[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDArgYkLDc-HRmUh0gD4uOf8muqo-9znyIIgAWuqtS04":3,"$f9hfR3Spk0l39ymJqeqpRC9XE_YMrq6cfBtcIj25vPqY":130,"$fgaeR9ixV5ODhcDHM9WtAfsri-wzi95e40_2qdDZ3plc":135},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":21,"download_link":22,"security_score":23,"vuln_count":11,"unpatched_count":11,"last_vuln_date":24,"fetched_at":25,"discovery_status":26,"vulnerabilities":27,"developer":28,"crawl_stats":24,"alternatives":34,"analysis":24,"fingerprints":24},"brightery-secure-2fa","Brightery Secure 2FA","1.0.0","Brightery","https:\u002F\u002Fprofiles.wordpress.org\u002Fbrighterycom\u002F","\u003Cp>Brightery Secure 2FA adds a strong second login step for WordPress accounts while staying lightweight in runtime.\u003C\u002Fp>\n\u003Cp>Features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Authenticator app (TOTP) support.\u003C\u002Fli>\n\u003Cli>Passkeys \u002F WebAuthn support for Touch ID, Face ID, Windows Hello, fingerprint readers, and device PIN.\u003C\u002Fli>\n\u003Cli>Role-based enforcement: require selected user groups to enroll.\u003C\u002Fli>\n\u003Cli>Forced enrollment page to block protected users until they configure security.\u003C\u002Fli>\n\u003Cli>Backup codes.\u003C\u002Fli>\n\u003Cli>Encrypted TOTP secret storage using WordPress salts.\u003C\u002Fli>\n\u003Cli>Login throttling for repeated primary-login and second-factor failures.\u003C\u002Fli>\n\u003Cli>Lightweight audit logs stored inside WordPress options.\u003C\u002Fli>\n\u003Cli>Email alerts for enrollment changes and lockouts.\u003C\u002Fli>\n\u003Cli>Trusted devices so users can skip 2FA on approved browsers for a limited period.\u003C\u002Fli>\n\u003Cli>CSV export for security logs.\u003C\u002Fli>\n\u003Cli>Advanced log filters and search.\u003C\u002Fli>\n\u003Cli>Custom labels for trusted devices and passkeys.\u003C\u002Fli>\n\u003Cli>Optional revocation of other sessions after security changes.\u003C\u002Fli>\n\u003Cli>Optional blocking of WordPress application passwords for protected \u002F 2FA-enabled users.\u003C\u002Fli>\n\u003Cli>Lightweight runtime: the plugin mostly runs on login, profile, AJAX, settings pages, WooCommerce account pages, and authenticated REST requests.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Important Notes\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>HTTPS is required for passkeys in production.\u003C\u002Fli>\n\u003Cli>This build is optimized for normal interactive WordPress logins and admin access enforcement.\u003C\u002Fli>\n\u003Cli>Passkey attestation trust-chain validation is intentionally not enforced in order to remain lightweight and dependency-free.\u003Cbr \u002F>\nThe plugin still validates challenge, origin, RP ID hash, user presence, optional user verification, signature, and signature counter.\u003C\u002Fli>\n\u003Cli>This lightweight build supports ES256 passkeys.\u003C\u002Fli>\n\u003Cli>TOTP setup includes a local QR-code renderer so the setup secret stays on your own WordPress site during enrollment.\u003C\u002Fli>\n\u003Cli>The plugin stores account-security data such as trusted-device records, passkey metadata, security logs, and a limited recent login-context history.\u003C\u002Fli>\n\u003Cli>A privacy-policy suggestion plus WordPress personal-data exporter and eraser integrations are included.\u003C\u002Fli>\n\u003Cli>There are no non-GPL third-party runtime libraries bundled with this plugin;\u003Cbr \u002F>\nthe distributed JavaScript and CSS files are included as human-readable source.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Security Model\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>TOTP secrets are encrypted before storing in user meta.\u003C\u002Fli>\n\u003Cli>Backup codes are stored hashed.\u003C\u002Fli>\n\u003Cli>Passkeys verify origin, RP ID hash, challenge, signature, and signature counter.\u003C\u002Fli>\n\u003Cli>Rate limiting helps slow repeated login and 2FA guessing attempts.\u003C\u002Fli>\n\u003Cli>The plugin can require passkey user verification for biometric\u002FPIN-backed sign-in.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>Brightery Secure 2FA stores security-related account data so it can protect logins and help administrators investigate suspicious access.\u003Cbr \u002F>\nThe plugin adds suggested privacy-policy text to WordPress and registers personal-data exporter\u002Feraser callbacks for the data it stores.\u003C\u002Fp>\n\u003Ch3>Source Code and Licensing\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>All distributed plugin PHP, JS, and CSS files are included as human-readable source.\u003C\u002Fli>\n\u003Cli>The local QR renderer is bundled directly in \u003Ccode>assets\u002Fjs\u002Fbs2fa-qr.js\u003C\u002Fcode> as readable source code.\u003C\u002Fli>\n\u003Cli>No non-GPL runtime libraries are required for normal plugin operation.\u003C\u002Fli>\n\u003C\u002Ful>\n","Production-focused two-factor authentication for WordPress with authenticator apps, passkeys, forced enrollment, and advanced session hardening.",0,189,"2026-04-23T09:39:00.000Z","6.9.5","6.2","7.4",[18,19,20],"2fa","authentication","security","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbrightery-secure-2fa.