Download the PHP package studio-lemon/2fa-login-security without Composer

On this page you can find all versions of the php package studio-lemon/2fa-login-security. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package 2fa-login-security

2FA Login Security

Latest Stable Version

2FA Login Security is a standalone WordPress plugin focused on two-factor authentication. It is a fork of the discontinued Wordfence Login Security plugin and is being pared down into a smaller plugin with fewer moving parts.

It is difficult to understand why a large security vendor such as Wordfence discontinued a widely used plugin that provided an important login-security feature.

This README covers the plugin's purpose, installation, day-to-day usage, and local development workflow. The user-facing setup guide from docs/how-to.md is also included here so the main README can stand on its own.

Current Scope

The current codebase is centered on:

The fork is moving away from earlier upstream integrations and bundled extras. In particular, this repository is being cleaned up to remove Wordfence-core coupling, WooCommerce integration, shortcode-specific flows, reCAPTCHA behavior, and other legacy paths that are not part of the core 2FA functionality.

Requirements

Installation

Standard WordPress install

  1. Upload the plugin to your site's wp-content/plugins/ directory, or install it through the WordPress admin.
  2. Activate the plugin in the WordPress Plugins screen.
  3. Open the Login Security area in wp-admin.
  4. Review the settings, configure any role requirements, and activate 2FA for the accounts that need it.

Composer install

Install the plugin from Packagist in your WordPress project's root directory:

Configure your project with Composer Installers so packages of type wordpress-plugin are placed in your WordPress plugins directory:

After Composer installs the package, activate it from the WordPress Plugins screen.

Multisite install

  1. Upload the plugin to the network's plugins directory.
  2. Network activate it.
  3. Super administrators can manage the plugin from Network Admin.
  4. Users on individual sites can manage their own 2FA settings when their role and permissions allow it.

Features

Two-factor authentication

XML-RPC hardening recommendation

The previous XML-RPC options were removed from this fork.

Reason: XML-RPC is a frequent brute-force and abuse target, and the safer default for most modern WordPress sites is to disable XML-RPC completely unless a specific integration requires it. Instead of carrying extra plugin toggles for a legacy endpoint, this plugin now focuses on core 2FA behavior and recommends turning XML-RPC off at the theme or infrastructure layer.

Example (theme-level): add this to your active theme's functions.php:

If your site relies on XML-RPC for a specific workflow, keep it enabled only as needed and restrict access at the edge (WAF, reverse proxy, or allowlist rules).

Admin and user management

How To

This section folds the user guide from docs/how-to.md into the main README.

What two-factor authentication means

Two-factor authentication adds a second proof of identity to the login process. In practice, that usually means you know your password and you also have access to an authenticator app on a phone, tablet, or another device. Both are required before access is granted.

This plugin uses Time-Based One-Time Passwords, or TOTP. Your authenticator app generates a short code that changes every 30 seconds. After entering your normal password, you enter the current code from the app.

How to enable two-factor authentication

Before you begin, install an authenticator app if you do not already use one. Common options include:

To enable 2FA:

  1. Open the Login Security page in WordPress admin.
  2. Open your authenticator app and create a new entry.
  3. Scan the QR code shown on the page.
  4. If you are on the same mobile device as the site, use the manual setup code shown below the QR code instead.
  5. Download the recovery codes and store them somewhere safe.
  6. Enter the six-digit code from your authenticator app.
  7. Click Activate.

If this is your first 2FA setup on the site, test it in another browser or a private window before ending your current session.

How to log in with two-factor authentication

The normal login flow is:

  1. Enter your username and password.
  2. Submit the login form.
  3. Enter the six-digit code from your authenticator app when prompted.
  4. Complete login.

If you use 2FA on multiple sites, make sure you are reading the code for the correct site entry in your app.

The plugin also supports the combined-password flow used by this codebase:

  1. Enter your username.
  2. Enter your password.
  3. Immediately append the current TOTP code to the end of the password in the same field.
  4. Submit the login form.

Example:

How to use recovery codes

Recovery codes are fallback login codes for when you lose access to your authenticator device or remove the stored account by mistake.

To log in with a recovery code:

  1. Enter your username and password.
  2. When prompted for a 2FA Code, enter one recovery code.
  3. Complete login.

Example recovery code:

If you use most of your recovery codes or no longer trust the saved copy, generate a new set from the Login Security page. Generating a new set invalidates the old set.

How to disable two-factor authentication

To disable 2FA on your own account:

  1. Log in to WordPress.
  2. Open the Login Security page.
  3. Click Deactivate.

To disable 2FA for another user:

  1. Open the Users screen in WordPress admin.
  2. Find the user.
  3. Click the 2FA link below the username.
  4. On the management screen for that user, click Deactivate.

Development

JavaScript and CSS assets

Source assets live in src/ and build into plain filenames under css/ and js/.

Available npm scripts:

Asset cache busting is handled by the WordPress enqueue version parameter, not by hashed filenames.

PHP tooling

Composer is used for development tools in this repository.

Available Composer scripts:

Repository notes

Project Structure

Documentation

License

This repository is licensed under GPL-2.0-or-later.


All versions of 2fa-login-security with dependencies

PHP Build Version
Package Version
Requires composer/installers Version ^2.3
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package studio-lemon/2fa-login-security contains the following files

Loading the files please wait ...