Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Make your WordPress login extra secure with One Time Passwords.
WP-OTP is a WordPress plugin that enables two-factor authentication using one-time passwords (OTPs) for enhanced security during login. After installation, users can activate the feature on their profile page by scanning a QR code or entering a secret key into an OTP generator app. This setup requires users to enter an OTP code along with their password for login, providing an additional layer of security.
The plugin offers a stealth mode that conceals the OTP input field, making the login screen appear standard. Users can also configure various settings, such as the expiration window for OTP codes and the generation of recovery codes. It is suitable for anyone looking to improve the security of their WordPress site through two-factor authentication.
Best for: This plugin is best for WordPress site owners seeking to enhance their login security.
What it does well
Where it falls short
WP-OTP provides a straightforward solution for implementing two-factor authentication. However, the lack of recent updates may be a concern for some users.
noplanman's own description of WP-OTP, lightly tidied.
With WP-OTP you can easily set up 2 Factor Authentication with One Time Passwords for your WordPress login.
This extra layer makes your WordPress site a lot more secure.
The new stealth mode allows for invisible OTP code entry, making your login screen look like any other, no extra OTP code input field.
After installing and activating the plugin, every user can enable WP-OTP on their profile page.
It’s as easy as scanning the provided QR Code or entering the OTP secret to any OTP generator app.
Then just activate it by entering the generated OTP and voilà, all set up.
Now, the login requires an OTP code to succeed.
Each user gets their own secret key to authenticate with, giving them control over their login security.
This plugin is completely open source and a work of passion.
If you would like to be part of it and join in, make your way over to the project page now.
Also, if you have an idea you would like to see in this plugin or if you’ve found a bug, please let me know.
WP_OTP_STEALTH: Set this to true to enable stealth OTP mode.There are a multitude of filters to be adjusted.
wp_otp_qr_code_provisioning_uri: URI for online QR Code rendering (must contain {PROVISIONING_URI} placeholder for QR Code data).wp_otp_login_form_text: Text for input field on the login screen.wp_otp_login_form_text_sub: Subtext for the input field on the login screen.wp_otp_login_form_invalid_code_text: Error text for an invalid code input on the login screen.wp_otp_code_expiration_window: Set the window of code verification expiration.wp_otp_recovery_codes_count: Number of recovery codes to generate.wp_otp_recovery_codes_length: Length of the recovery codes.wp_otp_secret_length: Length of the secret key.WordPress 4.6, PHP 7.4.
Other plugins for securing a site.
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...