[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXWNTYY1fnpIrkjNg3VdsriTnhJGA-mVxWk-_F3Tkjbg":3},{"slug":4,"display_name":4,"profile_url":5,"plugin_count":6,"total_installs":7,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"wppasskey","https:\u002F\u002Fprofiles.wordpress.org\u002Fwppasskey\u002F",1,10,100,30,94,"2026-08-29T00:24:40.501Z",[13],{"slug":14,"name":15,"version":16,"author":4,"author_profile":5,"description":17,"short_description":18,"active_installs":7,"downloaded":19,"rating":20,"num_ratings":20,"last_updated":21,"tested_up_to":22,"requires_at_least":23,"requires_php":24,"tags":25,"homepage":31,"download_link":32,"security_score":8,"vuln_count":20,"unpatched_count":20,"last_vuln_date":33,"fetched_at":34},"advanced-passkey-login","Advanced Passkeys for Secure Login","1.1.11","\u003Cp>Passwords are the single biggest security liability for your WordPress site. They get leaked, reused, and exploited by automated brute-force attacks every single day. While standard Two-Factor Authentication (2FA) adds a layer of safety, typing in temporary codes from SMS or authenticator apps introduces annoying workflow friction that hurts user adoption and slows down your day.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Passkeys for Secure Login\u003C\u002Fstrong> brings the future of un-phishable, lightning-fast authentication directly to WordPress using the official FIDO2 \u002F WebAuthn standard.\u003C\u002Fp>\n\u003Cp>Give your users a modern login experience. Users register a secure passkey just once using their device’s built-in biometric sensor (Face ID, Touch ID, Windows Hello), device PIN, or a hardware security key (like a YubiKey). Future sign-ins can bypass traditional password fields and reduce credential-theft risk.\u003C\u002Fp>\n\u003Ch3>Out-of-the-Box WooCommerce & Membership Integrations\u003C\u002Fh3>\n\u003Cp>Don’t settle for basic alternatives that only support the default backend login page. Advanced Passkeys features intelligent, dependency-aware integration modules that automatically inject secure passkey entry points into your existing platform ecosystem. Experience seamless, zero-configuration support for:\u003Cbr \u002F>\n* \u003Cstrong>WooCommerce\u003C\u002Fstrong> (Secure checkout & customer account login)\u003Cbr \u002F>\n* \u003Cstrong>MemberPress\u003C\u002Fstrong> & \u003Cstrong>Paid Memberships Pro (PMPro)\u003C\u002Fstrong> (Frictionless member portal protection)\u003Cbr \u002F>\n* \u003Cstrong>LearnDash\u003C\u002Fstrong> (Instant student sign-in to prevent account sharing)\u003Cbr \u002F>\n* \u003Cstrong>Ultimate Member\u003C\u002Fstrong> & \u003Cstrong>BuddyBoss\u003C\u002Fstrong> (Biometric profiles for modern communities)\u003Cbr \u002F>\n* \u003Cstrong>Gravity Forms\u003C\u002Fstrong> (Protected frontend user-registration flows)\u003C\u002Fp>\n\u003Ch3>Why Smart Site Owners Choose Passkeys\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Strong Phishing Resistance:\u003C\u002Fstrong> Passkeys are cryptographically bound to your specific domain name. A fake login page or copycat site cannot reuse a passkey issued for your real site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reduce Brute-Force Risk:\u003C\u002Fstrong> Passkey login does not rely on a static password being typed into the login form, reducing exposure to automated password-guessing attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Painless Cross-Device Sync:\u003C\u002Fstrong> Works natively with iCloud Keychain, Google Password Manager, and 1Password for reliable, frictionless cross-device access across desktop, mobile, and tablet.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>One-Click Passwordless Authentication:\u003C\u002Fstrong> Adds a native, highly visible “Sign in with Passkey” button directly to your core WordPress login screens.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conditional UI Autofill Support:\u003C\u002Fstrong> Offers optional browser-native passkey autofill prompts when a user focuses on the username field for an incredibly polished user experience.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Ecosystem-Aware Gutenberg Blocks & Shortcodes:\u003C\u002Fstrong> Automatically registers matching frontend login cards and components specifically tailored to your active third-party plugins.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>High-Yield Admin Nudge Notices:\u003C\u002Fstrong> Turn on built-in dashboard reminders that gently guide eligible users to secure their accounts with a passkey without administrator intervention.