Security plugin that adds per-role two-factor authentication to the WordPress login flow.
Information
Author:
ROBOTSTXTDownload
Price:
€0.00Requirements
Version:
1.6.0WordPress:
6.4–
7.0PHP >=
8.0Changelog
1.6.0
Release date: 2026-08-07
Added
- REST API (namespace
robotstxt-2fa/v1, admin-only):GET/PUT /settingsto read and update the full configuration;GET /users?role=&status=to list users with their 2FA status (enabled, configured methods, required methods, forced, frequency, preferred method, OTP configured, unused recovery codes). No secrets exposed.
Changed
wp 2fa list— separate Enabled, Methods, and Required columns; new--requiredfilter.
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer / WPCS — 0 errors
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 55 tests, 140 assertions
1.5.3
Release date: 2026-08-07
Added
- Per-user preferred sign-in method — “Preferred method” dropdown on the user profile (shown when two or more methods are enabled) lets each user pick which verification method is requested first at login.
- Failed attempts are now cleared for the user on any successful 2FA login (email, OTP, or recovery), so no errors remain queued once they authenticate correctly.
- GeoIP auto-download — optional “Use the free ROBOTSTXT GeoIP database” checkbox in 2FA > Settings downloads the country database from ip.robotstxt.es into the uploads directory and refreshes it daily via WordPress cron. Includes a manual “Update now” button.
Fixed
- Security: the “Require 2FA to create Application Passwords” guard could be bypassed by requesting
/wp/v2/users/me/application-passwords(the regex only matched numeric user IDs). Now accepts themealias.
Changed
- Role enforcement is now a floor, not a ceiling. Required methods are still forced on the profile (enforced setup), but at login users may authenticate with any method they have configured — not only the role-required ones. Fixes users who only saw email despite configuring OTP/recovery.
- “Remember this browser” duration now follows each user’s verification frequency (daily/weekly/monthly) instead of a fixed global value, so the checkbox always complies with the profile setting.
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer / WPCS — 0 errors
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 50 tests, 121 assertions
1.5.2
Release date: 2026-06-06
Added
- OTP import tool (2FA > Import) — import authenticator secrets from third-party 2FA plugins without requiring users to reconfigure their app:
- Two Factor (community) — plain Base32 from
_two_factor_totp_keyuser meta. - WP 2FA (Melapress) — plain or encrypted Base32 from
wp_2fa_totp_keyuser meta; decrypted if WP 2FA is active. - Wordfence Login Security — raw binary from
wfls_2fa_secretstable, Base32-encoded on import. - Admin notice banner when importable secrets are detected; dismissible per-admin for 7 days or permanently via Import page preference.
- Import correctly skips users who already have OTP actively configured in our plugin; only imports for users who have not yet activated OTP here.
Fixed
- Deactivating the Authenticator App method from the profile no longer pre-generates a new OTP secret immediately. The secret is deleted cleanly and a fresh QR code is generated lazily the next time the user views their profile. This ensures the import tool can correctly detect these users as candidates.
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer 3.13.5 / WPCS 3.3.0
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 42 tests, 109 assertions
1.5.1
Release date: 2026-06-06
Security
- CSV exports use RFC 4180 encoding — fields with commas, double-quotes, or line breaks are correctly quoted. Replaces
addslashes(). - GeoIP database path validated with
is_file()and!is_link()at read time to block symlink traversal. robotstxt_2fa_app_password_verification_windowfilter return validated as a positive integer; falls back to 900 for invalid values.
Fixed
- Export CSV button now only rendered to users with
manage_optionscapability.
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer 3.13.5 / WPCS 3.3.0
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 42 tests, 109 assertions
1.5.0
Release date: 2026-06-05
Added
- Full audit user table (WP_List_Table) with sortable columns, role/status filters, and CSV export.
- GeoIP country restrictions via optional MaxMind GeoLite2 database: per-country allow list, deny list, always-challenge list.
- Require recent 2FA verification before creating Application Passwords (REST endpoint, 15-min window, filterable).
- WP-CLI
wp 2fa export— CSV report via stdout. robotstxt_2fa_force_challengefilter — override frequency skip; used by GeoIP always-challenge.maxmind-db/readeradded as optional production Composer dependency.
Fixed
- Email digest cron now reschedules correctly when frequency changes (weekly ↔ monthly).
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer 3.13.5 / WPCS 3.3.0
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 42 tests, 109 assertions
1.4.0
Release date: 2026-06-05
Added
- Audit Dashboard — top-level admin page with summary cards (total users, 2FA-enabled, recent failed attempts), failed attempts table, and 2FA status column in Users list.
- Failed attempts log —
robotstxt_2fa_failed_logring buffer (max 100 entries) populated on every failed verification; IPs anonymized. - Email notifications (each independently configurable):
- Admin-enabled 2FA: user is notified when an administrator activates 2FA for them.
- New location login: user is notified on first successful login from an unrecognised context.
- Recovery code used: user (and optionally site admin) notified when a recovery code is consumed.
- Activity digest: WP-Cron weekly or monthly summary sent to administrators.
- Application Passwords exemption: REST API clients skip the 2FA browser challenge by default.
- IP allow list: IPs/CIDR ranges that bypass 2FA (via
robotstxt_2fa_skip_challenge). - IP deny list: IPs/CIDR ranges blocked from login entirely (via
authenticateat priority 1). - IPv4 + IPv6 CIDR matching (pure PHP, no external dependency).
