콘텐츠로 바로가기
WordPress.org

한국어

  • 테마
  • 플러그인
  • 소식
    • 문서
    • 포럼
  • About
    • WordPress 6.9
    • 워드프레스 6.8
    • 워드프레스와 40% 웹을 위한 여정
    • 워드프레스 번역 핸드북
  • 워드프레스 한국팀
  • 워드프레스 받기
워드프레스 받기
WordPress.org

Plugin Directory

Zeshan Login 2FA

  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인
  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인

Zeshan Login 2FA

작성자: zeshan495
다운로드
  • 세부사항
  • 평가
  • 설치
  • 개발
지원

설명

Zeshan Login 2FA adds real two-factor authentication (2FA) to your WordPress login. A password alone is no longer enough. Bots and leaked-password attacks target WordPress logins around the clock. With Zeshan Login 2FA, a second step (a 6-digit code from an authenticator app) stands between an attacker and your admin area.

It works with the authenticator apps you already know: Google Authenticator, Authy, Microsoft Authenticator, 1Password, and any other TOTP app.

Setup takes about two minutes: open your profile, scan a QR code with your phone, confirm one code, and save your backup codes. That is it. Your login is protected.

What you get (free)

  • App-based 2FA at login. Standard TOTP (RFC 6238), the same technology your bank uses.
  • QR-code setup. Scan once from your user profile. Your secret is generated on your own server.
  • 10 backup codes. One-time codes so you can always get in, even if you lose your phone.
  • Enforced for Administrators by default. Protect the accounts that matter most.
  • Lockout-safe. 2FA is only enforced for users who have finished setup, so enabling the plugin never locks anyone out before they opt in.
  • Privacy-first. No accounts, no tracking, no phone-home. Everything stays on your site.

Why Zeshan Login 2FA

  • Lightweight and focused. It does one thing (2FA) and does it well.
  • No account, no signup, no external service required.
  • Clean, standards-based TOTP that every authenticator app supports.
  • Backup codes are stored hashed (never in plaintext) and are one-time use.

Going further (Pro & personal setup)

The free plugin fully protects your login on its own. If you want more control or a done-for-you setup, Zeshan Login 2FA Pro adds:

  • Trusted-device management. Remember the devices you trust and skip the code for a set number of days.
  • Role-based enforcement. Require 2FA for editors, authors, shop managers, or everyone, with an optional grace period.
  • Malware attack shield. Brute-force login protection, malicious-request blocking, and file-editor lockdown.
  • Personal setup and priority support. I set it up for you and help your team get onboarded.

Pro is a one-time purchase and includes personal setup. Learn more at zeshanhaider.dev/zeshan-login-2fa.

Credits & third-party libraries

This plugin bundles the following third-party library, used to draw the QR code in your browser:

  • QRCode.js by Sangmin Shim (davidshimjs). Source: https://github.com/davidshimjs/qrcodejs (MIT License).

The library is included locally (not loaded from a third-party CDN) as required by the plugin directory guidelines. All other code is original work by the plugin author and licensed under GPLv2 or later.

스크린샷

The status page shows which administrators have two-factor authentication enabled across your site.
The status page shows which administrators have two-factor authentication enabled across your site.
The two-factor setup on your user profile. Scan the QR code with your app, confirm one code, and you are protected.
The two-factor setup on your user profile. Scan the QR code with your app, confirm one code, and you are protected.
Once enabled, your profile shows the status and how many backup codes you have left.
Once enabled, your profile shows the status and how many backup codes you have left.

설치

  1. In your WordPress admin, go to Plugins → Add New and search for “Zeshan Login 2FA”, or upload the plugin ZIP under Plugins → Add New → Upload Plugin.
  2. Activate the plugin.
  3. Go to Users → Your Profile (or Edit My Profile) and scroll to Two-Factor Authentication.
  4. Scan the QR code with your authenticator app (Google Authenticator, Authy, 1Password, etc.).
  5. Enter the 6-digit code to confirm, then click Update Profile.
  6. Save the backup codes shown to you. Store them somewhere safe.

From now on, administrators with 2FA set up will enter a code at login after their password.

FAQ

Which authenticator apps are supported?

Any app that supports standard TOTP: Google Authenticator, Authy, Microsoft Authenticator, 1Password, and others.

Will this lock me out of my site?

No. 2FA is only enforced for users who have completed setup. Enabling the plugin does nothing until you opt in by scanning the QR code and confirming. And if you ever lose your phone, your backup codes get you back in.

What if I lose my phone and my backup codes?

A site administrator can turn off 2FA for your account by editing your user profile. If you are the only administrator, you can remove the relevant user meta via your database or a tool like WP-CLI. Keep your backup codes safe to avoid this.

Does it work for all users or just admins?

By default, 2FA is enforced for Administrators. Requiring it for other roles (editors, authors, shop managers, everyone) is available in Zeshan Login 2FA Pro.

Does the plugin send my data anywhere?

No. There is no external service, no account, and no tracking. Your 2FA secret and backup codes stay on your own server.

Can I skip the code on my own computer?

“Trusted devices” (remember this device and skip the code for a set number of days) is a Pro feature.

Is this compatible with my other security plugins?

Zeshan Login 2FA only adds a second step at login and doesn’t modify your password flow, so it works alongside most security and login plugins. As always, test on a staging site if you run a complex setup.

후기

이 플러그인에 대한 평가가 없습니다.

기여자 & 개발자

“Zeshan Login 2FA”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자
  • zeshan495

자국어로 “Zeshan Login 2FA”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록을 RSS로 구독하세요.

변경이력

1.0.0

  • Initial public release.
  • App-based TOTP two-factor authentication at login (RFC 6238).
  • QR-code setup on the user profile.
  • 10 one-time backup codes.
  • Reset your authenticator key to move 2FA to a new phone.
  • Replay protection: a login code cannot be reused within its time window.
  • Enforced for Administrators by default, lockout-safe.

기초

  • 버전 1.0.0
  • 최근 업데이트: 1일 전
  • 활성화된 설치 10보다 적음
  • 워드프레스 버전 5.8 또는 그 이상
  • 다음까지 시험됨: 7.0.2
  • PHP 버전 7.4 또는 그 이상
  • 언어
    English (US)
  • 태그:
    2FAauthenticationlogin securitysecuritytwo factor
  • 고급 보기

평점

아직 제출된 리뷰가 없습니다.

Your review

모든 리뷰 보기

기여자

  • zeshan495

지원

할 말 있으신가요? 도움이 필요하신가요?

지원 포럼 보기

  • 소개
  • 뉴스
  • 호스팅
  • 개인정보
  • 쇼케이스
  • 테마
  • 플러그인
  • 패턴
  • 배우기
  • 지원
  • 개발자 도구
  • WordPress.tv ↗
  • 참여하기
  • 이벤트
  • 기부하기 ↗
  • 미래를 위한 5가지
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

한국어

  • X(이전 트위터) 계정 방문하기
  • 블루스카이 계정 방문하기
  • 마스토돈 계정 방문하기
  • 스레드 계정 방문하기
  • 페이스북 페이지 방문하기
  • 인스타그램 계정 방문하기
  • LinkedIn 계정 방문하기
  • 틱톡 계정 방문하기
  • 유튜브 채널 방문하기
  • 텀블러 계정 방문하기
코드는 詩다
The WordPress® trademark is the intellectual property of the WordPress Foundation.