ຂ້າມໄປທີ່ເນື້ອຫາ
WordPress.org

ລາວ

  • ທິມ
  • ປັກອິນ
  • ຂ່າວ
  • ກ່ຽວກັບ
  • ທິມລາວ
  • ຕິດຕໍ່
  • ດາວໂຫລດ WordPress
ດາວໂຫລດ WordPress
WordPress.org

Plugin Directory

Gupti 2FA

  • ສົ່ງປລັກອິນ
  • ທີ່ມັກຂອງຂ້ອຍ
  • ເຂົ້າສູ່ລະບົບ
  • ສົ່ງປລັກອິນ
  • ທີ່ມັກຂອງຂ້ອຍ
  • ເຂົ້າສູ່ລະບົບ

Gupti 2FA

ໂດຍ plexomedia
ດາວໂຫຼດ
  • ລາຍລອຽດ
  • ການຣີວິວ
  • ການຕິດຕັ້ງ
  • ການພັດທະນາ
ການຊ່ວຍເຫຼືອ

ຄຳອະທິບາຍ

Gupti 2FA adds an extra layer of security to your WordPress site by requiring a time-based one-time password (TOTP) from Google Authenticator (or any compatible app) at login. Everything runs locally on your server — no third-party APIs, no account signup, no data leaves your site.

For users:

  • Easy setup via QR code — scan and go, or enter the secret key manually.
  • Works with Google Authenticator, Authy, Microsoft Authenticator, 1Password, and any TOTP app.
  • 8 one-time recovery codes in case you lose your device.
  • Verification code required when enabling, so you can never lock yourself out by mistake.
  • Clean, distraction-free verification page at login.

For admins:

  • Modern dashboard with 2FA coverage stats across your site.
  • Role-based enforcement — require 2FA for administrators, editors, or any role.
  • Optional grace period so enforced users get time to set up.
  • Choose where users complete setup: right after login, or inside the dashboard.
  • 2FA Status Report — see who has 2FA enabled and reset a user’s 2FA in one click.
  • Login page branding — add your own logo to the verification pages.

Security hardening built in:

  • TOTP secrets are encrypted at rest (AES-256-GCM keyed from your site’s salts).
  • Rate limiting on all verification steps — codes can’t be brute-forced.
  • Replay protection — a used code is never accepted twice.
  • Recovery codes are stored hashed and each works only once.
  • QR codes are generated locally in pure PHP — nothing is sent to external services.
  • No external fonts, scripts, or API calls anywhere.

Development

The admin dashboard is built with React and Vite. The uncompiled, human-readable source is included in the plugin’s app/ directory. To rebuild the compiled files in assets/dist/, run npm install followed by npm run build inside the app/ directory.

ການຕິດຕັ້ງ

  1. Upload the gupti-2fa folder to /wp-content/plugins/, or install via Plugins → Add New.
  2. Activate the plugin through the Plugins menu in WordPress.
  3. To enable 2FA for yourself: go to your Profile page, scan the QR code with your authenticator app, and enter the 6-digit code to verify.
  4. To enforce 2FA for user roles: go to Gupti 2FA → Configuration, select the roles, and save.

ຄຳຖາມທີ່ພົບເລື້ອຍ

What if I lose my phone?

Use one of your 8 recovery codes on the login screen to complete verification, then reconfigure 2FA from your profile. If you have lost the recovery codes too, a site administrator can reset your 2FA from the 2FA Status Report.

Can I require 2FA only for administrators?

Yes. Go to Gupti 2FA → Configuration and select only the roles you want to enforce — for example, just Administrators. Other users can still enable 2FA voluntarily from their profile page.

Will this plugin slow down my site?

No. The plugin makes no external API calls and loads its scripts and styles only on the login page and its own admin pages. Your site’s front end is completely unaffected.

Does this work with custom login pages?

It hooks into WordPress core authentication, so it works with any theme or plugin that uses the standard wp_authenticate / wp_login_url flow.

Does it send my data anywhere?