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer 3.13.5 / WPCS 3.3.0
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 42 tests, 109 assertions
1.3.0
Release date: 2026-06-05
Security
- TOTP replay prevention: accepted counter step stored in a 90-second transient; same code rejected on second submission within the ±1 window.
- Login username removed from 2FA redirect URLs:
robotstxt-2fa-loginquery parameter replaced with an opaque 32-character token resolved server-side. Username never appears in browser history, logs, or referrer headers.
Added
- WP-CLI command family
wp 2fa(loaded only whenWP_CLIis defined): wp 2fa status— show 2FA configuration.wp 2fa enable [--method=]— enable 2FA.wp 2fa disable— disable 2FA, preserving secrets and codes.wp 2fa reset-recovery— regenerate and display recovery codes.wp 2fa list [--role=] [--without-2fa] [--format=table|csv|json]— list users with 2FA status.wp 2fa force-setup [] [--role=] [--method=]— enforce 2FA.wp 2fa bypass [--days=]— grant temporary bypass (max 30 days).
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer 3.13.5 / WPCS 3.3.0
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 42 tests, 109 assertions
1.2.1
Release date: 2026-06-05
Fixed
- Recovery code confirmation without the method checkbox now correctly activates the method.
- Fatal error on admin profile pages (add_settings_error not available at init in multisite).
- OTP and recovery text inputs no longer disabled by JS when Enable toggle is off.
- Regenerate codes now requires re-confirmation before the method reactivates.
- Entering a valid OTP or recovery code activates the method even without checking the checkbox.
- Recovery regeneration field validated with strict value check.
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer 3.13.5 / WPCS 3.3.0
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 42 tests, 109 assertions
1.1.0
Release date: 2026-06-05
Added
- Developer filter/action hooks:
robotstxt_2fa_skip_challenge,robotstxt_2fa_verification_success,robotstxt_2fa_verification_failed,robotstxt_2fa_method_enabled,robotstxt_2fa_method_disabled,robotstxt_2fa_code_length,robotstxt_2fa_code_ttl,robotstxt_2fa_resend_interval,robotstxt_2fa_email_subject,robotstxt_2fa_email_message,robotstxt_2fa_before_send_email. robotstxt_2fa_required_methods_for_userfilter to override per-user method requirements.robotstxt_2fa_profile_wrapper_classfilter for the frontend shortcode container.shortcode — renders the full 2FA settings section on any WordPress page without requiring wp-admin access. Supportsuser_idandredirectattributes.top_up_codes_for_user()method onRecovery_Codes— generates only the missing codes to fill the batch back to 10, preserving existing unused codes.- “Regenerate codes” button on the profile when recovery codes are active, without needing to disable and re-enable the method.
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer 3.13.5 / WPCS 3.3.0
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 42 tests, 109 assertions
1.0.0
Release date: 2026-06-05
Fixed
- Enable 2FA checkbox now defaults to email and pre-checks it in the UI on first activation.
- QR code for authenticator apps now displays correctly in the user profile.
- “Send the code again” link is disabled for 60 seconds after delivery with a live countdown.
Changed
- Recovery codes section redesigned: plain list with code chips, no coloured notification box.
- 2FA login screen links now in a vertical list for better readability.
Removed
- “Generate new secret” button from the OTP section.
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer 3.13.5 / WPCS 3.3.0
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 42 tests, 109 assertions
0.3.0
Release date: 2026-06-05
Added
- Delete-on-uninstall option (disabled by default — all plugin data is preserved on removal).
Security
- Email verification codes now use
random_int()(CSPRNG). - Recovery code preview transient TTL reduced from indefinite to 5 minutes.
Fixed
- Network admin settings now save correctly via a dedicated handler writing to
wp_sitemeta. - Settings option registered with
autoload=false. update.jsoncorrected to reference the 2FA plugin instead of the SMTP plugin.
Compatibility
- WordPress: 6.4 – 7.1
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer 3.13.5 / WPCS 3.3.0
- PHPStan: level 9 — 0 errors
- PHPCompatibility: 8.0–8.5 — 0 issues
- PHPUnit: 9.6.34 — 42 tests, 109 assertions
0.2.0
Release date: 2026-06-05
Added
- Per-role 2FA method matrix with select-all row/column controls.
- Authenticator app (TOTP) support with QR provisioning and manual setup key.
- Recovery codes: 10 single-use 8-digit codes with confirmation workflow.
- Email-based verification codes with 60-second resend throttle and 10-minute expiry.
- Configurable verification frequency (every login, daily, weekly, monthly) per device.
- Dedicated stage token (WP nonce) securing the 2FA screen.
- Network-wide multisite support.
- Admin settings page with top-level menu.
Changed
- Profile method checkboxes require explicit confirmation before activation.
Fixed
- QR generation errors caught; recovery-code preview persists until acknowledged.
Compatibility
- WordPress: 6.4 – 7.0
- PHP: 8.0 – 8.5
Tests
- PHP Coding Standards: PHP_CodeSniffer 3.13.5 / WPCS 3.3.0
- PHPStan: level 9 — 0 errors
- PHPUnit: 9.6.34
0.1.0
Release date: 2024-04-08
Added
- Initial plugin skeleton.
- Documentation files.
- Placeholder classes for login handling, profile integration, and admin settings.