Aurora Membership Manager

Opis

Aurora Membership Manager is a free, self-contained membership management plugin built for associations, clubs, nonprofit organizations and other membership-based groups that want to manage members directly inside WordPress and securely from a phone with the Aurora Admin companion app.

The Core plugin works without an Aurora account, license key or external service. Member data stays in the site’s WordPress database, and Core updates are delivered only through WordPress.org.

What Core includes

  • Member records with contact details, status, reference numbers and expiry dates.
  • Configurable rolling or annual membership validity, including a selectable next-membership-year sales cutover for annual expiries.
  • Renewal overview for active, expiring and expired members.
  • Member search and a mobile-friendly staff workspace.
  • Secure Aurora Admin mobile access with one-time device pairing and revocable credentials.
  • Capability-controlled mobile member list, search, profile, creation and updates through the same Core rules used in WordPress.
  • Server-authoritative QR membership verification from the Aurora Admin scanner.
  • Least-privilege scanner credentials for staff or volunteers who should verify cards without receiving member administration access.
  • CSV import and export with spreadsheet-formula protection.
  • Secure member portal with opaque, expiring email access links.
  • Member profile and privacy-consent management.
  • WordPress personal-data exporter and eraser integration.
  • Backup, restore, reconciliation, diagnostics and audit tools owned by Core.
  • Stable hooks and APIs for separately installed extensions.

Manage members from your phone with Aurora Admin

Aurora Admin is the companion mobile app for day-to-day association work. A WordPress administrator pairs a phone with a short-lived, one-time code; the app never needs to store the WordPress password. The paired device receives revocable credentials and can only use the operations allowed to that WordPress user.

With the Core mobile API, authorized administrators can search and open member profiles, create members, update supported member information and verify membership cards by QR code from the phone. For entrance desks and events, a dedicated scanner-only credential can be given to staff or volunteers without exposing the member list or member-editing functions.

When the separately installed Membership Manager Pro extension is active, Aurora Admin can also use Pro’s event workflows to show the active event and register event check-ins from the QR scanner. Pro can additionally expose communications and other authorized operational tools to the app. Event management, event check-in storage and communications are Pro features and are not included in the free Core package.

Built for organizations that want to keep control

Aurora runs inside WordPress rather than moving your membership database to a separate closed platform. Core can be used on its own and does not require WooCommerce, a digital-card provider or a commercial Aurora license.

Optional extensions

Core remains fully usable without paid extensions. Separate add-on plugins are available when an organization needs additional workflows:

  • Membership Manager Pro — communications, campaigns, events, member benefits and Aurora Admin event check-in workflows.
  • Membership Manager Commerce — WooCommerce membership products, order-to-member workflows and renewals.
  • Membership Manager Digital Cards — Passcreator-based digital membership cards and wallet delivery workflows.

Aurora can also support organization-specific extensions for workflows that do not belong in Core or in a standard add-on. These separately installed extensions can combine reusable Aurora capabilities with rules, labels, mappings, templates or integrations tailored to one organization.

For example, an organization may need different digital-card templates according to age, membership type or role, or may have its own membership categories and operational workflow. Aurora keeps reusable capabilities generic while organization-specific behavior remains isolated in a separate extension rather than creating a fork of Core.

During the 2026 launch period, eligible associations and membership organizations can request no-cost access to the standard separately distributed add-ons until 31 December 2026. Early Adopter 2026 programme details

Explore optional extensions and regular pricing or contact Aurora about an organization-specific extension.

Standard and organization-specific extensions are separate plugins with their own code, configuration, licensing, external-service disclosures and update channels. They are not included in or unlocked by this WordPress.org package.

Documentation and support

  • Aurora documentation
  • For Core support, use the support forum available from this plugin’s WordPress.org page.

Privacy

Aurora Membership Manager can store member names, email addresses, membership status, expiry dates, profile details, consent choices and administrator audit events in the local WordPress database.

The public member portal can send an access email through the site’s configured WordPress mail system. Access links use opaque, expiring tokens. The plugin integrates with WordPress personal-data export and erasure tools.

When an administrator pairs the Aurora Admin companion app, Core can store device identification metadata, granted scopes and usage timestamps. The bearer-token secret itself is not stored in plaintext; Core stores a cryptographic hash used to validate the presented credential. Device credentials can be revoked from WordPress.

Site administrators are responsible for choosing an appropriate legal basis, retention period and privacy notice for their organization. Installing this plugin does not by itself make a site compliant with any privacy law.

External services

Aurora Membership Manager does not require or automatically contact an external service.

Separately installed extensions and the separately distributed Aurora Admin app may use their own external services or network connections. Those components must disclose their behavior, transmitted data, terms and privacy policy in their own documentation.

Zrzuty ekranu

Instalacja

  1. Install and activate Aurora Membership Manager from WordPress.org.
  2. Open Membership Manager > Initial configuration.
  3. Enter the organization name and choose the membership validity rule.
  4. Add members manually or import a CSV file.
  5. Optionally create a member portal page from Membership Manager > Settings > Member portal.
  6. To manage members from a phone, open Membership Manager > Aurora Admin and generate the short-lived pairing code for the Aurora Admin companion app.

