콘텐츠로 바로가기
WordPress.org

한국어

  • 테마
  • 플러그인
  • 소식
    • 문서
    • 포럼
  • About
    • WordPress 6.9
    • 워드프레스 6.8
    • 워드프레스와 40% 웹을 위한 여정
    • 워드프레스 번역 핸드북
  • 워드프레스 한국팀
  • 워드프레스 받기
워드프레스 받기
WordPress.org

Plugin Directory

Logliy – Login Protect (Passkey, Email, SSO)

  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인
  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인

Logliy – Login Protect (Passkey, Email, SSO)

작성자: flobamedia
다운로드
  • 세부사항
  • 평가
  • 설치
  • 개발
지원

설명

Logliy – Login Protect controls how users sign in: Passkeys (WebAuthn) first, with Email one-time codes and Magic Links as fallback, plus optional SSO (OpenID Connect) and an optional password path.

It is not a security suite and not a generic OTP plugin. Keep Wordfence (or similar) for WAF, brute-force lockouts, CAPTCHA, malware scanning, and classic TOTP 2FA. Logliy is the login-method layer on top.

Features

  • Passkey login and registration (discoverable credentials, Conditional UI where available)
  • Email OTP login via wp_mail
  • Magic link (one-click email) login
  • Optional SSO via OpenID Connect (shown on the login form only when fully configured)
  • Password login off by default, re-enable site-wide and/or per role / per user
  • Role-based login/logout redirects
  • Optional custom login URL (auto-disabled if WPS Hide Login or similar is active)
  • Session length, Remember-me duration, admin idle timeout, logout everywhere
  • Users overview (Passkeys + last login)
  • Optional custom login logo, brand, background, and footer
  • Modern login UI on wp-login.php
  • WooCommerce classic + Blocks My Account/Checkout login forms
  • Cloudflare Turnstile compatible (verifies tokens on Passkey / Email OTP / Magic Link / SSO login)
  • REST API namespace logliy/v1
  • Rate limits for OTP, Passkey, and SSO auth
  • Wordfence-friendly: fires wp_login_failed / wp_login and uses normal auth cookies
  • Emergency override: define( 'LOGLIY_ALLOW_PASSWORD', true ); in wp-config.php

Wordfence compatibility

  • Failed Logliy attempts trigger wp_login_failed so Wordfence lockouts still apply
  • Successful Logliy logins use wp_set_auth_cookie + wp_login like a normal wp_signon
  • Wordfence IP lockouts still run during passwordless login; Wordfence Login Security 2FA is skipped for Passkey / Email OTP / Magic Link / SSO (those methods already replace the password)
  • Wordfence TOTP 2FA continues to apply on the classic password path
  • Logliy does not remove Wordfence hooks globally — only suspends LS 2FA for the passwordless completion step

Cloudflare Turnstile

When Simple CAPTCHA with Cloudflare Turnstile (or equivalent) is enabled on the WordPress login form, Logliy requires a valid Turnstile token for Email OTP, Passkey, Magic Link, and SSO login. The password path continues to use the Turnstile plugin’s own authenticate check.

WooCommerce

  • Classic My Account and Checkout login templates
  • Guest checkout unchanged
  • Does not block WooCommerce REST / Store API authentication
  • Optional panel above Checkout and Customer Account blocks for guests

Requirements

  • PHP 8.1+
  • WordPress 6.4+
  • HTTPS for Passkeys (localhost allowed for development)
  • Composer production dependencies are vendored in release builds (vendor-prefixed/)

External services

This plugin can contact Cloudflare Turnstile only when a compatible Turnstile plugin is active and configured for the WordPress login form. Logliy does not load Turnstile by itself.

When a visitor completes passwordless login (Passkey, Email OTP, Magic Link, or SSO) while Turnstile is required, Logliy sends the Turnstile response token and the visitor IP to Cloudflare’s siteverify API so the challenge can be validated. No other personal data is sent to Cloudflare by Logliy.

This service is provided by Cloudflare: Terms of Use and Privacy Policy.

When SSO (OpenID Connect) is enabled, Logliy contacts the OpenID Provider you configure (Issuer / discovery, token, and JWKS URLs) so visitors can sign in with that identity provider. Logliy does not send login data to FloBa Media. The identity provider receives standard OpenID Connect authentication data (such as the authorization request and, after sign-in, token exchange). Which personal data that provider stores is defined by that provider.

You must register this site’s Redirect URI at the provider and accept that provider’s own terms of service and privacy policy before enabling SSO.

설치

  1. Upload the logliy folder to /wp-content/plugins/
  2. Activate Logliy – Login Protect (Passkey, Email, SSO)
  3. Open Settings → Logliy
  4. Register a Passkey on your profile and/or test Email OTP before relying on passwordless-only mode
  5. Optionally enable SSO under the SSO tab (login form shows it only when fully configured)
  6. Optionally set a custom login logo / brand name under General
  7. Optionally enable password login again under General

FAQ

How do I enable SSO?