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":29,"display_name":7,"profile_url":8,"plugin_count":30,"total_installs":11,"avg_security_score":23,"avg_patch_time_days":31,"trust_score":32,"computed_at":33},"brighterycom",3,30,94,"2026-08-29T09:43:49.500Z",[35,55,76,96,115],{"slug":36,"name":37,"version":38,"author":39,"author_profile":40,"description":41,"short_description":42,"active_installs":43,"downloaded":44,"rating":45,"num_ratings":46,"last_updated":47,"tested_up_to":14,"requires_at_least":48,"requires_php":49,"tags":50,"homepage":53,"download_link":54,"security_score":23,"vuln_count":11,"unpatched_count":11,"last_vuln_date":24,"fetched_at":25},"two-factor","Two Factor","0.16.0","WordPress.org","https:\u002F\u002Fprofiles.wordpress.org\u002Fwordpressdotorg\u002F","\u003Cp>The Two-Factor plugin adds an extra layer of security to your WordPress login by requiring users to provide a second form of authentication in addition to their password.  This helps protect against unauthorized access even if passwords are compromised.\u003C\u002Fp>\n\u003Ch3>Setup Instructions\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Important\u003C\u002Fstrong>: Each user must individually configure their two-factor authentication settings.\u003C\u002Fp>\n\u003Ch3>For Individual Users\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\u003Cstrong>Navigate to your profile\u003C\u002Fstrong>: Go to “Users” \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> “Your Profile” in the WordPress admin\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Find Two-Factor Options\u003C\u002Fstrong>: Scroll down to the “Two-Factor Options” section\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Choose your methods\u003C\u002Fstrong>: Enable one or more authentication providers (noting a site admin may have hidden one or more so what is available could vary):\n\u003Cul>\n\u003Cli>\u003Cstrong>Authenticator App (TOTP)\u003C\u002Fstrong> – Use apps like Google Authenticator, Authy, or 1Password\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Codes\u003C\u002Fstrong> – Receive one-time codes via email\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Backup Codes\u003C\u002Fstrong> – Generate one-time backup codes for emergencies\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dummy Method\u003C\u002Fstrong> – For testing purposes only (requires WP_DEBUG)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configure each method\u003C\u002Fstrong>: Follow the setup instructions for each enabled provider\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Set primary method\u003C\u002Fstrong>: Choose which method to use as your default authentication\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Save changes\u003C\u002Fstrong>: Click “Update Profile” to save your settings\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>For Site Administrators\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Plugin settings\u003C\u002Fstrong>: The plugin provides a settings page under “Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Two-Factor” to configure which providers should be disabled site-wide.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User management\u003C\u002Fstrong>: Administrators can configure 2FA for other users by editing their profiles\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security recommendations\u003C\u002Fstrong>: Encourage users to enable backup methods to prevent account lockouts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Available Authentication Methods\u003C\u002Fh3>\n\u003Ch3>Authenticator App (TOTP) – Recommended\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security\u003C\u002Fstrong>: High – Time-based one-time passwords\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Setup\u003C\u002Fstrong>: Scan QR code with authenticator app\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compatibility\u003C\u002Fstrong>: Works with Google Authenticator, Authy, 1Password, and other TOTP apps\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Best for\u003C\u002Fstrong>: Most users, provides excellent security with good usability\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Backup Codes – Recommended\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security\u003C\u002Fstrong>: Medium – One-time use codes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Setup\u003C\u002Fstrong>: Generate 10 backup codes for emergency access\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compatibility\u003C\u002Fstrong>: Works everywhere, no special hardware needed\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Best for\u003C\u002Fstrong>: Emergency access when other methods are unavailable\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Email Codes\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security\u003C\u002Fstrong>: Medium – One-time codes sent via email\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Setup\u003C\u002Fstrong>: Automatic – uses your WordPress email address\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compatibility\u003C\u002Fstrong>: Works with any email-capable device\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Best for\u003C\u002Fstrong>: Users who prefer email-based authentication\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>FIDO U2F Security Keys\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Deprecated and removed due to loss of browser support.