콘텐츠로 바로가기
WordPress.org

한국어

  • 테마
  • 플러그인
  • 소식
    • 문서
    • 포럼
  • About
    • WordPress 6.9
    • 워드프레스 6.8
    • 워드프레스와 40% 웹을 위한 여정
    • 워드프레스 번역 핸드북
  • 워드프레스 한국팀
  • 워드프레스 받기
워드프레스 받기
WordPress.org

Plugin Directory

Digipacket Login Security with Two-Factor Authentication

  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인
  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인

Digipacket Login Security with Two-Factor Authentication

작성자: Digipacket
다운로드
  • 세부사항
  • 평가
  • 설치
  • 개발
지원

설명

Digipacket Login Security adds strong, standards-based two-factor authentication to any WordPress site. It uses the TOTP algorithm (RFC 6238), so it works with Google Authenticator, Authy, Microsoft Authenticator, FreeOTP and any standard authenticator app — with no external service or cloud dependency. Everything runs on your own server.

Key features

  • TOTP compatible with Google Authenticator and all standard apps.
  • Choice of method — each user picks an authenticator app (TOTP) or a one-time code sent by e-mail at login.
  • QR Code enrolment rendered locally on the user profile screen (no external image service).
  • Mandatory code verification after every login.
  • Single-use backup codes for account recovery if the device is lost.
  • Brute-force protection — lock an account after a configurable number of failed attempts, for a configurable duration. Blocks further sign-ins even with the correct password during the lockout window.
  • Security e-mail alerts — notify the account owner when repeated wrong-password attempts or too many incorrect 2FA codes are detected.
  • Login notifications — e-mail the user and/or the administrator (per selected roles) with sign-in details (user, date, IP, browser).
  • Login screen warning — optional full-screen security notice that visitors must accept before signing in.
  • Enforce 2FA by role with a configurable grace period.
  • Admin reset of a user’s 2FA from the Users list, plus a 2FA status column.
  • Audit log of all security events with filtering by role or user.
  • Modern admin interface — dashboard, focused settings tabs and an About page.
  • Translatable — ships with French (fr_FR) and English.

Privacy & external services

By default, Digipacket Login Security does not send any data to external services. All secrets, codes and logs are stored in your own WordPress database, and e-mails are sent through your site’s standard wp_mail() function.

Optional Telegram notifications (disabled by default): if you enable them and provide your own bot token and chat ID, the plugin sends security-event details (event type, username, IP address, date) to the Telegram Bot API at https://api.telegram.org so the message can be delivered to your chosen Telegram chat. This only happens while the feature is enabled and configured.

  • Telegram Bot API: https://core.telegram.org/bots/api
  • Telegram Privacy Policy: https://telegram.org/privacy

스크린샷

Security dashboard with 2FA adoption statistics.
Security dashboard with 2FA adoption statistics.
Access Policy settings — enforce 2FA by role and configure brute-force lockout.
Access Policy settings — enforce 2FA by role and configure brute-force lockout.
Notifications settings — security alerts and login notifications.
Notifications settings — security alerts and login notifications.
Audit log with filtering by role or user.
Audit log with filtering by role or user.
Two-factor enrolment on the user profile screen.
Two-factor enrolment on the user profile screen.

설치

  1. In WordPress, go to Plugins → Add New → Upload Plugin.
  2. Select digipacket-login-security.zip, click Install Now, then Activate.
  3. Go to Users → Profile and enable 2FA on your own account first.
  4. Configure site-wide options under Digipacket Login Security in the admin menu.

Manual installation: copy the digipacket-login-security folder into wp-content/plugins/ and activate it from the Plugins screen.

FAQ

Which authenticator apps are supported?

Any standard TOTP (RFC 6238) app: Google Authenticator, Authy, Microsoft Authenticator, FreeOTP, 1Password, and more.

Does it work without sending data to a third party?

Yes. Core 2FA has no external service or cloud dependency — the QR code is generated locally and all data stays on your server. The only optional exception is Telegram notifications, which are disabled by default and only contact api.telegram.org when you enable them with your own bot token (see Privacy & external services).

A user is locked out. How do I help them?

Administrators can reset a user’s 2FA from the Users list (the “Reset 2FA” row action), allowing them to enrol again.

My notification e-mails land in spam.

This is a mail-deliverability matter, not a plugin issue. Configure an SMTP plugin and set up SPF/DKIM/DMARC for your domain so messages are authenticated.

Does 2FA apply to REST API / XML-RPC / Application Passwords?

The interactive second factor applies to the browser login form. Non-interactive API authentication intentionally bypasses it — use Application Passwords for programmatic access.

후기

이 플러그인에 대한 평가가 없습니다.

기여자 & 개발자

“Digipacket Login Security with Two-Factor Authentication”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자
  • Digipacket

자국어로 “Digipacket Login Security with Two-Factor Authentication”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록을 RSS로 구독하세요.

변경이력

1.0.1

  • Fix: on a fresh install, the very first time the settings were saved the values were silently discarded (roles, brute-force options, Telegram token, etc.). Settings now save correctly from the first save.

1.0.0

  • Initial public release.
  • TOTP two-factor authentication (RFC 6238) compatible with Google Authenticator and all standard apps, plus an e-mail one-time-code method.
  • Local QR-code enrolment and single-use backup codes.
  • Enforce 2FA by role with a configurable grace period.
  • Configurable brute-force lockout (number of attempts and duration) with real sign-in enforcement.
  • Security e-mail alerts for repeated wrong-password attempts and 2FA lockouts.
  • Login notifications with sign-in details (user, date, IP, browser), scoped by role, to the user and/or administrator.
  • Optional login-screen security warning popup with a customizable message.
  • Audit log of security events with filtering by role or user.
  • Admin Dashboard “Security Overview” widget.
  • Reset 2FA and Ban / Unban actions from the Users list, with status badges.
  • Optional Telegram notifications for audit-log events, scoped by role/user, with one-click logout/ban response links.

기초

  • 버전 1.0.1
  • 최근 업데이트: 1개월 전
  • 활성화된 설치 10보다 적음
  • 워드프레스 버전 6.0 또는 그 이상
  • 다음까지 시험됨: 7.0.2
  • PHP 버전 8.2 또는 그 이상
  • 언어
    English (US)
  • 태그:
    2FABrute Forcelogin securitytotptwo factor authentication
  • 고급 보기

평점

아직 제출된 리뷰가 없습니다.

Your review

모든 리뷰 보기

기여자

  • Digipacket

지원

할 말 있으신가요? 도움이 필요하신가요?

지원 포럼 보기

  • 소개
  • 뉴스
  • 호스팅
  • 개인정보
  • 쇼케이스
  • 테마
  • 플러그인
  • 패턴
  • 배우기
  • 지원
  • 개발자 도구
  • WordPress.tv ↗
  • 참여하기
  • 이벤트
  • 기부하기 ↗
  • 미래를 위한 5가지
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

한국어

  • X(이전 트위터) 계정 방문하기
  • 블루스카이 계정 방문하기
  • 마스토돈 계정 방문하기
  • 스레드 계정 방문하기
  • 페이스북 페이지 방문하기
  • 인스타그램 계정 방문하기
  • LinkedIn 계정 방문하기
  • 틱톡 계정 방문하기
  • 유튜브 채널 방문하기
  • 텀블러 계정 방문하기
코드는 詩다
The WordPress® trademark is the intellectual property of the WordPress Foundation.