![]() phone, tablet) – so, someone can’t get into your website without getting hold of your device. Usually, this is a code that comes to a device you own (e.g. “Two factor” means adding a second requirement. If that’s broken, then everything’s wide open. This plugin began life in early 2015 as a friendly fork and enhancement of Oscar Hane’s “two factor auth” plugin.įAQ What is two factor authentication (TFA / 2FA) ?īasically, it’s to do with securing your logins, so that there’s more than one link in the chain needing to be broken before an unwanted intruder can get in your website.īy default, your WordPress accounts are protected by only one thing: your password. Google Authenticator, etc.) will show a different code every so often. These are used by Google Authenticator, Authy, and many other OTP applications that you can deploy on your phone etc.Ī TOTP code is valid for a certain time. This plugin uses the industry standard TFA / 2FA algorithm TOTP or HOTP for creating One Time Passwords. Administrators can access other users’ codes, and turn them on/off when needed ( Premium version).Works together with “WP Members” (shortcode form).When using the front-end shortcode ( Premium version), require the user to enter the current TFA code correctly to be able to activate TFA.Emergency codes for when you lose your phone/tablet ( Premium version).Alert users if someone appears to have found out their password, as indicated by successfully entering a password but repeatedly entering an incorrect TFA code.Added a number of extra security checks to the original forked code. ![]() Simplified user interface and code base for ease of use and performance.WP Multisite compatible (plugin should be network activated).nothing is shown to users who do not have it enabled) Does not mention or request second factor until the user has been identified as one with TFA enabled (i.e.Includes support for any and every third-party login form (Premium version) without any further coding needed via appending your TFA code to the end of your password.Includes support for login forms from the Gravity Forms User Registration add-on (Premium version).Includes support for bbPress login forms (Premium version).Includes support for Elementor Pro login forms (Premium version).Includes support for CozmosLabs Profile Builder.Includes support for the WooCommerce and Affiliates-WP login forms.Works together with “Theme My Login” (both forms and widgets).Encrypt the TFA-generating secret keys using an on-disk encryption key, so that an attacker would need to break into both your WordPress database and your files in order to break TFA codes (as well as breaking a user’s password in order to use them).Site owners can allow “trusted devices” on which TFA codes are only asked for a chosen number of days (instead of every login) e.g.(The Premium version allows custom designing of any layout you wish). users don’t need access to the WP dashboard). Supports front-end editing of settings, via shortcode (i.e.require all admins to have TFA, once their accounts are a week old) ( Premium version), including forcing them to immediately set up (by redirecting them to the page to do so) TFA can be required for specified user levels, after a defined time period (e.g.TFA can be turned on or off by each user.available for admins, but not for subscribers) TFA can be made available on a per-role basis (e.g.Displays graphical QR codes for easy scanning into apps on your phone/tablet.Supports standard TOTP + HOTP protocols (and so supports Google Authenticator, Authy, and many others).From the authors of UpdraftPlus – WP’s #1 backup/restore plugin, with over two million active installs.Īre you completely new to TFA? If so, please see our FAQ.įeatures (please see the “Screenshots” for more information): Users for whom it is enabled will require a one-time code in order to log in. Secure WordPress login with this two factor authentication (TFA / 2FA) plugin.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |