[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5RrqZfL0miqsuXUtKOGME_PTjGd31a83mRhKcdlmKSg":3,"$fljPfYyHqao0ineDK_Ah7LghXneK-Mwatmti_E-eyDkc":126,"$fhmsGAekd-W021MEu0e-dEHiGrKbPG4AzMIYxPiC78ZQ":131},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":26,"fingerprints":26},"configify-2fa","Configify 2FA","1.0.0","Configify","https:\u002F\u002Fprofiles.wordpress.org\u002Fconfigify\u002F","\u003Cp>Configify 2FA adds Two-Factor Authentication to every important action on your WordPress site, all configurable from a single settings page.\u003C\u002Fp>\n\u003Cp>Choose the method that fits your audience:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Google Authenticator (TOTP) — RFC 6238 compliant. Works with Google Authenticator, Authy, Microsoft Authenticator, 1Password, Bitwarden, and any TOTP app.\u003C\u002Fli>\n\u003Cli>Math CAPTCHA — Server-side arithmetic challenge. No external dependencies. Works offline.\u003C\u002Fli>\n\u003Cli>Google reCAPTCHA — v2 (checkbox) or v3 (invisible, score-based).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Protect any combination of:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Login (wp-login.php + WooCommerce)\u003C\u002Fli>\n\u003Cli>Registration (WordPress + WooCommerce)\u003C\u002Fli>\n\u003Cli>Forgot Password\u003C\u002Fli>\n\u003Cli>Change \u002F Reset Password\u003C\u002Fli>\n\u003Cli>Comment Submission\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What makes Configify 2FA different\u003C\u002Fh4>\n\u003Cp>Security Audit Dashboard — Every 2FA event (success, failure, lockout, setup, method change) is recorded with username, IP address, user agent, and timestamp. Filter, search, and export to CSV directly from your admin panel.\u003C\u002Fp>\n\u003Cp>Trusted Device Memory — After verifying, users can choose to trust their current device for a set number of days. Subsequent logins from that device skip the 2FA step. Tokens are cryptographically random and bound to the user agent. Admins can revoke trusted devices per user from the profile screen.\u003C\u002Fp>\n\u003Cp>Brute-Force Lockout — Repeated 2FA failures trigger a configurable lockout by user and IP address to stop automated attacks.\u003C\u002Fp>\n\u003Cp>Email OTP Fallback — When TOTP is active but a user has not yet set up their authenticator app, a 6-digit one-time code is sent to their email address as a fallback.\u003C\u002Fp>\n\u003Cp>Per-Role Enforcement — Require 2FA only for Administrators, Editors, or any custom role. Leave all unchecked to apply to every role.\u003C\u002Fp>\n\u003Cp>WooCommerce Support — Hooks into WooCommerce login, registration, lost password, and account password change, not just the default WordPress forms.\u003C\u002Fp>\n\u003Ch4>Security Details\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>TOTP implementation is pure PHP with no third-party library dependency. Secrets are stored in WordPress user-meta and never exposed in plain text.\u003C\u002Fli>\n\u003Cli>Math CAPTCHA answers are stored in server-side transients with a 10-minute TTL and consumed on first use.\u003C\u002Fli>\n\u003Cli>Pending login sessions are stored in a custom database table, expire after 10 minutes, and are purged daily via WP-Cron.\u003C\u002Fli>\n\u003Cli>Trusted device tokens are cryptographically random (48 characters), hashed with wp_hash() before storage, and bound to the user agent string.\u003C\u002Fli>\n\u003Cli>All form submissions require a WordPress nonce in addition to the 2FA challenge.\u003C\u002Fli>\n\u003Cli>TOTP verification includes a clock-skew tolerance of plus or minus two 30-second windows to account for imprecise device clocks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the following external services. No data is ever sent to Configify servers.\u003C\u002Fp>\n\u003Ch4>Google reCAPTCHA\u003C\u002Fh4>\n\u003Cp>This plugin can use Google reCAPTCHA to protect forms. It is only active when the admin selects reCAPTCHA as the 2FA method.\u003C\u002Fp>\n\u003Cp>It sends the user’s IP address and a browser interaction token to Google’s servers each time a protected form is submitted.\u003C\u002Fp>\n\u003Cp>This service is provided by Google LLC: \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>goQR.me QR Code API\u003C\u002Fh4>\n\u003Cp>This plugin uses the goQR.me API (api.qrserver.com) to generate QR code images for Google Authenticator setup. It is only used when a user clicks “Generate QR Code” on the Settings page while TOTP is the active method.