No. Secrets are generated, stored (encrypted), and verified entirely on your own server. QR codes are rendered locally in PHP. The plugin makes no external requests.

Will REST API or XML-RPC logins bypass 2FA?

No. Password-based programmatic logins are blocked for 2FA-enabled accounts. Use WordPress application passwords for API access — they are unaffected.

Where can I get support?

Use the plugin support forum on WordPress.org, or email us at hello@plexomedia.com.

ການຣີວິວ

ບໍ່ມີການຣີວິວສຳລັບປລັກອິນນີ້.

ຜູ້ຮ່ວມພັດທະນາ ແລະ ຜູ້ພັດທະນາ

“Gupti 2FA” ແມ່ນຊອຟແວໂອເພັນຊອດ (Open Source). ບຸກຄົນຕໍ່ໄປນີ້ໄດ້ມີສ່ວນຮ່ວມໃນການພັດທະນາປລັກອິນນີ້.

ຜູ້ຮ່ວມພັດທະນາ
  • plexomedia

ແປ “Gupti 2FA” ເປັນພາສາຂອງເຈົ້າ.

ສົນໃຈຮ່ວມພັດທະນາບໍ່?

ເບິ່ງລະຫັດ, ກວດເບິ່ງ ຄັງເກັບ SVN, ຫຼື ຕິດຕາມ ບັນທຶກການພັດທະນາ ຜ່ານ RSS.

ບັນທຶກການປ່ຽນແປງ

1.0.0

  • Initial release.

ຂໍ້ມູນກຳກັບ (Meta)

  • ເວີຊັນ 1.0.0
  • ອັບເດດຫຼ້າສຸດເມື່ອ 4 ອາທິດ ທີ່ຜ່ານມາ ທີ່ຜ່ານມາ
  • ການຕິດຕັ້ງທີ່ໃຊ້ງານຢູ່ ໜ້ອຍກວ່າ 10
  • ເວີຊັນ WordPress 6.0 ຫຼື ສູງກວ່າ
  • ທົດສອບເຖິງເວີຊັນ 7.0.5
  • ເວີຊັນ PHP 7.4 ຫຼື ສູງກວ່າ
  • ພາສາ
    English (US)
  • ແທັກ
    2FAgoogle authenticatorlogin securitytotptwo factor
  • ມຸມມອງຂັ້ນສູງ

ການໃຫ້ຄະແນນ

ຍັງບໍ່ມີການສົ່ງຄຳວິຈານເທື່ອ.

ການທົບທວນຂອງທ່ານ

ເບິ່ງທັງໝົດ ການຣີວິວ

ຜູ້ຮ່ວມພັດທະນາ

  • plexomedia

ການຊ່ວຍເຫຼືອ

ມີຄຳຖາມ ຫຼື ຕ້ອງການຄວາມຊ່ວຍເຫຼືອບໍ່?

ເບິ່ງຟໍຣັມການຊ່ວຍເຫຼືອ

  • ກ່ຽວກັບ
  • ຂ່າວສານ
  • ໂຮສຕິງ
  • ຄວາມເປັນສ່ວນຕົວ
  • ງານທີ່ໂດດເດັ່ນ
  • ທີມ
  • ປລັກອິນ
  • ຮູບແບບບລັອກ
  • ຮຽນຮູ້
  • ຊ່ວຍເຫຼືອ
  • ນັກພັດທະນາ
  • WordPress.tv ↗
  • ມີສ່ວນຮ່ວມ
  • ກິດຈະກຳ
  • ບໍລິຈາກ ↗
  • ຂອງທີ່ລະນຶກ ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

ລາວ

  • ຢ້ຽມຊົມບັນຊີ X (ຊື່ເກົ່າ Twitter) ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ Bluesky ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ Mastodon ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ Threads ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມໜ້າ Facebook ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ Instagram ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ LinkedIn ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ TikTok ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມຊ່ອງ YouTube ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ Tumblr ຂອງພວກເຮົາ
Code is Poetry.
The WordPress® trademark is the intellectual property of the WordPress Foundation.