Plugins

All plugins

Myload Security 2FA

Account security, email verification, and two-factor protection controls.

Plugin purpose

Myload Security 2FA provides a licensed customer security center. Customers open My Account > Security / 2FA or use the [myload_security_2fa] shortcode to manage verification.

Email authentication sends a six-digit code that expires after 10 minutes. Once verified, the code input is hidden and the customer can disable email authentication manually.

Authenticator app support uses standard TOTP codes. Customers scan the QR code or copy the secret into Google Authenticator, Microsoft Authenticator, 1Password, or another compatible app.

The main Account Security / 2FA box contains the protected status and the enable/disable action. 2FA can only be enabled after at least one authentication method is verified.

If a user loses access during login, the challenge screen includes a recovery request form. The user enters the account email; if it matches, the admin receives a recovery email and the user receives a confirmation email with a report button.

Recovery email can be configured by the user in Security / 2FA or by an administrator in the WordPress user profile. During login verification, users can request a code at the recovery email.

Failed login limits are configured in Myload Security > Failed Attempts. The log keeps the latest 500 rows and older rows are automatically removed.

Administrators can open Myload Security > 2FA Users to disable 2FA for a user, or Myload Security to configure email authentication, authenticator app, social login credentials, and Google reCAPTCHA.

The frontend uses Myload theme variables for buttons, cards, borders, text, and light/dark mode compatibility.

Functions

  • Adds a WooCommerce account Security / 2FA endpoint.
  • Lets customers verify account email with a short-lived code.
  • Lets customers verify an authenticator app with TOTP codes.
  • Lets customers configure a recovery email for login verification if the primary account email is unavailable.
  • Enforces a login challenge when 2FA is enabled and at least one method is active.
  • Limits repeated failed login attempts with configurable thresholds, lockout time, alert emails, and a 500-row backend log.
  • Lets administrators disable 2FA for users after a recovery request.
  • Adds backend settings for email authentication, authenticator app, social login API credentials, and Google reCAPTCHA.
  • Kërkon një licencë aktive Myload jashtë myload.net.