\u003C\u002Fp>\n\u003Cp>It sends the TOTP URI — which contains the site name, the user’s email address, and the TOTP secret — to api.qrserver.com to generate the QR code image. The service does not store or log QR code contents. The generated image is cached for approximately 30 seconds and then deleted.\u003C\u002Fp>\n\u003Cp>This service is provided by goQR.me: \u003Ca href=\"https:\u002F\u002Fgoqr.me\u002Flegal\u002Ftos-api.html\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgoqr.me\u002Fprivacy-safety-security\u002F\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>WooCommerce Compatibility\u003C\u002Fh4>\n\u003Cp>Configify 2FA integrates with WooCommerce out of the box with no additional configuration. It hooks into:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>woocommerce_process_login_errors\u003C\u002Fli>\n\u003Cli>woocommerce_process_registration_errors\u003C\u002Fli>\n\u003Cli>woocommerce_lostpassword_form\u003C\u002Fli>\n\u003Cli>woocommerce_edit_account_form\u003C\u002Fli>\n\u003Cli>woocommerce_save_account_details_errors\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>Configify 2FA stores the following data locally on your server:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>A TOTP secret and confirmation flag in wp_usermeta.\u003C\u002Fli>\n\u003Cli>Trusted device token hashes and expiry timestamps in wp_usermeta.\u003C\u002Fli>\n\u003Cli>Pending session tokens in a custom table (wp_c2fa_sessions) — deleted automatically after 10 minutes.\u003C\u002Fli>\n\u003Cli>Security audit log entries in a custom table (wp_c2fa_audit_log) — pruned automatically after the configured retention period (default 90 days).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All data is removed when the plugin is deleted (via uninstall.php).\u003C\u002Fp>\n","Flexible Two-Factor Authentication for WordPress. Choose Google Authenticator (TOTP), Math CAPTCHA, or Google reCAPTCHA — with a security audit log.",0,116,"2026-06-16T23:52:00.000Z","7.0.2","5.8","7.4",[18,19,20,21,22],"2fa","login","security","two-factor-authentication","woocommerce","https:\u002F\u002Fconfigify.ca\u002Fconfigify-2fa","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fconfigify-2fa.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"configify",1,30,94,"2026-08-29T17:04:51.312Z",[37,57,73,91,108],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":14,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":55,"download_link":56,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"wordfence-login-security","Wordfence Login Security","1.1.16","wfryan","https:\u002F\u002Fprofiles.wordpress.org\u002Fwfryan\u002F","\u003Ch3>WORDFENCE LOGIN SECURITY\u003C\u002Fh3>\n\u003Cp>Wordfence Login Security contains a subset of the functionality found in the full Wordfence plugin: Two-factor Authentication, XML-RPC Protection, and Login Page CAPTCHA.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>This plugin is being discontinued on or around July 1, 2026.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All of its features are already included in the main Wordfence plugin, which is also available to use for free. We recommend installing Wordfence to continue receiving updates, security improvements, and full functionality.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwordfence\u002F\" rel=\"ugc\">Install the full Wordfence plugin\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Two-factor authentication (2FA), one of the most secure forms of remote system authentication available.\u003C\u002Fli>\n\u003Cli>Use any TOTP-based authenticator app or service like Google Authenticator, Authy, 1Password or FreeOTP.\u003C\u002Fli>\n\u003Cli>Enable 2FA for any WordPress user role.\u003C\u002Fli>\n\u003Cli>Completely free to use, no limits or restrictions of any kind.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>LOGIN PAGE CAPTCHA\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Easily enable Google ReCAPTCHA v3 on your login and registration pages.\u003C\u002Fli>\n\u003Cli>Stops bots from logging in without inconveniencing your site visitors.\u003C\u002Fli>\n\u003Cli>Robust protection against password guessing and credential stuffing attacks distributed across large IP pools\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>XML-RPC PROTECTION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>XML-RPC is the biggest target for WordPress attacks, but is often overlooked.\u003C\u002Fli>\n\u003Cli>Protect XML-RPC with 2FA or disable it altogether if it’s not needed.