Ecommerce – Two Factor Authentication  

Descripción

Have a completely Secure login to your WordPress e-commerce website using this FREE, Simple & very easy setup plugin. It provides two-factor authentication (2FA, MFA) whenever login to your WordPress website ensuring no unauthorized access to your website.

User Identity Verification or OTP Verification

Login: Verify users on login with different authentication methods like SMS Verification, Email, Google Authenticator, Authy Authenticator, Duo, Microsoft Authenticator, TOTP Based Authenticator, Security Questions, and many others. Easy OTP Verification with SMS Verification and Email Verification.

Third-Party Custom SMS Gateway

The premium plugin supports any third-party custom SMS Gateway. If you don’t have your own SMS gateway you can use miniOrange gateway. Send SMS all over the world.
* Some Famous Gateways Supported:
* Twilio
* Clickatell
* ClickSend
* SendGrid
* Plivo
* GatewayApi

Others not listed gateway can be tested on our site, Test your Gateway: Custom Gateway

Supports variety of WordPress custom login forms and plugins

FREE Plugin Features

  • Simplified & easy user interface.
  • Two Factor Authentication (2FA) for 3 User forever FREE!
  • Variety of Authentication Methods: Any App supporting TOTP algorithm like Google, Authy, LastPass Authenticator, QR Code, Push Notification, Soft Token, Security Questions(KBA), OTP over Email and OTP over SMS
  • Includes Language Translation Support. Supports a wide variety of languages
  • Passwordless login or login with phone number
  • This plugin Supports standard TOTP + HOTP protocols for Authentication Methods.
  • Two Factor Authentication (2FA) allows authentication on the login page itself for Google Authenticator & miniOrange Soft Token.
  • Brute force attack prevention & IP Blocking.
  • User login Monitoring.
  • RCP Login Support

Standard Plugin Features

  • Two Factor Authentication (2FA) for Users as per the upgrade ( User-based pricing )
  • Available Authentication Methods: Google, Authy, LastPass Authenticator, QR Code, Push Notification, Soft Token, Security Questions(KBA), OTP Over Email, OTP Over SMS, OTP Over SMS and Email, Email Verification. ( SMS credits need to be purchased as per the need)
  • Includes language Translation Support. Supports a wide variety of languages.
  • Multiple Login Options: Username + password + two-factor (or) Username + two-factor i.e. Passwordless login. Guide
  • Backup Method: KBA(Security Questions)
  • Multisite compatible.
  • User role based redirection after Login Guide, Customize account name in Google Authenticator app Guide
  • Custom Security Questions (KBA) Guide

Premium Plugin Features

  • Two Factor Authentication (2FA) for Users as per the upgrade ( User-based pricing )
  • Available Authentication Methods: Google, Authy, LastPass Authenticator, QR Code, Push Notification, Soft Token, Security Questions(KBA), OTP Over Email, OTP Over SMS, OTP Over SMS and Email, Email Verification, Hardware Token. ( SMS and Email credits need to be purchased as per the need)
  • Language Translation Support
  • Multiple Login Options: Username + password + two-factor (or) Username + two-factor i.e. Passwordless login Guide
  • Backup Methods: KBA(Security Questions), OTP Over Email, Backup Codes Guide
  • Multisite compatible.
  • Force Two factor for users Guide
  • Email notification to users asking them to set up Two Factor Authentication (2FA) Guide
  • User role based redirection after Login Guide, Custom Security Questions (KBA) Guide, Customize account name in Google Authenticator app Guide.
  • Enable Two Factor Authentication (2FA) for specific Users/User Roles Guide
  • Choose specific authentication methods for Users Guide
  • Set Privacy Policy for users Guide
  • App-Specific Password to login from mobile Apps
  • Remember Device Guide
  • Add-Ons Included: RBA & Trusted Devices Management Add-on, Personalization Add-on, and Short Codes Add-on