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Dummy Method\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security\u003C\u002Fstrong>: None – Always succeeds\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Setup\u003C\u002Fstrong>: Only available when WP_DEBUG is enabled\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Testing and development only\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Best for\u003C\u002Fstrong>: Developers testing the plugin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Important Notes\u003C\u002Fh3>\n\u003Ch3>HTTPS Requirement\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>All methods work on both HTTP and HTTPS sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Browser Compatibility\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>TOTP and email methods work on all devices and browsers\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Account Recovery\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Always enable backup codes to prevent being locked out of your account\u003C\u002Fli>\n\u003Cli>If you lose access to all authentication methods, contact your site administrator\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Security Best Practices\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Use multiple authentication methods when possible\u003C\u002Fli>\n\u003Cli>Keep backup codes in a secure location\u003C\u002Fli>\n\u003Cli>Regularly review and update your authentication settings\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For more information about two-factor authentication in WordPress, see the \u003Ca href=\"https:\u002F\u002Fdeveloper.wordpress.org\u002Fadvanced-administration\u002Fsecurity\u002Fmfa\u002F\" rel=\"nofollow ugc\">WordPress Advanced Administration Security Guide\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>For more history, see \u003Ca href=\"https:\u002F\u002Fgeorgestephanis.wordpress.com\u002F2013\u002F08\u002F14\u002Ftwo-cents-on-two-factor\u002F\" rel=\"nofollow ugc\">this post\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Actions & Filters\u003C\u002Fh4>\n\u003Cp>Here is a list of action and filter hooks provided by the plugin:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>two_factor_providers\u003C\u002Fcode> filter overrides the available two-factor providers such as email and time-based one-time passwords. Array values are PHP classnames of the two-factor providers.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_providers_for_user\u003C\u002Fcode> filter overrides the available two-factor providers for a specific user. Array values are instances of provider classes and the user object \u003Ccode>WP_User\u003C\u002Fcode> is available as the second argument.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_enabled_providers_for_user\u003C\u002Fcode> filter overrides the list of two-factor providers enabled for a user. First argument is an array of enabled provider classnames as values, the second argument is the user ID.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_user_authenticated\u003C\u002Fcode> action which receives the logged in \u003Ccode>WP_User\u003C\u002Fcode> object as the first argument for determining the logged in user right after the authentication workflow.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_user_api_login_enable\u003C\u002Fcode> filter restricts authentication for REST API and XML-RPC to application passwords only. Provides the user ID as the second argument.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_email_token_ttl\u003C\u002Fcode> filter overrides the time interval in seconds that an email token is considered after generation. Accepts the time in seconds as the first argument and the ID of the \u003Ccode>WP_User\u003C\u002Fcode> object being authenticated.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_email_token_length\u003C\u002Fcode> filter overrides the default 8 character count for email tokens.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_backup_code_length\u003C\u002Fcode> filter overrides the default 8 character count for backup codes. Provides the \u003Ccode>WP_User\u003C\u002Fcode> of the associated user as the second argument.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_rest_api_can_edit_user\u003C\u002Fcode> filter overrides whether a user’s Two-Factor settings can be edited via the REST API. First argument is the current \u003Ccode>$can_edit\u003C\u002Fcode> boolean, the second argument is the user ID.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_before_authentication_prompt\u003C\u002Fcode> action which receives the provider object and fires prior to the prompt shown on the authentication input form.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_after_authentication_prompt\u003C\u002Fcode> action which receives the provider object and fires after the prompt shown on the authentication input form.\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_after_authentication_input\u003C\u002Fcode> action which receives the provider object and fires after the input shown on the authentication input form (if form contains no input, action fires immediately after \u003Ccode>two_factor_after_authentication_prompt\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>\u003Ccode>two_factor_login_backup_links\u003C\u002Fcode> filters the backup links displayed on the two-factor login form.