the wp_install hook to create custom table immediately.


  • Fix: Repair code blocks in the readme
  • Fix: Use a more defensive approach to starting sessions in the event another plugin has started one already


  • Fix: Add back in proper array access support for the deprecated WP_Session object.


  • Update: Pull a Sessionz fix


  • Update: Refactor to use Sessionz
  • Update: Add encryption at rest if WP_SESSION_ENC_KEY is set


  • Fix: Wire the data storage migration to a session init hook to ensure it runs.
  • Fix: Clean up sessions when all data is removed.


  • Fix: Repair data storage that was not returning actual stored session data.


  • Update: Use a table instead of options for storing session data.


  • Update: Use regex pattern matching to ensure session IDs are identical going in/out of the DB to account for encoding differences


  • Update: Additional filters for the setcookie parameters
  • Update: Expose the Session ID publicly
  • Fix: Better handling for malformed or broken session names


  • Update: Enhanced plugin organization
  • Update: Added WP_CLI support for session management
  • Update: Add Composer definitions
  • Fix: Break up the deletion of old sessions so queries don't time out under load


  • Fix a race condition where session expiration options could accidentally be set to autoload
  • Make the garbage collection routine run hourly to alleviate long-running tasks on larger sites


  • Fix a bug where session expiration was not properly set upon instantiation


  • Implement Recursive_ArrayAccess to provide multidimensional array support
  • Better expiration for session data
  • Implement garbage collection to keep the database clean


  • Switch to object persistence rather than transients


  • Changes implementation to avoid the use of a global variable (still registered for convenience)


  • First version

Upgrade Notice

4.0 This version requires PHP 7.1 or higher.

3.0 This version requires PHP 5.6 or higher and uses Composer-powered autoloading to incorporate Sessionz for transparent session management.


This version will create a new database table for storing session data! If you do not want such a table, please set the WP_SESSION_USE_OPTIONS constant to true in wp-config.php! Upgrading will delete all existing sessions!


First version

Additional Information

Contributors: ericmann
Donate link:
Tags: session
Requires at least: 4.7
Tested up to: 5.1.1
Requires PHP: 7.1
Stable tag: 4.2.0
License: GPLv2 or later
License URI:

You can’t perform that action at this time.