Enterprise Plugin Features

  • Two Factor Authentication (2FA) for Users as per the upgrade ( User-based pricing )
  • Available Authentication Methods: Google, Authy, LastPass Authenticator, QR Code, Push Notification, Soft Token, Security Questions(KBA), OTP Over Email, OTP Over SMS, OTP Over SMS and Email, Email Verification, Hardware Token. ( SMS and Email credits need to be purchased as per the need)
  • Language Translation Support
  • Multiple Login Options: Username + password + two-factor (or) Username + two-factor i.e. Passwordless login.
  • Backup Methods: KBA(Security Questions), OTP Over Email, Backup Codes
  • Multisite compatible.
  • Email notification to users asking them to set up Two Factor Authentication (2FA).
  • User role-based redirection after log in, Custom Security Questions (KBA), Customize account name in Google Authenticator app.
  • Enable Two Factor Authentication (2FA) for specific Users/User Roles
  • Choose specific authentication methods for Users
  • App-Specific Password to login from mobile Apps
  • Add-Ons Included: RBA & Trusted Devices Management Add-on, Personalization Add-on, and Short Codes Add-on
  • **Brute force attack prevention, IP Blocking & User login Monitoring. **
  • File protection & strong password

Why do you need to register?

miniOrange Two-factor Plugin uses miniOrange APIs to communicate between your WP and miniOrange. To keep this communication secure, we ask you to register and assign API keys specific to your account. This way your account and users’ calls can be only accessed by API keys assigned to you.
Adding to this, you can also use the same account on multiple applications and your users do not have to maintain multiple accounts or 2-factors.

Add Ons [Applicable for Free and Standard Plans, Inclusive in the Premium Plan]

  • RBA & Trusted Devices Management Add-on Features
     * Remember Device
     * Set Device Limit for the users to login
     * IP Restriction: Limit users to login from specific IPs
     * Personalization Add-on Features
     * Custom UI of Two Factor Authentication (2FA) popups
     * Custom Email and SMS Templates
     * Customize ‘Powered by’ Logo
     * Customize Plugin Icon
     * Customize Plugin Name

  • Short Codes Add-on Features
     * Option to turn on/off 2-factor by user
     * Option to configure the Google Authenticator and Security Questions by user
     * Option to ‘Enable Remember Device’ from a custom login form
     * On-Demand ShortCodes for specific functionalities ( like for enabling 2FA for specific pages)

Apps Supported by the plugin

  • miniOrange Authenticator App.
  • Google Authenticator App.
  • Duo Authenticator App.
  • Microsoft Authenticator Authenticator App.
  • Authy 2-Factor Authentication App [STANDARD / PREMIUM FEATURE]

Useful blog posts about two factor authenticaion plugin

*Beginner’s Guide: How to Add Two-Factor Authentication to WordPress
*How to Add WordPress Two-Factor Authentication (2FA)

Customized solutions and Active support are available. Email us at info@miniorange.com or call us at +1 9786589387.

Note: The plugin is GDPR Compliant and supports a wide variety of Language Translation

Capturas

  • Setup different 2-Factor methods.
  • Enable or Disable 2-factor for Users.

Instalación

From your WordPress dashboard

  1. Navigate to Plugins > Add New from your WP Admin dashboard.
  2. Search for Ecommerce Two Factor Authentication.
  3. Install Ecommerce Two Factor Authentication and Activate the plugin.

From WordPress.org

  1. Search for Ecommerce Two Factor Authentication and download it.
  2. Unzip and upload the Ecommerce Two Factor Authentication directory to your /wp-content/plugins/ directory.
  3. Activate Ecommerce Two Factor Authentication from the Plugins tab of your admin dashboard.

Once Activated

  1. Select E-Commerce 2-Factor from the left menu and follow the instructions.
  2. Once, you complete your setup. Click on Log Out button.
  3. Enter the username and password. After the initial validation, you will be prompted for the 2-factor method you had set up.
  4. Validate yourself with the 2-factor authentication method you configured.