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Redirect After the Two-Factor Challenge\u003C\u002Fh3>\n\u003Cp>To redirect users to a specific URL after completing the two-factor challenge, use WordPress Core built-in login_redirect filter. The filter works the same way as in a standard WordPress login flow:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>add_filter( 'login_redirect', function( $redirect_to, $requested_redirect_to, $user ) {\n    return home_url( '\u002Fdashboard\u002F' );\n}, 10, 3 );\n\u003C\u002Fcode>\u003C\u002Fpre>\n","Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email, and backup verification codes.",100000,1708019,96,208,"2026-03-27T17:24:00.000Z","6.8","7.2",[18,19,51,20,52],"mfa","totp","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Ftwo-factor\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftwo-factor.0.16.0.zip",{"slug":56,"name":57,"version":58,"author":59,"author_profile":60,"description":61,"short_description":62,"active_installs":63,"downloaded":64,"rating":65,"num_ratings":66,"last_updated":67,"tested_up_to":68,"requires_at_least":69,"requires_php":70,"tags":71,"homepage":21,"download_link":75,"security_score":23,"vuln_count":11,"unpatched_count":11,"last_vuln_date":24,"fetched_at":25},"wordfence-login-security","Wordfence Login Security","1.1.16","wfryan","https:\u002F\u002Fprofiles.wordpress.org\u002Fwfryan\u002F","\u003Ch3>WORDFENCE LOGIN SECURITY\u003C\u002Fh3>\n\u003Cp>Wordfence Login Security contains a subset of the functionality found in the full Wordfence plugin: Two-factor Authentication, XML-RPC Protection, and Login Page CAPTCHA.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>This plugin is being discontinued on or around July 1, 2026.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All of its features are already included in the main Wordfence plugin, which is also available to use for free. We recommend installing Wordfence to continue receiving updates, security improvements, and full functionality.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwordfence\u002F\" rel=\"ugc\">Install the full Wordfence plugin\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Two-factor authentication (2FA), one of the most secure forms of remote system authentication available.\u003C\u002Fli>\n\u003Cli>Use any TOTP-based authenticator app or service like Google Authenticator, Authy, 1Password or FreeOTP.\u003C\u002Fli>\n\u003Cli>Enable 2FA for any WordPress user role.\u003C\u002Fli>\n\u003Cli>Completely free to use, no limits or restrictions of any kind.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>LOGIN PAGE CAPTCHA\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Easily enable Google ReCAPTCHA v3 on your login and registration pages.\u003C\u002Fli>\n\u003Cli>Stops bots from logging in without inconveniencing your site visitors.\u003C\u002Fli>\n\u003Cli>Robust protection against password guessing and credential stuffing attacks distributed across large IP pools\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>XML-RPC PROTECTION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>XML-RPC is the biggest target for WordPress attacks, but is often overlooked.\u003C\u002Fli>\n\u003Cli>Protect XML-RPC with 2FA or disable it altogether if it’s not needed.\u003C\u002Fli>\n\u003C\u002Ful>\n","Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.",60000,1329360,78,26,"2026-04-29T15:29:00.000Z","7.0.2","4.7","7.0",[18,72,73,20,74],"captcha","login-security","two-factor-authentication","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwordfence-login-security.1.1.16.zip",{"slug":77,"name":78,"version":79,"author":80,"author_profile":81,"description":82,"short_description":83,"active_installs":84,"downloaded":85,"rating":86,"num_ratings":87,"last_updated":88,"tested_up_to":68,"requires_at_least":89,"requires_php":89,"tags":90,"homepage":91,"download_link":92,"security_score":93,"vuln_count":94,"unpatched_count":11,"last_vuln_date":95,"fetched_at":25},"miniorange-2-factor-authentication","miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator)","6.2.7","miniOrange","https:\u002F\u002Fprofiles.wordpress.org\u002Fcyberlord92\u002F","\u003Ch3>WordPress Two-Factor Authentication (2FA)\u003C\u002Fh3>\n\u003Cp>WordPress websites are frequently targeted by brute force attacks, credential stuffing attacks, phishing attempts, and unauthorized login attempts. Passwords alone are no longer sufficient to protect administrator accounts, customer accounts, and sensitive website data.\u003C\u002Fp>\n\u003Cp>The miniOrange \u003Cstrong>2-Factor Authentication\u003C\u002Fstrong> plugin adds an additional layer of security to WordPress logins by requiring users to verify their identity using a second authentication factor. Even if a password is compromised, unauthorized users cannot access accounts without completing the \u003Cstrong>2FA\u003C\u002Fstrong> verification process.\u003C\u002Fp>\n\u003Cp>The plugin supports multiple \u003Cstrong>Two-Factor Authentication (2FA)\u003C\u002Fstrong> and \u003Cstrong>Multi-Factor Authentication (MFA)\u003C\u002Fstrong> methods, including \u003Cstrong>Google Authenticator\u003C\u002Fstrong>, \u003Cstrong>Microsoft Authenticator\u003C\u002Fstrong>, \u003Cstrong>Authy\u003C\u002Fstrong>, \u003Cstrong>Email OTP\u003C\u002Fstrong>, \u003Cstrong>SMS OTP\u003C\u002Fstrong>, \u003Cstrong>WhatsApp OTP\u003C\u002Fstrong>, \u003Cstrong>Telegram OTP\u003C\u002Fstrong>, backup codes, security questions, and hardware token authentication.\u003C\u002Fp>\n\u003Cp>Whether you manage a \u003Cstrong>WooCommerce\u003C\u002Fstrong> store, membership website, LMS platform, enterprise portal, educational institution, government website, or agency-managed environment, \u003Cstrong>WordPress 2FA\u003C\u002Fstrong> helps secure user accounts and reduce the risk of account compromise.\u003C\u002Fp>\n\u003Cp>The \u003Cstrong>free\u003C\u002Fstrong> plan supports \u003Cstrong>2FA setup for up to 5 users\u003C\u002Fstrong>. \u003Cstrong>Premium\u003C\u002Fstrong> removes the user cap and adds enforcement policies, trusted devices, multisite support, custom branding, and more.