What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Yes—but WordPress does not provide a documented site-wide switch that automatically limits every account to one device. The practical approach is to limit active sessions: choose whether a second login should be refused or allowed to replace an existing session, then enforce that policy with a suitable plugin. WordPress core and WP-CLI can also revoke sessions, but those controls are manual rather than an automatic login limit.

What “one device” means in WordPress

WordPress manages authenticated sessions using session tokens. Limiting an account to one active session is a workable way to prevent concurrent logins, but it does not prove that a person is physically using only one device. A session policy governs logins; device binding is a separate approach that may identify a browser with a stored identifier.

Before choosing a solution, decide what should happen when a user signs in while another session is active. The right behavior depends on whether keeping the original session or allowing a convenient device switch matters more.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose what happens when a second login occurs

Policy What happens Useful when
Refuse the new login The existing session stays active, and the new login is denied once the limit is reached. You want to preserve the current session rather than let a new login take over.
Allow the new login and remove an older session The new login succeeds; an older session is ended to meet the configured limit. Users may legitimately switch devices and should not have to locate or sign out of the previous session first.
Keep only the latest login The newest session remains and the other sessions are terminated. You want a strict one-session-at-a-time rule where the latest login wins.

These are session-management behaviors, not proof of a user’s physical device identity. If the requirement is to bind an account to a set number of recognized devices, look specifically for device-binding functionality and review how it identifies devices.

What WordPress core and WP-CLI can do

WordPress core: revoke sessions, not enforce a site-wide cap

WordPress includes session-token functions for removing active sessions. The developer reference for wp_destroy_other_sessions() says it “Removes all but the current session token for the current user for the database.” The function operates on the current user’s session manager and token; the reference lists its introduction in WordPress 4.0.

The related session-token method can destroy all sessions except the one identified by a supplied token. If that token is not present, it destroys all sessions for that user. These are revocation tools; the references do not describe them as an automatic policy that blocks or replaces sessions whenever a user logs in.

WP-CLI: inspect or end sessions manually

WP-CLI’s user session commands can list a user’s sessions and destroy a specific session or all sessions for that user. This is useful for account recovery, support, or incident response. By itself, running a command is a manual action, not ongoing enforcement of a one-session limit.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Plugin approaches and their trade-offs

Plugin-directory descriptions outline several ways to implement session limits. They are publisher-provided feature descriptions, not independent verification of how a plugin behaves on a particular site. Check the current listing for compatibility, maintenance, support, pricing, and any license requirement before installing.

Plugin Described controls Best fit Important qualifications
SessionQuota A global concurrent-session limit, with options to block a new login, log out older session(s), or keep the latest login and remove the others. A straightforward site-wide session cap when one global rule is sufficient. The listing describes one global limit in the free edition. Role-based, membership-level, and per-user overrides are described as Pro features. The listing reported a release dated August 10, 2026 and compatibility with WordPress 7.1; verify the live listing because these details can change.
Sessions by PerfOps One Per-role limits based on user, IP, country, device class/type, client type, browser, or operating system; idle-session expiration, active-session reporting, and WP-CLI controls. Sites that need role-specific rules, session visibility, or limits based on network or client criteria. The listing says country criteria require the IP Locator plugin and device criteria require the Device Detector plugin. Confirm current dependencies and feature availability in the listing.
east115 Account Guard The listing describes ending other sessions, denying a login from another device while one is active, or binding an account to a configured number of devices. Sites considering a device-binding approach as well as session-kicking or login-denial behavior. The listing says device binding uses an anonymous device-identifier cookie and device-binding timestamps in user metadata. These are vendor-published feature and privacy statements; review current behavior and disclosures before use.

Choose based on the policy you need and how much control administrators require. A global limit may be enough for a small site. Sites with different rules by role, session reporting needs, or device-identification requirements should confirm those features and their dependencies before committing.

Set up the policy without locking users out unexpectedly

  1. Choose the login behavior. Decide whether a second login must be refused, may replace an older session, or should terminate every session except the newest.
  2. Match the plugin to the scope. Confirm that it supports the required global, role-based, membership-level, or per-user controls, and check whether any needed feature requires a paid license or companion plugin.
  3. Test with a low-risk account. Configure the policy for a test account and sign in through two separate browsers or devices. Confirm which session remains active and what message appears when a login is denied or displaced.
  4. Plan recovery. Tell users that a device switch may require signing in again on a previous device. Administrators should know how to inspect or revoke sessions using the selected plugin or WP-CLI before applying a strict policy broadly.
  5. Review upkeep and privacy. Check compatibility with the site’s WordPress version, recent maintenance and support activity, and the plugin’s privacy disclosures—especially if its rules depend on device, browser, IP, or country information.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What users and administrators should expect

With a block-new-login rule, the user may need to return to the active device and sign out before logging in elsewhere, depending on the plugin’s behavior. With a replace-old-session rule, a user signed in on another device may be logged out when a new login succeeds. Administrators can use session reporting, where available, or WP-CLI’s listing and destruction commands to help resolve access problems.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.