Video Guide :

FAQ

I have a Woocommerce theme login page on my site. How can I enable Two Factor?

If you have Woocommerce theme login then go to Advanced Options Tab and check Enable Two-Factor for Woocommerce Front End Login. If you need any help setting up 2-Factor for your Woocommerce theme login form, please submit a query in our Support Section in the plugin or you can contact us at info@miniorange.com.

How do I gain access to my website if I get locked out?

You can obtain access to your website by one of the below options:

  1. If you have an additional administrator account whose Two Factor is not enabled yet, you can log in with it.
  2. If you had set up KBA questions earlier, you can use them as an alternate method to log in to your website.
  3. Rename the plugin from FTP – this disables the Two-Factor (2FA) plugin and you will be able to log in with your WordPress username and password.

For detailed information, Please check on our website. Locked Out.
You can also check our video Tutorial:

I want to enable Two-Factor Authentication (2FA) role-wise?

You can select the roles under Login Settings tab to enable the plugin role-wise. [PREMIUM FEATURE]

I have enabled Two-Factor Authentication (2FA) for all users, what happens if an end-user tries to log in but has not yet registered?

If a user has not set up Two-Factor yet, the user has to register by inline registration that will be invoked during the login.

I want to enable only one authentication method for my users. What should I do?

You can select the authentication methods under Login Settings tab. The selected authentication methods will be shown to the user during inline registration. [PREMIUM FEATURE]

I am getting the fatal error of call to undefined function json_last_error(). What should I do?

Please check your PHP version. The plugin is supported in PHP version 5.3.0 or above. You need to upgrade your PHP version to 5.3.0 or above to use the plugin.

I did not receive OTP while trying to register with miniOrange. What should I do?

The OTP is sent to the email address with which you have registered with miniOrange. If you can’t see the email from miniOrange in your emails, please make sure to check your SPAM folder. If you don’t see an email even in the SPAM folder, please submit a query in our Support Section in the plugin or you can contact us at info@miniorange.com.

I want to configure 2nd factor by Google Authenticator.

Select the radio button next to Google Authenticator/Authy App and select the phone type and then scan the QR Code by Google Authenticator App. Enter the 6 digit code in the textbox and click on Save and verify button.

I want to configure the 2nd factor by Authy 2-Factor Authentication App.

Select the radio button next to Google Authenticator/Authy App and select the phone type and then scan the QR Code by Authy 2-Factor Authentication App. Enter the 6 digit code from the Authy App into the textbox available and click on Save and Verify button.

I forgot the password of my miniOrange account. How can I reset it?

There are two cases according to the page you see –
 1. Login with miniOrange screen: You should click on forgot password link. You will get a new password on your email address with which you have registered with miniOrange. Now you can log in with the new password.

 2. Register with miniOrange screen: Enter your email ID and any random password in the password and confirm the password input box. This will redirect you to log in with the miniOrange screen. Now follow the first step.

I have a custom/front-end login page on my site and I want the look and feel to remain the same when I add 2 factor?

If you have a custom login form other than wp-login.php then we will provide you the shortcode. Shortcode will work only for the customized login page created from WordPress plugins. We are not claiming that it will work with all the customized login pages. In such a case, custom work is needed to integrate two factors with your customized login page. You can submit a query in our Support Section in the plugin or you can contact us at info@miniorange.com for more details.

I have installed plugins that limit the login attempts like Limit Login Attempt, Loginizer, Wordfence, etc. Are there any incompatibilities with this kind of plugin?

The limit login attempt kind of plugins limit the number of login attempts and block the IP temporarily. So if you are using 2 factors along with this kind of plugin then you should increase the login attempts (minimum 5) so that you don’t get locked out yourself.

If you are using any Security Plugin in WordPress like Simple Security Firewall, All in One WP Security Plugin and you are not able to login with Two-Factor.

 Our Two-Factor plugin is compatible with most of the security plugins, but if it is not working for you. Please submit a query in our Support Section in the plugin or you can contact us at info@miniorange.com.