\u003C\u002Fp>\n\u003Ch3>Why Use Two-Factor Authentication for WordPress?\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Protect Administrator Accounts\u003C\u002Fstrong>\u003Cbr \u002F>\nAdministrator accounts are the primary target of attackers. \u003Cstrong>WordPress Two-Factor Authentication\u003C\u002Fstrong> ensures that only verified users can access administrative dashboards.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent Unauthorized Access\u003C\u002Fstrong>\u003Cbr \u002F>\nEven if passwords are stolen through phishing attacks or data breaches, additional \u003Cstrong>authentication\u003C\u002Fstrong> requirements help prevent unauthorized access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Improve WordPress Login Security\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cstrong>WordPress MFA\u003C\u002Fstrong> strengthens login security by combining passwords with additional verification methods.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Reduce Account Takeover Risks\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cstrong>Multi-factor authentication\u003C\u002Fstrong> significantly reduces the likelihood of successful account takeover attempts.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Secure WooCommerce Customer Accounts\u003C\u002Fstrong>\u003Cbr \u002F>\nProtect customer profiles, order information, payment details, and store management accounts using \u003Cstrong>WooCommerce Two-Factor Authentication\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Quick Links:\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fstep-by-step-guide-for-wordpress-2-factor-authentication\" rel=\"nofollow ugc\">Setup Guide\u003C\u002Fa> |\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002F2-factor-authentication-for-wordpress-wp-2fa\" rel=\"nofollow ugc\">Features\u003C\u002Fa> |\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002F2-factor-authentication-for-wordpress-wp-2fa#pricing\" rel=\"nofollow ugc\">Pricing Plans\u003C\u002Fa> |\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Ffaq.miniorange.com\u002F\" rel=\"nofollow ugc\">Support\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>WordPress 2FA Plugin Explained in Minutes\u003C\u002Fh3>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FrE-awZZt13Q?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch3>WordPress 2FA Core Features\u003C\u002Fh3>\n\u003Cp>miniOrange provides comprehensive \u003Cstrong>WordPress Two-Factor Authentication\u003C\u002Fstrong> and \u003Cstrong>Multi-Factor Authentication\u003C\u002Fstrong> capabilities for websites of all sizes.\u003C\u002Fp>\n\u003Ch3>Google Authenticator and OTP Authentication for WordPress\u003C\u002Fh3>\n\u003Cp>Secure WordPress logins using multiple \u003Cstrong>2FA\u003C\u002Fstrong> authentication methods:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Google Authenticator\u003C\u002Fstrong> (TOTP-based 2FA)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Microsoft Authenticator\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Authy Authenticator\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Duo Authenticator\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>LastPass Authenticator\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email OTP\u003C\u002Fstrong> Verification\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SMS OTP\u003C\u002Fstrong> Verification\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WhatsApp OTP\u003C\u002Fstrong> Authentication \u003Cem>(Premium)\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Telegram OTP\u003C\u002Fstrong> Authentication\u003C\u002Fli>\n\u003Cli>Security Questions (KBA)\u003C\u002Fli>\n\u003Cli>Backup Codes\u003C\u002Fli>\n\u003Cli>Hardware Token Authentication\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>WordPress MFA Policies and User Authentication\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Enforce \u003Cstrong>2FA\u003C\u002Fstrong> for all users\u003C\u002Fli>\n\u003Cli>Role-based \u003Cstrong>authentication\u003C\u002Fstrong> policies\u003C\u002Fli>\n\u003Cli>User-specific \u003Cstrong>MFA\u003C\u002Fstrong> settings\u003C\u002Fli>\n\u003Cli>Trusted device support\u003C\u002Fli>\n\u003Cli>Grace period configuration\u003C\u002Fli>\n\u003Cli>Backup authentication methods\u003C\u002Fli>\n\u003Cli>Force \u003Cstrong>2FA\u003C\u002Fstrong> setup on login\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>WooCommerce Two-Factor Authentication\u003C\u002Fh3>\n\u003Cp>Protect WooCommerce stores with enhanced login \u003Cstrong>security\u003C\u002Fstrong> and customer account protection.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Secure customer accounts with \u003Cstrong>WooCommerce 2FA\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Protect store managers and administrators\u003C\u002Fli>\n\u003Cli>Improve customer \u003Cstrong>WooCommerce login security\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Compatible with WooCommerce login and account pages\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Passwordless Login for WordPress\u003C\u002Fh3>\n\u003Cp>Allow users to securely access WordPress without traditional passwords.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Magic Link Login\u003C\u002Fli>\n\u003Cli>OTP Login (without password)\u003C\u002Fli>\n\u003Cli>Email Verification Login\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Login Security and Account Protection\u003C\u002Fh3>\n\u003Cp>Improve overall \u003Cstrong>WordPress login security\u003C\u002Fstrong> using advanced authentication controls.