\u003C\u002Fli>\n\u003C\u002Ful>\n","Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.",60000,1329360,78,26,"2026-04-29T15:29:00.000Z","4.7","7.0",[18,53,54,20,21],"captcha","login-security","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwordfence-login-security.1.1.16.zip",{"slug":58,"name":59,"version":60,"author":61,"author_profile":62,"description":63,"short_description":64,"active_installs":65,"downloaded":66,"rating":25,"num_ratings":32,"last_updated":67,"tested_up_to":14,"requires_at_least":68,"requires_php":16,"tags":69,"homepage":55,"download_link":72,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"loginarmor-email-2fa","LoginArmor – Email 2FA","1.2","TechArk Solutions","https:\u002F\u002Fprofiles.wordpress.org\u002Fgotechark\u002F","\u003Cp>LoginArmor adds an extra layer of protection to WordPress logins by requiring a one-time verification code after a valid username and password are entered.\u003C\u002Fp>\n\u003Ch4>Key features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Email-based one-time passcodes for WordPress logins\u003C\u002Fli>\n\u003Cli>Apply 2FA to selected user roles\u003C\u002Fli>\n\u003Cli>Apply 2FA to specific users\u003C\u002Fli>\n\u003Cli>Optional grace period before activation is enforced\u003C\u002Fli>\n\u003Cli>Recovery codes for backup access\u003C\u002Fli>\n\u003Cli>Customizable email subject and login code email template\u003C\u002Fli>\n\u003Cli>Optional debug logging to \u003Ccode>wp-content\u002Fuploads\u002Floginarmor-email-2fa\u002Floginarmor-debug.log\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Automatic log rotation to prevent unbounded log file growth\u003C\u002Fli>\n\u003Cli>Compatible with WordPress application passwords and REST API clients\u003C\u002Fli>\n\u003Cli>Dedicated settings screen inside the WordPress admin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How it works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>A user enters a valid username and password.\u003C\u002Fli>\n\u003Cli>LoginArmor sends a one-time code to the user’s email address.\u003C\u002Fli>\n\u003Cli>The user enters the code to complete login.\u003C\u002Fli>\n\u003Cli>If needed, the user can use a recovery code instead.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Recovery codes\u003C\u002Fh4>\n\u003Cp>The plugin includes recovery codes as a backup login option. Codes are stored securely as hashes in user meta. Plaintext codes are shown only temporarily so users can save or download them once.\u003C\u002Fp>\n\u003Ch4>Grace period\u003C\u002Fh4>\n\u003Cp>You can optionally set a grace period in days. During the grace period, eligible users can continue signing in while they complete activation. After the grace period ends, 2FA is enforced.\u003C\u002Fp>\n\u003Ch4>No external service required\u003C\u002Fh4>\n\u003Cp>LoginArmor uses WordPress email delivery and does not require a third-party 2FA service.\u003C\u002Fp>\n\u003Ch4>Developer notes\u003C\u002Fh4>\n\u003Cp>The plugin exposes a filter for sites running behind a reverse proxy (Cloudflare, load balancers, etc.) that need to supply the real visitor IP:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>add_filter( 'la2fa_get_client_ip', function( $ip ) {\n    return $_SERVER['HTTP_CF_CONNECTING_IP'] ?? $_SERVER['REMOTE_ADDR'] ?? 'unknown';\n} );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Without this filter the plugin behaves exactly as before — it reads \u003Ccode>REMOTE_ADDR\u003C\u002Fcode> by default.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>LoginArmor does not connect to an external third-party verification service.\u003C\u002Fp>\n\u003Cp>The plugin may process and store the following data on your WordPress site:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Email-based one-time passcodes for login verification\u003C\u002Fli>\n\u003Cli>Recovery code hashes stored in user meta\u003C\u002Fli>\n\u003Cli>Optional debug log entries in \u003Ccode>wp-content\u002Fuploads\u002Floginarmor-email-2fa\u002Floginarmor-debug.log\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Temporary transients used for login, cooldown, and verification flow\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This data stays on your site unless your own email delivery system or hosting stack routes it elsewhere.