DocID®
The DocID® plugin connects your WordPress website with one of the largest online networks of healthcare professionals, helping you reach a broad professional audience with relevant content. DocID® is an authentication and marketing platform designed specifically for the healthcare and pharmaceutical industry. The plugin enables WordPress site owners to define technical access restrictions for healthcare content and use verified professional attributes when evaluating access eligibility. Whether you’re presenting medical products, hosting webinars, or sharing restricted content, DocID® provides professional authentication and verification without requiring website owners to operate their own healthcare-professional identity system. The plugin supplies technical controls and configuration options. Website operators remain responsible for assessing, configuring, documenting, and operating their implementation in accordance with the legal and regulatory requirements applicable to their content, audience, jurisdiction, and use case. Features ✅ Professional Verification — Authenticate doctors, pharmacists, and other healthcare professionals and evaluate verified professional attributes for access decisions. ⚡ Instant Access — No passwords, no waiting time, no hassle. HCPs get instantly verified and immediate access to your content. 🔐 Data-Minimizing Scope Control — Request only the identity and profile attributes needed by the website, with optional data governed through configured scopes and user authorization. 🔍 User Insights & Analytics — Gain valuable insights about your audience and campaign activities. 🎯 Targeted Content — Redirect users by profession, language, or country. 📊 Campaign Management — Create campaign links, track performance, collect consents, and much more with the DocID® business modules. 🧩 WordPress-Native Integration — Protect posts, pages, custom post types, and media; add authentication-aware account navigation; and use scope-aware profile shortcodes in content and widgets. 👤 Optional Native Accounts — Provision linked WordPress users for integrations that rely on the native current user, roles, and capabilities. 🧭 Role Mapping and Login Destinations — Map verified DocID® profile attributes to non-administrative WordPress roles and configure deterministic profession- or discipline-based landing pages. Native WordPress accounts and roles Native account provisioning is optional and extends the existing DocID® authentication session. New accounts receive a deterministic non-personal username and are linked exclusively through the stable DocID® account identifier. Existing WordPress accounts are never linked by email address. Enabling email synchronization also enables the optional email scope. The WordPress admin bar can be hidden separately for provisioned DocID® users without affecting other WordPress users. Linked accounts remain federated identities and cannot use local WordPress passwords, password reset, or application passwords. Role mappings can apply to every DocID® user or match exact profession, discipline, institution, or subject values. All matching roles are combined. Synchronization adds and removes only roles managed by DocID®; roles assigned independently in WordPress remain unchanged. Administrative and user-management roles cannot be mapping targets. Login destinations can match an exact profession or discipline and point to a local WordPress URL. Lower priority numbers are evaluated first. When authentication started from protected content, the originally requested content always takes precedence over a configured profile destination. Menu links and shortcodes The WordPress menu editor provides a dynamic Login/Logout link, a Login link shown only to visitors, and a Logout link shown only to authenticated DocID® users. Each item supports WordPress’s standard editable Navigation Label. The settings page also lists all available shortcodes and the scope required for each profile value. Common examples are: [docid-account-navigation] — shows Sign in to visitors or {username} | Log out to authenticated DocID® users. The username follows the same scope-aware fallback order as [docid-username]. [docid-loggedin-content]Content[/docid-loggedin-content] — shows content only to authenticated DocID® users. [docid-loggedout-content]Content[/docid-loggedout-content] — shows content only to visitors without an authenticated DocID® session. [docid-login-link] — renders Sign in for visitors and Log out for authenticated DocID® users. Optional login_text and logout_text attributes customize both labels, for example [docid-login-link login_text="Access" logout_text="Leave"]. [docid-username] — renders the best available username: the authorized profile name; authorized email address; or a translated generic user label. [docid-profile-id] — renders the stable DocID® account identifier supplied by the required openid scope. [docid-profile-name], [docid-profile-title], [docid-profile-given-name], [docid-profile-family-name], and [docid-profile-gender] — require the optional profile scope and user authorization. [docid-profile-email] — requires the optional email scope and user authorization. [docid-profile-phone-number] — requires the optional phone scope and user authorization. Developers can inspect the current session without creating a WordPress user: $docid = new \DOCID\Includes\DOCID_Base(); $is_authenticated = $docid->docid_is_loggedin(); $identity = $docid->docid_get_user(); $account_id = is_array($identity) ? ($identity['id'] ?? '') : ''; $profession_id = is_array($identity) ? ($identity['profession_id'] ?? '') : ''; $discipline_id = is_array($identity) ? ($identity['discipline_id'] ?? '') : ''; $profession_verified = is_array($identity) ? (bool) ($identity['profession_verified'] ?? false) : false; The normalized identity contains the stable account ID and, when returned by the authorized scopes, profile, email, phone, profession_id, discipline_id, institution_id, subject_id, and professional verification data. When native provisioning is enabled, the linked WordPress user ID is available as wordpress_user_id for the current DocID® session. Additional Resources Learn more about DocID® at https://docid.de/industry. More about authentication requirements and healthcare regulations: – Login for Healthcare Professionals – German Drug Advertising Act (HWG) – German Medical Products Act Data-privacy and external Services This plugin connects to DocID® to authenticate users and confirm their professional access eligibility. It always requests the stable DocID® identifier and professional access data. Profile, email, and phone data are requested only when the website administrator enables the corresponding optional scope and are transferred only after the user grants the required authorization. The available technical controls do not constitute a guarantee of legal or regulatory compliance. Website operators are responsible for selecting appropriate scopes, establishing the required legal basis, providing applicable notices, configuring consent collection where required, and validating the complete implementation for their use case. This service is provided by 8awake GmbH: Privacy Policy, Terms of Use. DocID® is a service offer from 8awake.
Top keywords
- docid27×2.88%
- wordpress16×1.71%
- content13×1.39%
- user13×1.39%
- identity12×1.28%
- id10×1.07%
- optional9×0.96%
- profile9×0.96%
- users9×0.96%
- access8×0.85%
- only8×0.85%
- professional8×0.85%
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!