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Secure user verification\u003C\u002Fli>\n\u003Cli>Trusted device management\u003C\u002Fli>\n\u003Cli>Backup authentication options\u003C\u002Fli>\n\u003Cli>Account recovery methods\u003C\u002Fli>\n\u003Cli>Strong access control policies\u003C\u002Fli>\n\u003Cli>Login reports & IP alerts\u003C\u002Fli>\n\u003Cli>Custom redirects after login\u003C\u002Fli>\n\u003Cli>Custom SMS gateway integration \u003Cem>(Premium)\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>Custom branding & white labeling \u003Cem>(Premium)\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>Multisite support \u003Cem>(Premium)\u003C\u002Fem>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Works with Popular WordPress Plugins\u003C\u002Fh3>\n\u003Cp>Compatible with:\u003Cbr \u002F>\n– WooCommerce\u003Cbr \u002F>\n– Elementor\u003Cbr \u002F>\n– Ultimate Member\u003Cbr \u002F>\n– BuddyPress\u003Cbr \u002F>\n– Theme My Login\u003Cbr \u002F>\n– LoginPress\u003Cbr \u002F>\n– Custom login forms\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>Some \u003Cstrong>2FA\u003C\u002Fstrong> methods require communication with miniOrange services to send or verify OTP, SMS, email, push, or account-related requests. These services are used only when you configure or use the related \u003Cstrong>2FA\u003C\u002Fstrong> method.\u003C\u002Fp>\n\u003Cp>Service links:\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.miniorange.com\u002Fusecases\u002FminiOrange_User_Agreement.pdf\" rel=\"nofollow ugc\">miniOrange Terms\u003C\u002Fa> |\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.miniorange.com\u002Fprivacypolicy\" rel=\"nofollow ugc\">miniOrange Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n","Protect WordPress logins with Two-Factor Authentication (2FA), MFA, Google Authenticator, Email OTP, SMS OTP, WooCommerce 2FA & passwordless login.",10000,2447436,90,383,"2026-07-22T05:46:00.000Z","5.3.0",[18,19,51,20,74],"https:\u002F\u002Fminiorange.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fminiorange-2-factor-authentication.6.2.7.zip",93,10,"2025-08-23 00:00:00",{"slug":97,"name":98,"version":99,"author":100,"author_profile":101,"description":102,"short_description":103,"active_installs":104,"downloaded":105,"rating":106,"num_ratings":107,"last_updated":108,"tested_up_to":68,"requires_at_least":109,"requires_php":110,"tags":111,"homepage":113,"download_link":114,"security_score":23,"vuln_count":11,"unpatched_count":11,"last_vuln_date":24,"fetched_at":25},"rublon","Rublon Multi-Factor Authentication (MFA)","4.4.5","Rublon","https:\u002F\u002Fprofiles.wordpress.org\u002Frublon\u002F","\u003Cp>Rublon MFA is a multi-factor authentication (MFA) solution that protects your organization’s data and access to networks, servers, and applications. Rublon MFA provides MFA for cloud apps, VPNs, servers, and Microsoft technologies using authentication methods like \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fproduct\u002Fmobile-push\u002F\" rel=\"nofollow ugc\">Mobile Push\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fproduct\u002Fsms-passcodes\u002F\" rel=\"nofollow ugc\">SMS Passcode\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fproduct\u002Fqr-codes\u002F\" rel=\"nofollow ugc\">QR Code\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fproduct\u002Fsecurity-keys\u002F\" rel=\"nofollow ugc\">WebAuthn\u002FU2F Security Keys\u003C\u002Fa>, and more.\u003C\u002Fp>\n\u003Cp>Rublon MFA is easy to use, affordable, and scalable. It helps reduce compliance risk, improve user experience, and reduce costs. Rublon MFA is compatible with a variety of technologies, including but not limited to \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fdocs\u002F#vpn\" rel=\"nofollow ugc\">VPN\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fdoc\u002Frds\u002F\" rel=\"nofollow ugc\">Remote Desktop Services (RDS)\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fdoc\u002Fowa\u002F\" rel=\"nofollow ugc\">Outlook Web App (OWA)\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fproduct\u002Fldap-mfa\u002F\" rel=\"nofollow ugc\">LDAP\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fproduct\u002Fradius-mfa\u002F\" rel=\"nofollow ugc\">RADIUS\u003C\u002Fa>, and \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fdoc\u002Fwordpress\u002F\" rel=\"nofollow ugc\">WordPress\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Start your \u003Ca href=\"https:\u002F\u002Fadmin.rublon.net\u002Fauth\u002Fregister\" rel=\"nofollow ugc\">Free 30-Day Trial\u003C\u002Fa> and see how easy it is to get started with Rublon MFA.\u003C\u002Fh3>\n\u003Ch3>To learn more, visit \u003Ca href=\"https:\u002F\u002Frublon.com\u002F\" rel=\"nofollow ugc\">www.rublon.com\u003C\u002Fa>.