跳至内容
WordPress.org

China 简体中文

  • 主题
  • 插件
  • 新闻
    • 文档
    • 论坛
  • 关于
  • 获取 WordPress
获取 WordPress
WordPress.org

Plugin Directory

Flavor 2FA

  • 提交插件
  • 我的收藏
  • 登录
  • 提交插件
  • 我的收藏
  • 登录

Flavor 2FA

作者:kuckovic
下载
  • 详情
  • 评价
  • 安装
  • 开发进展
支持

描述

Flavor 2FA adds powerful two-factor authentication to your WordPress site without the complexity. No bloat, no confusing settings – just solid security that protects your site from unauthorized access.

Why Flavor 2FA?

  • Zero configuration needed – Works out of the box
  • Native WordPress styling – Feels like part of WordPress
  • Two verification methods – Authenticator apps (Google Authenticator, Authy, 1Password) or email codes
  • User-friendly setup – Guided 3-step process with QR code scanning
  • Complete admin control – Force 2FA, reset users, manage lockouts

Features

For Users:
* Choose between authenticator app or email verification
* 10 recovery codes for emergency access
* “Trust this device” option to skip 2FA on personal devices
* Simple, clean verification screens

For Admins:
* Require 2FA for specific user roles
* Grace period for new users
* Force immediate 2FA setup on next login
* Lockout protection against brute force attacks
* Reset 2FA or unlock accounts with one click
* See 2FA status for all users at a glance

Perfect For

  • Agencies managing client sites
  • WooCommerce stores handling sensitive data
  • Membership sites with user accounts
  • Any WordPress site that needs extra security

External services

This plugin uses a third-party service to generate QR codes during the TOTP authenticator app setup process.

QR Server API

When a user chooses the “Authenticator App” method during 2FA setup, the plugin generates a QR code image via the QR Server API. This QR code contains the TOTP secret URI (which includes the site name, user email, and secret key) so the user can scan it with their authenticator app.

  • What data is sent: A TOTP provisioning URI containing the site name, user email address, and a generated secret key.
  • When it is sent: Only once, when a user sets up TOTP-based two-factor authentication. No data is sent during normal login verification.
  • Service provider: goQR.me / QR Server
  • Service URL: https://goqr.me/api/
  • Terms of service: https://goqr.me/api/doc/
  • Privacy policy: https://goqr.me/privacy-policy/

安装

  1. Upload flavor-2fa to /wp-content/plugins/
  2. Activate through ‘Plugins’ menu
  3. Go to Settings → Flavor 2FA
  4. Select which user roles require 2FA
  5. Done! Users will be prompted to set up 2FA on their next login

常见问题

Which authenticator apps are supported?

Any TOTP-compatible app works: Google Authenticator, Authy, 1Password, Microsoft Authenticator, LastPass Authenticator, and more.

What if a user loses their phone?

Users receive 10 one-time recovery codes during setup. If those are also lost, an admin can reset their 2FA from the Users page or plugin settings.

Can I require 2FA only for administrators?

Yes! You can choose exactly which user roles must enable 2FA. Common setups include requiring it for Administrators and Editors while leaving it optional for Subscribers.

Is there a grace period for new users?

Yes, configurable from 0-365 days. New users won’t be forced to set up 2FA until the grace period expires.

What happens when 2FA is deactivated?

All plugin data is automatically cleaned up, including user secrets and recovery codes. Nothing is left behind.

评价

此插件暂无评价。

贡献者及开发者

「Flavor 2FA」是开源软件。 以下人员对此插件做出了贡献。

贡献者
  • kuckovic

帮助将「Flavor 2FA」翻译成简体中文。

对开发感兴趣吗?

您可以浏览代码,查看SVN仓库,或通过RSS订阅开发日志。

更新日志

1.0.0

  • Initial release

额外信息

  • 版本 1.0.0
  • 最后更新:4 月前
  • 活跃安装数量 不到10
  • WordPress 版本 5.0 或更高版本
  • 已测试的最高版本为 6.9.4
  • PHP 版本 8.0 或更高版本
  • 语言
    English (US)
  • 标签
    2FAloginsecuritytotptwo factor authentication
  • 高级视图

评级

尚未提交反馈。

Your review

查看全部评论

贡献者

  • kuckovic

支持

有话要说吗?是否需要帮助?

查看支持论坛

  • 关于
  • 新闻
  • 主机
  • 隐私
  • 陈列窗
  • 主题
  • 插件
  • 区块样板
  • 学习
  • 支持
  • 开发者
  • WordPress.tv ↗︎
  • 参与
  • 活动
  • 捐赠 ↗
  • 未来五分计划
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

China 简体中文

  • 关注我们的 X(原 Twitter)账号
  • 访问我们的 Bluesky 账号
  • 关注我们的 Mastodon 账号
  • 访问我们的 Threads 账号
  • 访问我们的 Facebook 公共主页
  • 关注我们的 Instagram 账号
  • 关注我们的 LinkedIn 主页
  • 访问我们的 TikTok 账号
  • 访问我们的 YouTube 频道
  • 访问我们的 Tumblr 账号
代码如诗
The WordPress® trademark is the intellectual property of the WordPress Foundation.