\u003C\u002Fp>\n","Add secure email-based 2FA authentication to WordPress logins with OTP verification, recovery codes, a grace period, and flexible user targeting.",10,323,"2026-06-05T06:59:00.000Z","6.0",[18,70,54,71,21],"email-otp","recovery-codes","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Floginarmor-email-2fa.1.2.zip",{"slug":74,"name":75,"version":76,"author":77,"author_profile":78,"description":79,"short_description":80,"active_installs":65,"downloaded":81,"rating":11,"num_ratings":11,"last_updated":82,"tested_up_to":83,"requires_at_least":84,"requires_php":85,"tags":86,"homepage":88,"download_link":89,"security_score":90,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"passclip-auth-for-wordpress","PassClip Auth for WordPress","1.0.5","Passlogy","https:\u002F\u002Fprofiles.wordpress.org\u002Fpasslogy\u002F","\u003Cp>You need strong password to protect your site. However, how do you remember it or is it really strong?\u003Cbr \u002F>\n“PassClip Auth” provides really strong password that is also easy to remember.\u003Cbr \u002F>\nOnce you make your “pattern”, you can get your password using “PassClip”. And the password will change every 30 seconds(at the shortest).\u003C\u002Fp>\n\u003Ch4>Get and sign up for PassClip\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Ca href=\"https:\u002F\u002Fwww.passclip.com\u002F\" rel=\"nofollow ugc\">the page about PassClip\u003C\u002Fa> and install PassClip on your smart phone.\u003C\u002Fli>\n\u003Cli>Activate your PassClip by registering your “pattern” and email address.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Sign up for PassClip Auth(PCA)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Input PassClip Code “paauth” in your PassClip. That makes a new slot in your PassClip.\u003C\u002Fli>\n\u003Cli>Go to \u003Ca href=\"https:\u002F\u002Fmember.passclip.com\u002Fmember\u002Fui\u002F\" rel=\"nofollow ugc\">PassClip Auth member’s page\u003C\u002Fa> and log in with your email address and password which the slot shows you.\u003C\u002Fli>\n\u003Cli>Make your “PassClip Code”. And then you get your “PassClip Auth app service id(PCA app service id)”. You need both “code” and “id” to use this plugin.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>How to apply PassClip Auth to your site\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install and activate this plugin to your WordPress.\u003C\u002Fli>\n\u003Cli>Go to PassClip Auth Options Setting from the menu.\u003C\u002Fli>\n\u003Cli>Input the PassClip Auth app service id(PCA app service id), PassClip Code and other items in the setting page and click the “Save Change” button.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>How to log in to WordPress site with PassClip Auth\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Users register PassClip Code of your site in their PassClip. That makes a new slot to get password to log in to your site.\u003C\u002Fli>\n\u003Cli>Show the password in PassClip (tap the new slot).\u003C\u002Fli>\n\u003Cli>In login form of your site, users enter email address and password in the slot. (\u003Cstrong>Users do not need general WordPress password.\u003C\u002Fstrong>)\u003C\u002Fli>\n\u003Cli>Click the “Log in” button.\u003C\u002Fli>\n\u003C\u002Fol>\n","\"PassClip Auth\" provides strong and easy authentication. \"PassClip Auth for WordPress\" is the plugin to launch PassClip Auth to Wo &hellip;",2639,"2019-12-27T07:42:00.000Z","5.3.21","4.5","5.3.3",[18,19,87,20,21],"otp","https:\u002F\u002Fwww.passclip.com\u002Fja\u002Fpca\u002Fpca_for_wp\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpassclip-auth-for-wordpress.1.0.6.zip",85,{"slug":92,"name":93,"version":94,"author":95,"author_profile":96,"description":97,"short_description":98,"active_installs":11,"downloaded":99,"rating":11,"num_ratings":11,"last_updated":100,"tested_up_to":101,"requires_at_least":102,"requires_php":103,"tags":104,"homepage":105,"download_link":106,"security_score":107,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"4login-for-secure-and-smart-access","4Login for Secure And Smart Access","0.1.0","4login","https:\u002F\u002Fprofiles.wordpress.org\u002F4login\u002F","\u003Cp>Secure your site with a strong password — without the hassle of remembering it.\u003Cbr \u002F>\nWith 4Login, you get simple yet powerful authentication that connects to an external server.\u003Cbr \u002F>\nSimply create your own pattern to generate a dynamic password that updates every 60 minutes.\u003C\u002Fp>\n\u003Cp>Please refer to the \u003Ca href=\"https:\u002F\u002Fwww.4login.jp\u002F\" rel=\"nofollow ugc\">operation Instructions \u003C\u002Fa> for instructions on how to use 4Login.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to an external API to enable 4Login authentication.\u003Cbr \u002F>\nWhen logging in with 4Login, the plugin sends the 4Login App Service ID, the user’s email address, and a dynamic password .\u003Cbr \u002F>\nThese credentials are entered directly within the WordPress login interface.