\u003C\u002Fh3>\n\u003Cblockquote>\n\u003Ch4>Recommended by Security Experts and Industry Professionals\u003C\u002Fh4>\n\u003Cp>\u003Cem>“The fact that I could speak instantly with tech support while evaluating was super important. Connecting with Rublon technicians via remote sessions was SUPER handy to assist with setting things up.” &mdash; \u003Cstrong>Chris D., Manager of GIS\u002FIT\u003C\u002Fstrong>\u003C\u002Fem> \u003C\u002Fp>\n\u003Cp>  \u003Cem>“We were able to get Rublon MFA installed, tested, and in use in under a day across all offices.” &mdash; \u003Cstrong>Ethan M. Hospital & Health Care\u003C\u002Fstrong>\u003C\u002Fem> \u003C\u002Fp>\n\u003Cp>  \u003Cem>“Product was absolutely superb for integrating MFA into our RDS solution very easy to use and the moblie app was brilliant for our end users.” &mdash; \u003Cstrong>Scott L., IT Network Manager\u003C\u002Fstrong>\u003C\u002Fem> \u003C\u002Fp>\n\u003Cp>  \u003Cem>“we tested a trial version, it was very easy to set up. we got the pricing immediately. other suppliers did not even replied to my email yet and i already implemented Rublon” &mdash; \u003Cstrong>Mihail B., Logistics Manager\u003C\u002Fstrong>\u003C\u002Fem> \u003C\u002Fp>\n\u003Cp>  \u003Cem>“I searched for a tool for a very specific security need and Rublon filled that need perfectly. Not only does it work every single time as expected, the support and setup are amazing! Highly recommended.” &mdash; \u003Cstrong>Charles D., Financial Services\u003C\u002Fstrong>\u003C\u002Fem> \u003C\u002Fp>\n\u003Cp>  \u003Ca href=\"https:\u002F\u002Frublon.com\u002Fcustomers\u002F\" rel=\"nofollow ugc\">Read More\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>In What Languages Is Rublon For WordPress Available?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Japanese (translated by \u003Ca href=\"https:\u002F\u002Fen.digitalcube.jp\" rel=\"nofollow ugc\">Digital Cube\u003C\u002Fa>)\u003C\u002Fli>\n\u003Cli>Turkish (translated by Mehmet Emre Baş, proofread by Tarık Çayır)\u003C\u002Fli>\n\u003Cli>Polish\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cblockquote>\n\u003Ch4>Follow Us\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002FRublonApp\" rel=\"nofollow ugc\">Facebook\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002F2772205\" rel=\"nofollow ugc\">LinkedIn\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Ftwitter.com\u002Frublon\" rel=\"nofollow ugc\">Twitter\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>Legal notice\u003C\u002Fh3>\n\u003Cp>I have read and agree to the \u003Ca href=\"https:\u002F\u002Flegal.rublon.com\u002Ftos\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Flegal.rublon.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa> before installing the Rublon WordPress Plugin.\u003C\u002Fp>\n","Instant account security with effortless multi-factor authentication via Mobile Push, Mobile Passcode (TOTP), WebAuthn\u002FU2F Security Keys, and more.",400,117001,84,88,"2026-06-02T09:55:00.000Z","5.0","5.5.1",[18,51,112,20,74],"multi-factor-authentication","http:\u002F\u002Fwordpress.org\u002Fplugins\u002Frublon\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Frublon.4.4.5.zip",{"slug":116,"name":117,"version":118,"author":119,"author_profile":120,"description":121,"short_description":122,"active_installs":123,"downloaded":124,"rating":23,"num_ratings":125,"last_updated":126,"tested_up_to":14,"requires_at_least":109,"requires_php":16,"tags":127,"homepage":21,"download_link":129,"security_score":23,"vuln_count":11,"unpatched_count":11,"last_vuln_date":24,"fetched_at":25},"basecloud-shield","BaseCloud Shield","2.0.9","BaseCloud","https:\u002F\u002Fprofiles.wordpress.org\u002Fbasecloud\u002F","\u003Cp>BaseCloud Shield is a lightweight yet powerful security plugin that enforces Two-Factor Authentication (2FA) on your WordPress login page. Unlike other bloat-heavy plugins, BaseCloud Shield focuses on reliability and flexibility in OTP delivery.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Plug & Play:\u003C\u002Fstrong> Works immediately using standard WordPress email delivery.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-Recipient System:\u003C\u002Fstrong> Send OTPs to the logging-in user, a manager email, or selected users.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-Channel Delivery:\u003C\u002Fstrong> Choose multiple delivery methods simultaneously (Email, SendGrid, WhatsApp, SMS, Webhook).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WhatsApp Integration:\u003C\u002Fstrong> Send OTPs directly via WhatsApp using Twilio API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SMS Integration:\u003C\u002Fstrong> Deliver OTPs via SMS using Twilio API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SendGrid API V3:\u003C\u002Fstrong> Native integration for high-deliverability emails.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Webhook Support:\u003C\u002Fstrong> Connect to custom webhooks for advanced automation flows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure OTPs:\u003C\u002Fstrong> 6-digit one-time passwords that expire automatically.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Browser Trust:\u003C\u002Fstrong> “Remember this device” functionality to reduce friction for authorized users.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Attack Protection (v1.4.2):\u003C\u002Fstrong> Credential stuffing detection, progressive delays, username enumeration protection.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin may connect to external third-party services depending on your configuration. Below is a detailed explanation of what services are used, what data is sent, and when:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>SendGrid Email API (Optional)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If you select “SendGrid API” as your delivery method in the plugin settings, this plugin will send data to SendGrid’s email service to deliver one-time password (OTP) codes.