{"id":368830,"date":"2026-09-15T09:35:17","date_gmt":"2026-09-15T09:35:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/otp-sentinel-two-factor-authentication-email-google-authenticator\/"},"modified":"2026-09-16T05:59:39","modified_gmt":"2026-09-16T05:59:39","slug":"rad-2fa","status":"publish","type":"plugin","link":"https:\/\/sa.wordpress.org\/plugins\/rad-2fa\/","author":17553519,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.1","stable_tag":"1.2.1","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Rad 2FA \u2014 Two-Factor Login (Email & Authenticator App)","header_author":"Rad","header_description":"Secure WordPress login with two-factor authentication: email one-time codes or a TOTP authenticator app (e.g. Google Authenticator), per role.","assets_banners_color":"3d434c","last_updated":"2026-09-16 05:59:39","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/rad-2fa\/","header_author_uri":"https:\/\/profiles.wordpress.org\/rad18\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":77,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.0":{"tag":"1.2.0","author":"rad18","date":"2026-09-15 09:35:04","revision":3696617},"1.2.1":{"tag":"1.2.1","author":"rad18","date":"2026-09-16 05:59:39","revision":3697962}},"upgrade_notice":{"1.2.0":"<p>Plugin renamed to Rad 2FA. Admin language now follows each user&#039;s own WordPress profile setting instead of a plugin-specific toggle.<\/p>","1.1.1":"<p>Security hardening: TOTP replay protection, encrypted secret integrity check, login challenge rate limiting.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3696591,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3696591,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3696591,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3696591,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3696591,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.0","1.2.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3696591,"resolution":"1","location":"assets","locale":"","width":792,"height":871},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3696591,"resolution":"2","location":"assets","locale":"","width":820,"height":457}},"screenshots":{"1":"Settings \u2014 choose which roles require 2FA and the verification method (email code or authenticator app).","2":"Connecting an authenticator app from your own profile \u2014 scan the QR code or enter the key manually."}},"plugin_section":[],"plugin_tags":[9211,602,600,9225,9217],"plugin_category":[38,54],"plugin_contributors":[280823],"plugin_business_model":[],"class_list":["post-368830","plugin","type-plugin","status-publish","hentry","plugin_tags-2fa","plugin_tags-login","plugin_tags-security","plugin_tags-totp","plugin_tags-two-factor","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-rad18","plugin_committers-rad18"],"banners":{"banner":"https:\/\/ps.w.org\/rad-2fa\/assets\/banner-772x250.png?rev=3696591","banner_2x":"https:\/\/ps.w.org\/rad-2fa\/assets\/banner-1544x500.png?rev=3696591","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/rad-2fa\/assets\/icon.svg?rev=3696591","icon":"https:\/\/ps.w.org\/rad-2fa\/assets\/icon.svg?rev=3696591","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/rad-2fa\/assets\/screenshot-1.png?rev=3696591","caption":"Settings \u2014 choose which roles require 2FA and the verification method (email code or authenticator app)."},{"src":"https:\/\/ps.w.org\/rad-2fa\/assets\/screenshot-2.png?rev=3696591","caption":"Connecting an authenticator app from your own profile \u2014 scan the QR code or enter the key manually."}],"raw_content":"<!--section=description-->\n<p>This plugin adds a second authentication factor for the user roles you choose. After a correct username and password, an extra code is required \u2014 the site admin picks the method:<\/p>\n\n<ul>\n<li><strong>Email<\/strong> \u2014 a one-time numeric code sent to the user's email address.<\/li>\n<li><strong>Authenticator app (TOTP)<\/strong> \u2014 a standard 6-digit code from an app such as Google Authenticator, Authy, or Microsoft Authenticator (this plugin is not affiliated with or endorsed by Google). Each user connects the app in their own profile: scan the QR code or enter the secret key manually.<\/li>\n<\/ul>\n\n<p>If the site uses TOTP but a specific user hasn't connected the app yet, they temporarily get an email code at login instead \u2014 so nobody gets locked out.<\/p>\n\n<p>Features:<\/p>\n\n<ul>\n<li>Enable 2FA per user role<\/li>\n<li>Two verification methods: email code or authenticator app (TOTP)<\/li>\n<li>Configurable email code length, lifetime, and attempt limit<\/li>\n<li>Admin screens and email codes follow each user's own WordPress language setting (Users \u2192 Profile \u2192 Language) \u2014 no site-wide language switch needed<\/li>\n<li>Email codes are stored only as a hash; the TOTP secret is stored encrypted (AES-256-CBC)<\/li>\n<li>The QR code is generated entirely in the browser \u2014 the secret is never sent to a third-party service<\/li>\n<\/ul>\n\n<h3>Credits<\/h3>\n\n<p>The QR code on the authenticator app setup screen is rendered client-side using QRCode.js by davidshimjs (MIT license). This plugin bundles the minified build; the unminified source is available at https:\/\/github.com\/davidshimjs\/qrcodejs<\/p>\n\n<h3>Donate<\/h3>\n\n<p>If you find this plugin useful, please consider supporting its development.