No license key is required for the Core plugin.

Najczęściej zadawane pytania

Is Aurora Membership Manager really free?

Yes. Core is free and fully usable without a trial period, Aurora account or license key. Optional extensions are separate plugins.

What can I do with the Aurora Admin mobile app?

With Core, an authorized administrator can securely pair a phone, view and search members, open member profiles, create members, update supported member information and verify membership cards by QR code. Scanner-only credentials can be issued for staff or volunteers who only need card verification. With the separately installed Membership Manager Pro extension, the app can also register event check-ins and expose other Pro operational workflows according to the user’s permissions.

Does Core require WooCommerce?

No. Core works independently. WooCommerce is only needed if you separately install an extension that integrates WooCommerce workflows.

Does Core require a digital-card provider?

No. Digital-card providers are optional and are implemented by separate extensions.

Can Aurora be adapted to our organization?

Yes. Aurora exposes stable hooks and APIs so separately installed extensions can add organization-specific rules, mappings, integrations or workflows without modifying Core. Tailored extensions are separate from the free WordPress.org package and are evaluated according to the requested scope.

Does Aurora Admin need my WordPress password?

No. Core can generate a short-lived, one-time pairing challenge for the Aurora Admin companion app. The resulting device credential is revocable and limited to Aurora’s own mobile REST namespace and to the permissions of the WordPress user who paired it.

Does the plugin contact Aurora automatically?

No. The WordPress.org Core build does not contact Aurora, perform license checks or download executable code from external servers. Connecting the separately distributed Aurora Admin app is an explicit administrator action.

Where is member data stored?

Member records, profile metadata and Core audit records are stored in tables in the local WordPress database. Core settings are stored as WordPress options.

Can members access their own information?

Yes. Core includes an optional member portal that can send expiring access links through the site’s configured WordPress mail system. Site administrators control whether and how the portal is used.

What happens when I uninstall the plugin?

By default, membership data is preserved. Mobile device credentials are security state and are removed when Core is uninstalled. If Delete Core data when Core is uninstalled is enabled first, the uninstaller also removes Core-owned tables, options, files and roles. Data owned by separate extensions is never deleted by Core.

Recenzje

2026-08-24
We tested Aurora Membership Manager in a real association environment, together with the Pro, Commerce and Digital Cards add-ons. Our first impression was actually a little intimidating. Seeing membership management connected directly with WooCommerce and Passcreator made the initial setup look like something that might require considerable WordPress experience. That impression changed very quickly. Once we understood how the different modules work together, most of the configuration required only a few clicks and the logic became surprisingly clear. Even people in our team who have never professionally managed a WordPress website were able to understand the main workflows and work with the system. We particularly appreciated that WooCommerce, membership management and digital cards are connected without feeling like completely separate systems. We also contacted the developers during our testing and found them responsive to questions and practical feedback. There is a small learning curve at the beginning, especially when using several add-ons together, but once that initial step is overcome Aurora becomes much simpler than it first appears. A very promising solution for associations that want to manage memberships directly inside WordPress.
Przeczytaj 1 recenzje

Kontrybutorzy i deweloperzy

„Aurora Membership Manager” jest oprogramowaniem open source. Poniższe osoby miały wkład w rozwój wtyczki.

Zaangażowani

Rejestr zmian

1.3.4

  • Makes Aurora Admin practical for event entrances by adding dedicated least-privilege scanner credentials for authorized event/check-in staff without granting member-list or member-write access.
  • Adds dedicated checkins_read and checkins_write mobile scopes while preserving compatibility for existing administrator devices through the established member-scope fallback.
  • Allows authorized staff to create a one-time Aurora Admin pairing challenge from the Core staff workspace without requiring full membership-management privileges.
  • Keeps QR verification and event check-in authorization server-authoritative and re-evaluates the current WordPress user’s capabilities for every request.
  • Keeps the additive Aurora Mobile API contract at 1.2.0 and the Core database schema at 1.2.0; no re-pairing or database migration is required for existing administrator devices.

1.3.3

  • Adds a server-authoritative Aurora Admin QR verification endpoint using the existing paired-device credentials and member-management permissions.
  • Reuses existing Aurora membership/check-in QR identifiers instead of introducing a second QR standard, including member-specific URLs, mmc: values, member IDs, unambiguous email identifiers and external references.
  • Reloads the canonical Core member before every result and returns current membership status and expiry rather than trusting validity information carried by a QR payload.
  • Adds neutral and legacy-compatible resolver hooks for provider-specific QR identifiers while keeping Core independent from Digital Cards and Pro.
  • Adds capability-gated Aurora Admin member creation through the canonical Core repository, preserving server-owned identity fields and applying the configured Core expiry rule when no explicit expiry is supplied.
  • Keeps formal privacy-consent provenance out of mobile member creation while allowing supported communication preferences and profile fields to be stored through existing Core rules.
  • Advances the additive Aurora Mobile API contract to 1.2.0 while preserving existing members_write device credentials, so paired devices do not need to be paired again.
  • Changes no database schema and does not change the public Core add-on API contract.