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Granular Role-Based Security Policies:\u003C\u002Fstrong> Configure exactly which user roles are permitted to use biometric authentication (Default: Administrators-only out of the box).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer-Managed Overrides:\u003C\u002Fstrong> Manage passkey settings in PHP using the centralized \u003Ccode>advapafo_local_configuration\u003C\u002Fcode> filter or the \u003Ccode>ADVAPAFO_SETTINGS\u003C\u002Fcode> constant.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Theme Template Customization:\u003C\u002Fstrong> Seamlessly match your active brand by overriding the login button template layout via \u003Ccode>\u002Fadvanced-passkeys\u002Flogin\u002Fbutton.php\u003C\u002Fcode> inside your child theme.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Analytics Dashboard:\u003C\u002Fstrong> Track credential performance over time with a live Authenticator Overview breakdown card and a Last Login audit trail log.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hardened Brute-Force Rate Limiting:\u003C\u002Fstrong> Enforce strict local connection limits to log and block malicious behavior, backed by automated daily cleanup crons to keep your database lean.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multisite Network Provisioning:\u003C\u002Fstrong> Network-aware architecture instantly partitions tables dynamically and inherits security guardrails across newly deployed network sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean Housekeeping Routine:\u003C\u002Fstrong> Implements a strict, responsible uninstall function that leaves behind absolutely zero orphaned database tables or leftover configuration choices.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Developer Configuration\u003C\u002Fh3>\n\u003Cp>Advanced Passkeys supports code-managed configuration for developers, agencies, and infrastructure teams that deploy settings through version control. This helps apply the same passkey policy across many sites without manual option changes.\u003C\u002Fp>\n\u003Ch4>Configuration evaluation priority order\u003C\u002Fh4>\n\u003Cp>When resolving a configuration key, the plugin respects this strict top-down hierarchy:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Centralized \u003Ccode>advapafo_local_configuration\u003C\u002Fcode> hook filter\u003C\u002Fli>\n\u003Cli>Global \u003Ccode>ADVAPAFO_SETTINGS\u003C\u002Fcode> array constant definition\u003C\u002Fli>\n\u003Cli>Site-level \u003Ccode>advapafo_settings\u003C\u002Fcode> option array map\u003C\u002Fli>\n\u003Cli>Single historical legacy \u003Ccode>advapafo_*\u003C\u002Fcode> options\u003C\u002Fli>\n\u003Cli>Core plugin out-of-the-box system defaults\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Values resolve individually by index key. Overriding a key like \u003Ccode>login_challenge_ttl\u003C\u002Fcode> via code leaves your remaining settings completely manageable via the dashboard UI or database choices.\u003C\u002Fp>\n\u003Ch4>Example: Enforce HTTPS and restrict passkey enrollment to administrators\u003C\u002Fh4>\n\u003Cp>Drop this configuration array inside your active theme’s functions file or a custom functionality plugin:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u003C?php\nadd_filter(\n    'advapafo_local_configuration',\n    static function ( array $configuration ): array {\n        return array_replace(\n            $configuration,\n            array(\n                'enforce_https'  => true,\n                'eligible_roles' => array( 'administrator' ),\n            )\n        );\n    }\n);\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>Example: Global array constant configuration within wp-config.php\u003C\u002Fh4>\n\u003Cp>For automated environments that favor infrastructure-level array maps, define this constant:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>define(\n    'ADVAPAFO_SETTINGS',\n    array(\n        'conditional_ui_enabled'     => true,\n        'login_challenge_ttl'        => 300,\n        'registration_challenge_ttl' => 300,\n        'max_passkeys_per_user'      => 0,\n    )\n);\n\u003C\u002Fcode>\u003C\u002Fpre>\n","Add secure passwordless passkey login with Face ID, Touch ID, Windows Hello, and hardware keys.",367,0,"2026-07-08T22:58:00.000Z","7.0.2","6.0","8.0",[26,27,28,29,30],"login","passkeys","passwordless","security","webauthn","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fadvanced-passkey-login\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadvanced-passkey-login.1.1.11.zip",null,"2026-07-22T17:31:50.256Z"]