plugin-icon

Loqwall 2FA

Lightweight Two-Factor Authentication with Email OTP and Authenticator App support. No bloat, no external services.
Sürüm
1.0.0
Son güncellenme
Jul 19, 2026

Loqwall 2FA adds a secure second authentication step after the standard WordPress username/password login. After entering their credentials, users must verify their identity with a one-time code before gaining access.

Features

  • Email OTP — a 6-digit code is sent to the user’s registered email address.
  • Authenticator App (TOTP) — time-based codes compatible with Google Authenticator, Authy, Bitwarden, and any RFC 6238 app.
  • Backup codes — 10 one-time recovery codes generated per user.
  • Device trust — optionally remember a trusted device for up to 30 days.
  • Role enforcement — admins can be required to use 2FA regardless of their personal preference.
  • Per-user control — users enable and configure 2FA from their own profile page.
  • Rate limiting — brute-force protection on OTP verification.
  • Audit log — every authentication event is recorded in a private database table.
  • No external dependencies — all cryptographic operations use PHP’s built-in functions. No Composer, no remote APIs.
  • Developer-friendly — hooks and filters let you customise behaviour without modifying plugin files.

For Developers: Hooks & Filters

Filters

Loqwall_2FA_required_for_user

Runs on every login attempt. Return false to exempt a user, or true to force 2FA regardless of settings.

add_filter( 'Loqwall_2FA_required_for_user', function( $required, $user ) { // Exempt the user with ID 5 from 2FA. if ( 5 === $user->ID ) { return false; } return $required; }, 10, 2 ); Loqwall_2FA_otp_email_message

Filters the email body before the OTP is sent. Receives the body string, the WP_User object, the plain-text 6-digit code, and a boolean indicating whether the email is HTML.

add_filter( 'Loqwall_2FA_otp_email_message', function( $body, $user, $code, $html_mode ) { // Append a custom footer to every OTP email. return $body . '<p>Need help? Contact support@example.com</p>'; }, 10, 4 );

Actions

Loqwall_2FA_verified

Fires immediately after a user successfully passes 2FA. Receives the user ID and the method used ('email', 'totp', or 'backup_code').

add_action( 'Loqwall_2FA_verified', function( $user_id, $method ) { // Log the successful verification to a custom audit system. my_audit_log( $user_id, 'login_verified', $method ); }, 10, 2 ); Loqwall_2FA_failed

Fires after each failed 2FA verification attempt. Receives the user ID and the method attempted.

add_action( 'Loqwall_2FA_failed', function( $user_id, $method ) { // Notify an admin after a failed attempt. wp_mail( get_option('admin_email'), 'Failed 2FA attempt', "User #$user_id failed via $method." ); }, 10, 2 );<h3>Third Party Libraries</h3>

This plugin bundles the following third-party library:

qrcodejs * Author: Sangmin Shim (davidshimjs) * License: MIT * Source: https://github.com/davidshimjs/qrcodejs * Files: assets/js/qrcode.min.js, assets/js/qrcode.js * Purpose: Renders the QR code displayed during Authenticator App setup. Used entirely client-side; makes no external network requests.

Ücretsiz(ücretli paketlerde)
Kurulum işlemini tamamlayarak, WordPress.com'un Hizmet Şartları ile Üçüncü Taraf Eklenti Şartlarını kabul etmiş olursunuz.
Test edilen son sürüm
WordPress 7.0.2
Bu eklenti, sitenizde kullanılmak üzere indirilebilir.