콘텐츠로 바로가기
WordPress.org

한국어

  • 테마
  • 플러그인
  • 소식
    • 문서
    • 포럼
  • About
    • WordPress 6.9
    • 워드프레스 6.8
    • 워드프레스와 40% 웹을 위한 여정
    • 워드프레스 번역 핸드북
  • 워드프레스 한국팀
  • 워드프레스 받기
워드프레스 받기
WordPress.org

Plugin Directory

Riverbox Passwordless Login

  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인
  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인

Riverbox Passwordless Login

작성자: riverbox
다운로드
  • 세부사항
  • 평가
  • 설치
  • 개발
지원

설명

Riverbox replaces passwords with modern, frictionless login. Users sign in with a one-time code, a magic link, a passkey, or their phone number — and new visitors can get an account automatically.

Login methods

  • Email one-time codes — type your address, get a short code, you’re in.
  • Magic links — one-click login links by email; single-use and expiring.
  • Passkeys (WebAuthn) — sign in with a fingerprint, face, or security key. Includes an account page ([riverbox-account]) where users manage their devices. No external services; the WebAuthn ceremony is verified on your own server.
  • Phone one-time codes — SMS login through your own HTTP SMS gateway ({{to}}/{{message}} placeholder templates).
  • Password — classic login can stay available alongside the passwordless methods.

Security

  • Codes stored only as hashes, with expiry, attempt caps, and resend cooldowns.
  • Per-IP and per-identifier rate limiting; responses never reveal whether an account exists.
  • Magic links are single-use and blocked for accounts that require multi-factor login.
  • A delivery log records every code dispatch with the raw gateway response.

Developer friendly

  • REST API under riverbox/v1 (/begin, /verify, passkey endpoints) built on an extensible authentication-factor architecture — every method is a “factor”, and login flows are factor chains.
  • Documented hooks: riverbox_register_factors, riverbox_login_chain, riverbox_otp_sent, riverbox_logged_in, riverbox_login_redirect, riverbox_user_created, plus settings extension points.

Riverbox Pro (sold separately at dontworry2much.com) adds Twilio and WhatsApp Cloud API gateways, social login (Google, Microsoft, Facebook, GitHub, LinkedIn, Discord), and role-based 2FA/3FA login flows.

Privacy

The free plugin does not connect to any external service. Emails go through your site’s own mail system, SMS goes through the gateway you configure, and all data stays in your WordPress database.

스크린샷

The login form with every method enabled: one-time codes (email or phone), magic links, password, passkeys, and social login (Pro).
The login form with every method enabled: one-time codes (email or phone), magic links, password, passkeys, and social login (Pro).
The one-time code verification step after a code has been sent.
The one-time code verification step after a code has been sent.

설치

  1. Install and activate the plugin.
  2. Add [riverbox-login] to any page; optionally add [riverbox-account] to a members page for passkey management.
  3. Configure methods, codes, signup behavior, and gateways under Settings → Riverbox.

FAQ

Does this replace my normal WordPress login?

No. Riverbox adds passwordless login wherever you place the shortcode. The standard wp-login.php form keeps working, so you can never lock yourself out.

Can new visitors register through the form?

Yes — enable automatic account creation in settings and choose the role new users receive. Signup works with email and phone codes.

Do passkeys need a third-party service?

No. Registration and verification happen entirely on your server using the WebAuthn standard. Passkeys require HTTPS in production (browsers allow localhost for testing).

How does phone login send SMS?

The free plugin includes a generic HTTP gateway you can point at any SMS provider’s API. Riverbox Pro adds ready-made Twilio and WhatsApp Cloud API integrations.

The code email doesn’t arrive — what do I check?

Email delivery depends on your site’s mail configuration. Check the Riverbox delivery log and consider an SMTP plugin if your host’s default mail is unreliable.

후기

이 플러그인에 대한 평가가 없습니다.

기여자 & 개발자

“Riverbox Passwordless Login”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자
  • riverbox

자국어로 “Riverbox Passwordless Login”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록을 RSS로 구독하세요.

변경이력

1.1.1

  • Security: rate limiting is now atomic (single-statement counter on a dedicated table), so concurrent requests can no longer race past the limit.
  • Security: a code’s expiry is fixed at issue time — failed verification attempts can no longer extend its lifetime.

1.1.0

  • New: magic link login (single-use, expiring, blocked for MFA accounts).
  • New: passkey (WebAuthn) login and registration with an account security page.
  • New: phone one-time-code login via a configurable HTTP SMS gateway.
  • New: password as an optional method alongside passwordless login.
  • New: multi-step login chains (foundation for role-based 2FA/3FA in Pro).
  • New: extension hooks for gateways, factors, and settings.

1.0.0

  • Initial release: email one-time-code login and signup, [riverbox-login] shortcode, REST API, delivery log, rate limiting.

기초

  • 버전 1.1.1
  • 최근 업데이트: 2주 전
  • 활성화된 설치 10보다 적음
  • 워드프레스 버전 6.4 또는 그 이상
  • 다음까지 시험됨: 7.0.2
  • PHP 버전 8.1 또는 그 이상
  • 언어
    English (US)
  • 태그:
    authenticationloginotppasskeyspasswordless
  • 고급 보기

평점

아직 제출된 리뷰가 없습니다.

Your review

모든 리뷰 보기

기여자

  • riverbox

지원

할 말 있으신가요? 도움이 필요하신가요?

지원 포럼 보기

  • 소개
  • 뉴스
  • 호스팅
  • 개인정보
  • 쇼케이스
  • 테마
  • 플러그인
  • 패턴
  • 배우기
  • 지원
  • 개발자 도구
  • WordPress.tv ↗
  • 참여하기
  • 이벤트
  • 기부하기 ↗
  • 미래를 위한 5가지
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

한국어

  • X(이전 트위터) 계정 방문하기
  • 블루스카이 계정 방문하기
  • 마스토돈 계정 방문하기
  • 스레드 계정 방문하기
  • 페이스북 페이지 방문하기
  • 인스타그램 계정 방문하기
  • LinkedIn 계정 방문하기
  • 틱톡 계정 방문하기
  • 유튜브 채널 방문하기
  • 텀블러 계정 방문하기
코드는 詩다
The WordPress® trademark is the intellectual property of the WordPress Foundation.