Beskrivning
With WP-OTP you can easily set up 2 Factor Authentication with One Time Passwords for your WordPress login.
This extra layer makes your WordPress site a lot more secure.
The new stealth mode allows for invisible OTP code entry, making your login screen look like any other, no extra OTP code input field.
Komma igång
After installing and activating the plugin, every user can enable WP-OTP on their profile page.
It’s as easy as scanning the provided QR Code or entering the OTP secret to any OTP generator app.
Then just activate it by entering the generated OTP and voilà, all set up.
Now, the login requires an OTP code to succeed.
Each user gets their own secret key to authenticate with, giving them control over their login security.
Utveckling
This plugin is completely open source and a work of passion.
If you would like to be part of it and join in, make your way over to the project page now.
Also, if you have an idea you would like to see in this plugin or if you’ve found a bug, please let me know.
Configuration
WP_OTP_STEALTH
: Set this totrue
to enable stealth OTP mode.
Filter
There are a multitude of filters to be adjusted.
wp_otp_qr_code_provisioning_uri
: URI for online QR Code rendering (must contain{PROVISIONING_URI}
placeholder for QR Code data).wp_otp_login_form_text
: Text för inmatningsfält på inloggningsskärmen.wp_otp_login_form_text_sub
: Subtext for the input field on the login screen.wp_otp_login_form_invalid_code_text
: Error text for an invalid code input on the login screen.wp_otp_code_expiration_window
: Set the window of code verification expiration.wp_otp_recovery_codes_count
: Number of recovery codes to generate.wp_otp_recovery_codes_length
: Length of the recovery codes.wp_otp_secret_length
: Length of the secret key.
Minimikrav
WordPress 4.6, PHP 7.4.
Donate / Support
All donations are much appreciated, thank you 🙏
Get professional support for this plugin with a Tidelift subscription
Tidelift helps make open source sustainable for maintainers while giving companies assurances about security, maintenance, and licensing for their dependencies.
Security
To report a security vulnerability, please use the Tidelift security contact. Tidelift will coordinate the fix and disclosure.
Installation
You can either use the built in WordPress installer or install the plugin manually.
För automatisk installation:
- Go to ’Plugins -> Add New’ on your WordPress Admin page.
- Search for the ’WP OTP’ plugin.
- Installera genom att klicka på knappen ”Installera nu”.
- Activate the plugin on the ’Plugins’ page in your WordPress Admin.
För manuell installation:
- Ladda upp ”wp-otp”-mappen till tilläggskatalogen för din WordPress-installation.
- Activate the plugin on the ’Plugins’ page in your WordPress Admin.
Vanliga frågor
-
Vad händer om jag förlorar min OTP-autentiserare?
-
No problem! When activating WP-OTP, you will also get a list of recovery codes that you can use instead of entering the OTP from your authenticator app.
Be sure to regenerate them when you run out though, or better yet, reconfigure your WP-OTP to get a new secret and a new set of recovery codes. -
Kan jag återställa min OTP hemliga nyckel?
-
Yes, just click the
Reconfigure
button on the profile page. -
Why is there no OTP input field on the login form?
-
Your site admin has either disabled the plugin or enabled stealth mode.
This means that you will need to add your OTP (or recovery) code at the end of your password.
Recensioner
Bidragsgivare och utvecklare
”WP-OTP” är programvara med öppen källkod. Följande personer har bidragit till detta tillägg.
Bidragande personer”WP-OTP” har översatts till 5 språk. Tack till översättarna för deras bidrag.
Översätt ”WP-OTP” till ditt språk.
Intresserad av programutveckling?
Läs programkoden, kika på SVN-filförvaret eller prenumerera på utvecklarloggen via RSS.
Ändringslogg
0.6.1
- Fix nonce issue when saving profile.
0.6.0
- Require at least PHP 7.4 and update all code.
- Allow for PHP 8.0.
- Bump dependencies.
0.5.1
- Fix activation and deactivation hooks.
0.5.0
- Require at least PHP 7.2.
- Update OTPHP to 10.0.
- Add native QR code rendering.
- Harden security by adhering to WordPress Code Sniffer.
0.4.1
- Fix nullable return type when checking if OTP is enabled.
0.4.0
- Drop all custom i18n and rely on translate.wordpress.org.
- Minimum requirements are now WP 4.6 and PHP 7.1.
- Update OTPHP to 9.1.
- Tested for WP 5.3.
0.3.0
- Update list of OTP mobile apps.
- Add stealth mode (via WP_OTP_STEALTH), passing OTP code concatenated to password.
- Add donation, support and security sections to readme.
0.2.1
- Add GitLab CI for PHP Code Sniffer.
- Fix changed Base32 namespace.
0.2.0
- Testad för WP 5.0.
- Update OTPHP to 8.3.3.
- Moved project to Feneas GitLab (git.feneas.org)
0.1.4
- Testad för WP 4.8.
- Uppdatera OTPHP till 8.3.0.
0.1.3
- Make OTP code input a normal text field, to allow input verification.
0.1.2
- Add proper localisation.
0.1.1
- Längre hemlighet som standard.
- Replace/override packages not compatible with WordPress.
0.1.0
- Första versionen!