<\/p>\n\n<p>https:\/\/buymeacoffee.com\/rad181<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code><\/li>\n<li>Activate the plugin from the Plugins screen<\/li>\n<li>Go to the Rad 2FA menu item, choose the roles and the verification method<\/li>\n<li>If the authenticator app method is selected, each user sets it up in their own profile (Users \u2192 Your Profile)<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20if%20a%20user%20doesn%27t%20receive%20the%20code%20email%3F\"><h3>What if a user doesn't receive the code email?<\/h3><\/dt>\n<dd><p>Check the site's outgoing mail (SMTP) setup. The plugin uses WordPress's standard <code>wp_mail()<\/code> function.<\/p><\/dd>\n<dt id=\"can%20i%20enable%202fa%20for%20specific%20roles%20only%2C%20not%20everyone%3F\"><h3>Can I enable 2FA for specific roles only, not everyone?<\/h3><\/dt>\n<dd><p>Yes \u2014 in the plugin settings, tick the roles that require 2FA.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20the%20authenticator%20app%20method%20is%20enabled%20but%20a%20user%20hasn%27t%20set%20it%20up%20yet%3F\"><h3>What happens if the authenticator app method is enabled but a user hasn't set it up yet?<\/h3><\/dt>\n<dd><p>That user temporarily gets the code by email instead \u2014 it doesn't block login.<\/p><\/dd>\n<dt id=\"can%20an%20administrator%20set%20up%20the%20authenticator%20app%20for%20another%20user%3F\"><h3>Can an administrator set up the authenticator app for another user?<\/h3><\/dt>\n<dd><p>No \u2014 for security, the secret is tied to one person and can only be set up by that person in their own profile.<\/p><\/dd>\n<dt id=\"does%20this%20protect%20application%20passwords%20%2F%20the%20rest%20api%20too%3F\"><h3>Does this protect Application Passwords \/ the REST API too?<\/h3><\/dt>\n<dd><p>No. 2FA applies to the login form (wp-login.php). WordPress Application Passwords authenticate REST API requests through a separate mechanism that doesn't go through the login form, so they aren't covered. If this matters for your site, disable Application Passwords for accounts that require 2FA.<\/p><\/dd>\n<dt id=\"is%20this%20plugin%20affiliated%20with%20google%3F\"><h3>Is this plugin affiliated with Google?<\/h3><\/dt>\n<dd><p>No. \"Google Authenticator\" is mentioned only as an example of a compatible authenticator app; this plugin implements the standard, open TOTP algorithm (RFC 6238) and works with any compatible app.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Added a Plugin URI header linking to the wordpress.org plugin page<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Renamed to Rad 2FA (was OTP Sentinel)<\/li>\n<li>Removed the plugin-specific language toggle; admin screens and OTP emails now follow each user's own WordPress language setting (Users \u2192 Profile \u2192 Language)<\/li>\n<li>Inline admin scripts moved to properly enqueued files<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>TOTP codes can no longer be reused across login attempts<\/li>\n<li>Encrypted TOTP secrets are now integrity-checked (HMAC)<\/li>\n<li>Rate-limited login challenge issuance to reduce email\/brute-force abuse<\/li>\n<li>Fixed a redirect_to double-encoding bug affecting post-login redirects<\/li>\n<li>Added uninstall.php to remove plugin data on deletion<\/li>\n<li>Activation now checks for the required OpenSSL extension<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added authenticator app (TOTP) support as an alternative to the email code<\/li>\n<li>Settings moved to their own top-level menu item<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<\/ul>","raw_excerpt":"Secure WordPress login with two-factor authentication: email one-time codes or a TOTP authenticator app, per role.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/368830","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=368830"}],"author":[{"embeddable":true,"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/rad18"}],"wp:attachment":[{"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=368830"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=368830"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=368830"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=368830"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=368830"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/sa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=368830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}