Open Settings → Logliy → SSO. Enable SSO and enter your OpenID Provider Issuer URL, Client ID, and Client Secret. Register the shown Redirect URI at the provider. The SSO tab appears on the login form only when those three fields are set. ID tokens must be signed with RS256. New WordPress users are not created unless you turn on Create users.

I locked myself out

Add to wp-config.php:

define( 'LOGLIY_ALLOW_PASSWORD', true );

Then sign in with your password and adjust Logliy settings.

Does this replace Wordfence?

No. Logliy is the login method layer. Wordfence remains your WAF / lockout / scanner layer.

Application Passwords / WP-CLI / XML-RPC

Application Passwords and WP-CLI are not blocked by the password policy.
With password login off, XML-RPC authentication with the account password is blocked by default (affects the WordPress mobile app, Jetpack, and some backup tools). Enable Allow XML-RPC passwords under Logliy → General if a tool still requires it. Prefer Application Passwords when the client supports them.

후기

이 플러그인에 대한 평가가 없습니다.

기여자 & 개발자

“Logliy – Login Protect (Passkey, Email, SSO)”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자
  • flobamedia

자국어로 “Logliy – Login Protect (Passkey, Email, SSO)”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록을 RSS로 구독하세요.

변경이력

0.1.1

  • Fix: SSO no longer fails with “denied” when Cloudflare Turnstile is enabled on the login form

0.1.0

  • Optional SSO login via OpenID Connect (authorization code + PKCE). Shown on the login form only when fully configured.
  • Plugin name updated to include SSO

0.0.9

  • Tested up to WordPress 7.1

0.0.8

  • Remove arbitrary custom CSS from settings (use Additional CSS instead)
  • Enqueue remember-me check via login.js; drop inline script tag
  • Document Cloudflare Turnstile as an external service (terms + privacy)
  • Stop bundling .po/.mo and vendor PHPUnit helpers; include composer.json
  • WordPress.org loads translations automatically (no load_plugin_textdomain)
  • Limit admin notices to Logliy settings / profile screens

0.0.7

  • Ignore leftover Turnstile DB options when the Captcha plugin is not active (fixes false CAPTCHA block)
  • Show plugin version on settings page; remove duplicate “settings saved” notice

0.0.6

  • Captcha only required when Cloudflare Turnstile is enabled and configured; sites without Captcha are not blocked
  • Fix Advanced settings save (nested import form) and add Save button at top

0.0.5

  • Settings import/export (JSON) for cloning config between sites
  • Vendor namespaces prefixed with Strauss (Logliy) to avoid Symfony conflicts
  • Passwordless login skips Wordfence 2FA (lockouts still apply); Wordfence 2FA remains on password path
  • Optional “Allow XML-RPC passwords” (off by default) when password login is disabled
  • Atomic rate-limit DB table (no option-lock); OTP HMAC bound to user; safer settings import

0.0.4

  • Security: password policy applies to XML-RPC; REST exemption limited to Application Passwords
  • Security: passwordless login runs authenticate / wp_authenticate_user before cookies (Wordfence lockouts)
  • Privacy: system font stack instead of Google Fonts CDN
  • Hardening: account cooldown/rate-limit responses no longer enumerate users; atomic rate-limit buckets; OTP HMAC

0.0.3

  • Fix: Divi fatal when hiding wp-admin (no theme 404 template during early init)

0.0.2

  • Magic link, custom login URL, redirects, sessions, users overview, WC blocks, branding extras

0.0.1

  • Initial pre-release: Passkeys, Email OTP, password policy (default off), wp-login + WooCommerce classic
  • Admin settings, profile Passkey management, Cloudflare Turnstile compatibility
  • Optional login branding (logo / name / tagline); DE/EN i18n
  • Auth hardening: no OTP enumeration, redirect validation, Turnstile token verify, rate limits

기초

  • 버전 0.1.1
  • 최근 업데이트: 1주 전
  • 활성화된 설치 10+
  • 워드프레스 버전 6.4 또는 그 이상
  • 다음까지 시험됨: 7.1.1
  • PHP 버전 8.1 또는 그 이상
  • 언어
    English (US)
  • 태그:
    loginotppasskeypasswordlesssso
  • 고급 보기

평점

아직 제출된 리뷰가 없습니다.

Your review

모든 리뷰 보기

기여자

  • flobamedia

지원

할 말 있으신가요? 도움이 필요하신가요?

지원 포럼 보기

  • 소개
  • 뉴스
  • 호스팅
  • 개인정보
  • 쇼케이스
  • 테마
  • 플러그인
  • 패턴
  • 배우기
  • 지원
  • 개발자 도구
  • WordPress.tv ↗
  • 참여하기
  • 이벤트
  • 기부하기 ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

한국어

  • X(이전 트위터) 계정 방문하기
  • 블루스카이 계정 방문하기
  • 마스토돈 계정 방문하기
  • 스레드 계정 방문하기
  • 페이스북 페이지 방문하기
  • 인스타그램 계정 방문하기
  • LinkedIn 계정 방문하기
  • 틱톡 계정 방문하기
  • 유튜브 채널 방문하기
  • 텀블러 계정 방문하기
코드는 詩다
The WordPress® trademark is the intellectual property of the WordPress Foundation.