PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchA WordPress nonce is a time-limited token that helps protect a request from cross-site request forgery (CSRF). Despite the name, it is not a one-time-use token: it can be accepted repeatedly while valid. A nonce also does not prove a user has permission to perform an action, so code that processes a request must check both the nonce and the user’s capability.
What a WordPress nonce does
CSRF occurs when a site is induced to send a request that a user did not intend—for example, an action submitted through the browser while the user is signed in. A WordPress nonce gives the request handler a way to check that the request includes a token associated with the intended action. This helps defend against forged requests, but it is not a complete security system.
WordPress’s use of “nonce” differs from the strict cryptographic meaning of a number used once. A WordPress nonce can be reused during its validity period; it is not checked for one-time use and does not prevent replay attacks. The WordPress Common APIs Handbook explains both the CSRF purpose and this limitation.
What a nonce does not do
Nonce verification is not authentication, authorization, or access control. It does not identify a user or establish that the user may carry out the requested operation. After validating the nonce, check the relevant capability, usually with current_user_can(), before making the change. WordPress explicitly advises that nonces should not be relied on for authentication, authorization, or access control.
#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
For example, a request to delete a post should validate a nonce tied to that deletion and the relevant post, then independently confirm that the current user can delete that post. A valid token alone is not permission to delete it.
How long a WordPress nonce lasts
The default nonce life is a 24-hour interval, but that does not mean every nonce is valid for exactly 24 hours. WordPress divides the interval into two ticks and accepts the current tick and the previous one. With the default interval, a nonce’s usable window is just over 12 hours at its shortest and up to 24 hours, depending on when it was created relative to a tick boundary.
Rank #2
- Time- and headache-saving little volume is organized with tabbed A to Z pages, with space on each page to write down websites, usernames, passwords, and notes.
wp_verify_nonce() returns 1 when the nonce matches the current tick, 2 when it matches the previous tick, and false when it is invalid or expired. The nonce_life filter can change the interval; changing it affects security-relevant behavior and should be done deliberately. See the WordPress nonce documentation and the WordPress Developer Blog’s explanation of nonce ticks.
Creating and checking a nonce for a form
Add the hidden field
Use wp_nonce_field() to print a hidden input containing a nonce. Give it an action string that describes the operation; where useful, include the target object so tokens for different objects are not interchangeable.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →wp_nonce_field( 'delete_post_' . $post_id, 'delete_post_nonce' );
By default, the function also prints a referrer field. The action and field name are choices your code makes; use the same action when validating the submitted value. Details are in the Common APIs Handbook and the wp_nonce_field() reference.
Validate before processing
For an admin form or URL, check_admin_referer() checks the nonce and referrer and terminates with a forbidden response on failure by default. Then check the user’s capability before carrying out the operation.
Rank #4
- Used Book in Good Condition
if ( ! current_user_can( 'delete_post', $post_id ) ) {
wp_die( 'You are not allowed to delete this post.' );
}
check_admin_referer( 'delete_post_' . $post_id, 'delete_post_nonce' );
// Perform the authorized operation.
Keep request validation and authorization distinct: the nonce checks the request token; the capability check checks whether the user may act.
Choosing the right helper for the request
| Request context | Nonce helper | What it checks or returns |
|---|---|---|
| Admin form or URL | check_admin_referer() |
Checks the nonce and referrer; terminates on failure by default. |
| AJAX request | check_ajax_referer() |
Checks the nonce, not the referrer; terminates on failure by default. |
| Custom request or validation flow | wp_verify_nonce() |
Returns 1, 2, or false; your code must stop processing when validation fails. |
| Nonce in a URL | wp_nonce_url() |
Adds a nonce for the specified action to a URL. |
| Custom transport or context | wp_create_nonce() |
Returns a nonce for the specified action. |
Use an action string that identifies the operation, and validate against that same string. Consult the nonce handbook for function behavior and arguments. Whichever helper fits the request, a separate capability check is still required for protected operations.
Best Value
Nonces in AJAX and REST API requests
AJAX
For AJAX handlers, send a nonce with the request and validate it with check_ajax_referer(). That helper does not check the referrer. If validation fails, it terminates by default; the handler must still check whether the current user is allowed to perform the requested action.
REST API cookie authentication
For REST API requests authenticated with WordPress cookies, WordPress uses the action wp_rest to mitigate CSRF. Without the nonce, the request is treated as unauthenticated even if the user is logged in. The REST API authentication handbook recommends using the built-in JavaScript API, which handles transmitting the nonce.
Logged-out visitors and guest nonces
By default, WordPress uses user ID 0 when generating nonces for logged-out users. As a result, guests share the same default identity for nonce generation; the default does not give each visitor a unique guest nonce. Sites that need guest-specific behavior must add a guest-session mechanism rather than assuming the built-in default distinguishes visitors. For logged-in users, a nonce is tied to the user context, but it still does not replace permission checks.
Handle submitted nonce values carefully
When reading a nonce from request input, follow WordPress guidance to unslash and sanitize the value before verification. The verification function is pluggable, so do not treat raw request input as inherently trustworthy. See the Common APIs Handbook for nonce validation guidance.
Quick Recap
Common nonce mistakes
- Calling it one-time-use: WordPress accepts a nonce repeatedly while it remains valid.
- Assuming every nonce lasts exactly 24 hours: the default acceptance window varies with the two-tick boundary.
- Treating verification as authorization: check the user’s capability separately before performing the action.
- Assuming guests have unique default nonces: logged-out users share user ID
0unless the site adds a guest-session mechanism. - Assuming REST cookie authentication works without a nonce: without the
wp_restnonce, WordPress treats the request as unauthenticated.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