1.3.2

  • Exposes the existing fixed-annual-expiry rollover policy in Initial configuration so an organization can choose the month from which new memberships and renewals use the next membership year.
  • Keeps the Core expiry engine as the single source of truth; no WooCommerce-specific expiry calculation or database schema change is introduced.
  • Preserves existing installations and defaults: annual memberships continue to roll to the next year from the configured threshold, with October as the historical default when the option has never been explicitly changed.

1.3.1

  • Fixes an early-load mobile bearer-authentication route check that could call WordPress REST URL helpers before rewrite initialization and fatally interrupt unrelated REST requests.
  • Keeps Aurora Admin bearer authentication restricted to the aurora-mobile/v1 namespace while allowing unrelated REST endpoints to operate normally during early WordPress bootstrap.
  • Restores compatibility for sites that run Core alongside independent REST services such as the Aurora License Server; no database schema or Core add-on API contract change.

1.3.0

  • Adds the native Aurora Admin REST API to Core for secure direct administration from compatible mobile clients.
  • Adds short-lived, one-time pairing challenges and revocable device credentials without storing WordPress passwords or plaintext bearer-token secrets.
  • Restricts device authentication to Aurora’s own mobile REST namespace and rechecks the paired WordPress user’s capabilities for every request.
  • Adds mobile member list, search and detail endpoints plus controlled member updates through the canonical Core repository, including supported profile and consent fields.
  • Protects integration-owned member identity fields from mobile editing and keeps existing Core validation, expiry and consent rules authoritative.
  • Adds paired-device management to the existing Core Admin App workspace.
  • Adds a controlled extension surface so separately installed add-ons can expose their own Aurora Admin capabilities and protected routes without being bundled into Core.
  • Corrects a translation-context annotation in the CSV import error path identified by Plugin Check.
  • No database schema change; the existing Core add-on API contract remains 2.0.0.

1.2.8

  • Documents organization-specific extensions as a supported way to add tailored rules and workflows without forking Core.
  • Adds one contextual extension-discovery panel to the Extensions screen with links to optional extensions and tailored-extension support.
  • Keeps commercial discovery limited to the Extensions screen: no global promotional notices, dashboard advertising, remote promotional assets, tracking or locked Core controls.
  • No database schema or public API contract changes.

1.2.7

  • Fix checkbox and radio sizing in the member editor.
  • Improve WordPress.org discovery tags and screenshot captions.
  • Confirm compatibility with WordPress 7.1 after final-release testing.
  • Clarifies that a saved renewal fee and currency are manual dashboard assumptions, while installed extensions may supply both values only when the fee is left blank.
  • Fix final CSV import button remaining disabled when valid rows are ready.
  • Prevent immediate import and backup-restore lock refreshes from being misreported as lost when their expiry value is unchanged within the same second.
  • Keep a retained CSV preview visible and renew its retry window when a recoverable final-import error occurs.
  • Keep member-bound portal tokens restricted to their original member identities.
  • Preserve extension-defined consent keys when Core consent fields are updated.
  • Report partial CSV write failures instead of treating them as skipped successful completion.
  • Fix the renewal onboarding completion condition.
  • Clean up Core schema/lock state completely when data deletion is requested on uninstall.

1.2.6

  • Refreshes the WordPress.org presentation, documentation and screenshot captions, and adds one public link to information about optional extensions. No runtime, API or database schema changes.

1.2.5

  • Removes promotional/storefront content from the WordPress administration while preserving the operational extension inventory and existing add-on hooks; no API or database schema changes.

1.2.4

  • Completes the WordPress.org review hardening by fixing translator annotations for backup/restore notices; no functional API or database schema changes.

1.2.3

  • Hardened Plugin Check handling for read-only backup/restore status notices; no functional API or schema changes.

1.2.2

  • Hardened request/upload handling for WordPress.org review while preserving Core/add-on contracts.
  • Normalized admin notice inputs and documented read-only request parameters for static analysis.

1.2.1

  • Aligns the WordPress.org text domain with the approved aurora-membership-manager slug.
  • Hardens Basic Setup upload hand-off so extension callbacks receive only explicitly registered and validated upload metadata, never the raw PHP upload superglobal.
  • Completes the review audit for request nonces, permissions and early input sanitization while preserving the Core 2.0.0 API contract.
  • Keeps Core free of commercial licensing and external update delivery; commercial add-ons remain separate plugins.

1.2.0

  • Introduces collision-resistant Aurora_MMC and aurora_mmc prefixes across Core APIs, hooks, options, capabilities, routes and interface identifiers.
  • Adds a conservative one-time migration for legacy Core tables, options and role capabilities while preserving existing add-on data.
  • Uses identifier placeholders for dynamic database table names on supported WordPress versions.
  • Removes inline administration JavaScript and strengthens direct output escaping.
  • Preserves legacy public shortcodes as compatibility aliases.
  • Publishes Core API contract 2.0.0 for the coordinated add-on releases.