plugin-icon

Loqwall 2FA

Lightweight Two-Factor Authentication with Email OTP and Authenticator App support. No bloat, no external services.
版本
1.0.0
最近更新:
Jul 19, 2026

Loqwall 2FA adds a secure second authentication step after the standard WordPress username/password login. After entering their credentials, users must verify their identity with a one-time code before gaining access.

Features

  • Email OTP — a 6-digit code is sent to the user’s registered email address.
  • Authenticator App (TOTP) — time-based codes compatible with Google Authenticator, Authy, Bitwarden, and any RFC 6238 app.
  • Backup codes — 10 one-time recovery codes generated per user.
  • Device trust — optionally remember a trusted device for up to 30 days.
  • Role enforcement — admins can be required to use 2FA regardless of their personal preference.
  • Per-user control — users enable and configure 2FA from their own profile page.
  • Rate limiting — brute-force protection on OTP verification.
  • Audit log — every authentication event is recorded in a private database table.
  • No external dependencies — all cryptographic operations use PHP’s built-in functions. No Composer, no remote APIs.
  • Developer-friendly — hooks and filters let you customise behaviour without modifying plugin files.

For Developers: Hooks & Filters

Filters

Loqwall_2FA_required_for_user

Runs on every login attempt. Return false to exempt a user, or true to force 2FA regardless of settings.

add_filter( 'Loqwall_2FA_required_for_user', function( $required, $user ) { // Exempt the user with ID 5 from 2FA. if ( 5 === $user->ID ) { return false; } return $required; }, 10, 2 ); Loqwall_2FA_otp_email_message

Filters the email body before the OTP is sent. Receives the body string, the WP_User object, the plain-text 6-digit code, and a boolean indicating whether the email is HTML.

add_filter( 'Loqwall_2FA_otp_email_message', function( $body, $user, $code, $html_mode ) { // Append a custom footer to every OTP email. return $body . '<p>Need help? Contact support@example.com</p>'; }, 10, 4 );

Actions

Loqwall_2FA_verified

Fires immediately after a user successfully passes 2FA. Receives the user ID and the method used ('email', 'totp', or 'backup_code').

add_action( 'Loqwall_2FA_verified', function( $user_id, $method ) { // Log the successful verification to a custom audit system. my_audit_log( $user_id, 'login_verified', $method ); }, 10, 2 ); Loqwall_2FA_failed

Fires after each failed 2FA verification attempt. Receives the user ID and the method attempted.

add_action( 'Loqwall_2FA_failed', function( $user_id, $method ) { // Notify an admin after a failed attempt. wp_mail( get_option('admin_email'), 'Failed 2FA attempt', "User #$user_id failed via $method." ); }, 10, 2 );<h3>Third Party Libraries</h3>

This plugin bundles the following third-party library:

qrcodejs * Author: Sangmin Shim (davidshimjs) * License: MIT * Source: https://github.com/davidshimjs/qrcodejs * Files: assets/js/qrcode.min.js, assets/js/qrcode.js * Purpose: Renders the QR code displayed during Authenticator App setup. Used entirely client-side; makes no external network requests.

目前已測試版本
WordPress 7.0.2
此外掛程式已可供下載,並可用於你 系統。