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service\u003C\u002Fstrong>: SendGrid by Twilio\u003C\u002Fli>\n\u003Cli>\u003Cstrong>What it’s used for\u003C\u002Fstrong>: Sending two-factor authentication codes via email with improved deliverability\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When data is sent\u003C\u002Fstrong>: Every time a user attempts to log in and 2FA is enabled\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent\u003C\u002Fstrong>:\n\u003Cul>\n\u003Cli>Recipient email address (user’s email or manager email if configured)\u003C\u002Fli>\n\u003Cli>Sender email address (configured in plugin settings)\u003C\u002Fli>\n\u003Cli>Site name\u003C\u002Fli>\n\u003Cli>Username attempting to log in\u003C\u002Fli>\n\u003Cli>6-digit one-time password code\u003C\u002Fli>\n\u003Cli>Email subject and HTML body\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>API Endpoint\u003C\u002Fstrong>: https:\u002F\u002Fapi.sendgrid.com\u002Fv3\u002Fmail\u002Fsend\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service\u003C\u002Fstrong>: https:\u002F\u002Fwww.twilio.com\u002Flegal\u002Ftos\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fwww.twilio.com\u002Flegal\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Important\u003C\u002Fstrong>: You must have a SendGrid account and API key to use this feature. You are responsible for complying with SendGrid’s terms of service and ensuring proper data handling practices.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Twilio API for WhatsApp & SMS (Optional)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If you select “WhatsApp” or “SMS” as delivery methods, the plugin will send data to Twilio’s API to deliver one-time password codes.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service\u003C\u002Fstrong>: Twilio\u003C\u002Fli>\n\u003Cli>\u003Cstrong>What it’s used for\u003C\u002Fstrong>: Sending two-factor authentication codes via WhatsApp and\u002For SMS\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When data is sent\u003C\u002Fstrong>: Every time a user attempts to log in and 2FA is enabled with WhatsApp\u002FSMS selected\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent\u003C\u002Fstrong>:\n\u003Cul>\n\u003Cli>Recipient phone number (from user meta field ‘billing_phone’)\u003C\u002Fli>\n\u003Cli>Sender phone number (WhatsApp number or SMS number configured in settings)\u003C\u002Fli>\n\u003Cli>Site name\u003C\u002Fli>\n\u003Cli>Username attempting to log in\u003C\u002Fli>\n\u003Cli>6-digit one-time password code\u003C\u002Fli>\n\u003Cli>Message body\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>API Endpoint\u003C\u002Fstrong>: https:\u002F\u002Fapi.twilio.com\u002F2010-04-01\u002FAccounts\u002F{AccountSid}\u002FMessages.json\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service\u003C\u002Fstrong>: https:\u002F\u002Fwww.twilio.com\u002Flegal\u002Ftos\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fwww.twilio.com\u002Flegal\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Important\u003C\u002Fstrong>: You must have a Twilio account with WhatsApp and\u002For SMS capabilities enabled. Phone numbers must be stored in user meta (field: ‘billing_phone’). You are responsible for complying with Twilio’s terms of service.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Custom Webhook (Optional)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If you select “Webhook” as a delivery method, the plugin will send login notification data to a webhook URL you configure.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service\u003C\u002Fstrong>: Custom webhook endpoint (configured by you)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>What it’s used for\u003C\u002Fstrong>: Sending login notifications to external systems for custom processing\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When data is sent\u003C\u002Fstrong>: Every time a user attempts to log in and 2FA is enabled\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent\u003C\u002Fstrong>:\n\u003Cul>\n\u003Cli>Site name\u003C\u002Fli>\n\u003Cli>Username attempting to log in\u003C\u002Fli>\n\u003Cli>User email address\u003C\u002Fli>\n\u003Cli>6-digit one-time password code\u003C\u002Fli>\n\u003Cli>Recipient information array\u003C\u002Fli>\n\u003Cli>Timestamp of login attempt\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint\u003C\u002Fstrong>: User-configured webhook URL\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Important\u003C\u002Fstrong>: When using the webhook option, you are responsible for the security and privacy compliance of the endpoint you configure. Ensure your webhook endpoint uses HTTPS and follows proper data protection practices.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Standard WordPress Email (Default)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>By default, this plugin uses WordPress’s built-in \u003Ccode>wp_mail()\u003C\u002Fcode> function, which does not involve any external services unless your WordPress installation is configured to use a third-party SMTP service.\u003C\u002Fp>\n","Enterprise-grade Two-Factor Authentication (2FA) with support for Email, SendGrid API, Webhooks, WhatsApp, and SMS delivery.",40,1833,1,"2026-06-30T12:30:00.000Z",[18,19,128,20,36],"otp","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbasecloud-shield.2.0.9.zip",{"error":131,"url":132,"statusCode":133,"statusMessage":134,"message":134},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fbrightery-secure-2fa\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":125,"versions":136},[137],{"version":6,"download_url":22,"svn_tag_url":138,"released_at":24,"has_diff":139,"diff_files_changed":140,"diff_lines":24,"trac_diff_url":24,"vulnerabilities":141,"is_current":131},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbrightery-secure-2fa\u002Ftags\u002F1.0.0\u002F",false,[],[]]