If you are using any render-blocking javascript and CSS plugin like Async JS and CSS Plugin and you are not able to login with Two-Factor or your screen got blank.

If you are using Async JS and CSS Plugin. Please go to its settings and add jquery to the list of exceptions and save settings. It will work. If you are still not able to get it right, Please submit a query in our Support Section in the plugin or you can contact us at info@miniorange.com.

My users have different types of phones. What phones are supported?

We support all types of phones. Smart Phones, Basic Phones, Landlines, etc. Go to Setup Two-Factor Tab and select the Two-Factor method of your choice from a range of 8 different options.

What if a user does not have a smartphone?

You can select OTP over SMS, Phone Call Verification, or Email Verification as your Two-Factor method. All these methods are supported on basic phones.

What if a user does not have any phone?

You can select Email Verification or Security Questions (KBA) as your Two-Factor method.

What if I am trying to log in from my phone?

If your Security Questions (KBA) are configured then you will be asked to answer them when you are logging in from your phone.

I want to hide the default login form and just want to show login with the phone?

You should go to Login Settings Tab and check Login with Phone Only checkbox to hide the default login form.

My phone has no internet connectivity and configured 2nd factor with miniOrange App, how can I log in?

You can log in using our alternate login method. Please follow the below steps to login:

  • Enter your username and click on login with your phone.
  • Click on Phone is Offline? button below QR Code.
  • You will see a textbox to enter one-time passcode.
  • Open miniOrange Authenticator App and Go to Soft Token Tab.
  • Enter the one-time passcode shown in the miniOrange Authenticator App in a textbox, just like Google authenticator.
  • Click on submit button to validate the OTP.
  • Once you are authenticated, you will be logged in.

My phone is lost, stolen, or discharged. How can I log in?

You can log in using our alternate login method. Click on the Forgot Phone link and you will get 2 alternate methods to log in. Select “Send a one-time passcode to my registered email” to authenticate by OTP over EMAIL or Select “Answer your Security Questions (KBA)” to authenticate by knowledge-based authentication.

My phone has no internet connectivity and I am entering the one-time passcode from the miniOrange Authenticator App, it says Invalid OTP?

Click on the Settings Icon on top right corner in miniOrange Authenticator App and then press Sync button under ‘Time correction for codes’ to sync your time with miniOrange Servers. If you still can’t logged in then please email us at info@miniorange.com or Contact us.Soft Token method is just like google authenticator method.

I want to go back to default login with password?

You should go to Login Settings Tab and uncheck Enable Two-Factor plugin checkbox. This will disable 2-Factor and you can log in using WordPress default login.

I am upgrading my phone.

You should go to Setup Two Factor Tab and click on Reconfigure to reconfigure 2-Factor with your new phone.

What If I want to use any other second factor like OTP Over SMS, Security Questions, Device Id, etc?

miniOrange authentication service has 15+ authentication methods. One time passcodes (OTP) over SMS, OTP over Email, OTP over SMS and Email, Out of Band SMS, Out of Band Email, Soft Token, Push Notification, USB based Hardware token (yubico), Security Questions, Mobile Authentication (QR Code Authentication), Voice Authentication (Biometrics), Phone Verification, Device Identification, Location, Time of Access User Behavior. To know more about authentication methods, please visit https://miniorange.com/strong_auth . If you want to have any other 2-factor for your WordPress site, please email us at info@miniorange.com or Contact us.

Reseñas

No hay reseñas para este plugin.

Colaboradores y desarrolladores

«Ecommerce – Two Factor Authentication  » es un software de código abierto. Las siguientes personas han colaborado con este plugin.

Colaboradores

Registro de cambios

1.0.0

The first version of the Two Factor Authentication ( 2FA ) plugin supports mobile authentication for admin only.

1.0.1

Fixes – Conflict with other plugins

1.0.3

Fixes – Feedback form(eCommerce two-factor authentication)

1.0.4

Fixes – vulnerability fixes