\u003C\u002Fp>\n\u003Cp>This authentication service is provided by Passlogy.\u003Cbr \u002F>\nFor more information, please review our\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.4login.jp\u002Fen\u002Fauto_terms\u002F\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> and\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.4login.jp\u002Fprivacy-policy\u002F?en=app\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fp>\n","4Login will give you an easy and powerful authentication (connect to an external server for authentication).",696,"2025-06-19T05:41:00.000Z","6.8.6","6.7","8.0",[18,19,87,20,21],"https:\u002F\u002Fwww.4login.jp\u002F4login-for-secure-and-smart-access\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F4login-for-secure-and-smart-access.0.1.0.zip",92,{"slug":109,"name":110,"version":111,"author":112,"author_profile":113,"description":114,"short_description":115,"active_installs":11,"downloaded":116,"rating":25,"num_ratings":117,"last_updated":118,"tested_up_to":119,"requires_at_least":120,"requires_php":16,"tags":121,"homepage":123,"download_link":124,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":125},"av-2fa","AV 2FA","1.2.0","Avrasys","https:\u002F\u002Fprofiles.wordpress.org\u002Favrasys\u002F","\u003Cp>AV 2FA adds a crucial layer of security to your WordPress login process. After a user successfully enters their password, this plugin sends a unique, time-sensitive verification code to their registered email address. The user must then enter this code to complete the login, effectively protecting their account even if their password is compromised.\u003C\u002Fp>\n\u003Cp>The plugin is designed to be lightweight, easy to use, and seamlessly integrated into the WordPress experience.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Email-Based 2FA:\u003C\u002Fstrong> Sends a 6-digit verification code to the user’s email.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Login URL:\u003C\u002Fstrong> Hide your login page by setting a custom login slug. The default wp-login.php becomes inaccessible, protecting against brute force attacks and bots.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate Limiting & Account Lockout:\u003C\u002Fstrong> Protects against brute force attacks on 2FA codes with configurable thresholds and temporary lockouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Progressive Lockout:\u003C\u002Fstrong> Automatically increases lockout duration for repeat offenders (2x, 4x, 8x multiplier).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP-Based Protection:\u003C\u002Fstrong> Tracks failed attempts by IP address to prevent distributed attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Notifications:\u003C\u002Fstrong> Alerts users when their account is locked due to suspicious activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Controls:\u003C\u002Fstrong> View and manually unlock locked accounts from the settings page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable Code Validity:\u003C\u002Fstrong> Admin can set how long the code is valid for (default is 60 seconds).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Exclusion List:\u003C\u002Fstrong> Easily bypass 2FA for specific users (e.g., admin or integration accounts) by adding their User ID to an exclusion list.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Countdown Timer:\u003C\u002Fstrong> The verification screen displays a countdown timer to show the user how much time is left.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure & Reliable:\u003C\u002Fstrong> Uses WordPress’s built-in mailer and secure practices for code generation and verification.\u003C\u002Fli>\n\u003C\u002Ful>\n","A simple and secure Two-Factor Authentication plugin that sends a verification code to your email.",334,2,"2026-01-10T19:54:00.000Z","6.9.4","5.2",[18,122,20,21],"secure-login","https:\u002F\u002Favrasys.hu\u002Fletoltes\u002Fav-2fa-wordpress-ketfaktoros-hitelesites-bovitmeny","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fav-2fa.1.2.0.zip","2026-04-16T10:56:18.058Z",{"error":127,"url":128,"statusCode":129,"statusMessage":130,"message":130},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fconfigify-2fa\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":32,"versions":132},[133],{"version":6,"download_url":24,"svn_tag_url":134,"released_at":26,"has_diff":135,"diff_files_changed":136,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":137,"is_current":127},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fconfigify-2fa\u002Ftags\u002F1.0.0\u002F",false,[],[]]