Ecommerce – Two Factor Authentication

Descrição

Have a completely Secure login to your WordPress e-commerce website using this FREE, Simple & very easy to setup plugin. It provides two factor authentication (2FA, MFA) whenever login to your WordPress website ensuring no unauthorised access to your website.

User Identity Verification or OTP Verification

Login : Verify users on login with different authentication methods like SMS Verification, Email, Google Authenticator, Authy Authenticator, Duo, Microsoft Authenticator, TOTP Based Authenticator, Security Questions and many others. Easy OTP Verification with SMS Verification and Email Verification.

Third Party Custom SMS Gateway

Premium plugin supports any third party custom SMS Gateway. If you don’t have your own SMS gateway you can use miniOrange gateway. Send SMS all over the world.
* Some Famous Gateways Supported:
* Twilio
* Clickatell
* ClickSend
* SendGrid
* Plivo
* GatewayApi

Others not listed gateway can be tested on our site, Test your Gateway: Custom Gateway

Supports variety of WordPress custom login forms and plugins

FREE Plugin Features

  • Simplified & easy user interface.
  • Two Factor Authentication (2FA) for 3 User forever FREE!
  • Variety of Authentication Methods: Any App supporting TOTP algorithm like Google, Authy, LastPass Authenticator, QR Code, Push Notification, Soft Token, Security Questions(KBA), OTP over Email and OTP over SMS
  • Includes Language Translation Support. Supports a wide variety of languages
  • Passwordless login or login with phone number
  • This plugin Supports standard TOTP + HOTP protocols for Authentication Methods.
  • Two Factor Authentication (2FA) allows authentication on login page itself for Google Authenticator & miniOrange Soft Token.
  • Brute force attack prevention & IP Blocking.
  • User login Monitorning.
  • RCP Login Suppport

Standard Plugin Features

  • Two Factor Authentication (2FA) for Users as per the upgrade ( User-based pricing )
  • Available Authentication Methods: Google, Authy, LastPass Authenticator, QR Code, Push Notification, Soft Token, Security Questions(KBA), OTP Over Email, OTP Over SMS, OTP Over SMS and Email, Email Verification. ( SMS credits need to be purchased as per the need)
  • Includes language Translation Support. Supports wide variety of languages.
  • Multiple Login Options: Username + password + two-factor (or) Username + two-factor i.e. Passwordless login. Guide
  • Backup Method: KBA(Security Questions)
  • Multisite compatible.
  • User role based redirection after Login Guide, Customize account name in Google Authenticator app Guide
  • Custom Security Questions (KBA) Guide

Premium Plugin Features

  • Two Factor Authentication (2FA) for Users as per the upgrade ( User-based pricing )
  • Available Authentication Methods: Google, Authy, LastPass Authenticator, QR Code, Push Notification, Soft Token, Security Questions(KBA), OTP Over Email, OTP Over SMS, OTP Over SMS and Email, Email Verification, Hardware Token. ( SMS and Email credits need to be purchased as per the need)
  • Language Translation Support
  • Multiple Login Options: Username + password + two-factor (or) Username + two-factor i.e. Passwordless login Guide
  • Backup Methods: KBA(Security Questions), OTP Over Email, Backup Codes Guide
  • Multisite compatible.
  • Force Two factor for users Guide
  • Email notification to users asking them to set up Two Factor Authentication (2FA) Guide
  • User role based redirection after Login Guide, Custom Security Questions (KBA) Guide, Customize account name in Google Authenticator app Guide.
  • Enable Two Factor Authentication (2FA) for specific Users/User Roles Guide
  • Choose specific authentication methods for Users Guide
  • Set Privacy Policy for users Guide
  • App Specific Password to login from mobile Apps
  • Remember Device Guide
  • Add-Ons Included: RBA & Trusted Devices Management Add-on, Personalization Add-on and Short Codes Add-on

Enterprise Plugin Features

  • Two Factor Authentication (2FA) for Users as per the upgrade ( User-based pricing )
  • Available Authentication Methods: Google, Authy, LastPass Authenticator, QR Code, Push Notification, Soft Token, Security Questions(KBA), OTP Over Email, OTP Over SMS, OTP Over SMS and Email, Email Verification, Hardware Token. ( SMS and Email credits need to be purchased as per the need)
  • Language Translation Support
  • Multiple Login Options: Username + password + two-factor (or) Username + two-factor i.e. Passwordless login.
  • Backup Methods: KBA(Security Questions), OTP Over Email, Backup Codes
  • Multisite compatible.
  • Email notification to users asking them to set up Two Factor Authentication (2FA).
  • User role based redirection after Login, Custom Security Questions (KBA), Customize account name in Google Authenticator app.
  • Enable Two Factor Authentication (2FA) for specific Users/User Roles
  • Choose specific authentication methods for Users
  • App Specific Password to login from mobile Apps
  • Add-Ons Included: RBA & Trusted Devices Management Add-on, Personalization Add-on and Short Codes Add-on
  • **Brute force attack prevention, IP Blocking & User login Monitorning. **
  • File protection & strong password

Why do you need to register?

miniOrange Two-factor Plugin uses miniOrange APIs to communicate between your WP and miniOrange. To keep this communication secure, we ask you to register and assign you API keys specific to your account. This way your account and users calls can be only accessed by API keys assigned to you.
Adding to this, you can also use the same account on multiple applications and your users do not have to maintain multiple accounts or 2-factors.

Add Ons [Applicable for Free and Standard Plans, Inclusive in the Premium Plan]

  • RBA & Trusted Devices Management Add-on Features

    • Remember Device
    • Set Device Limit for the users to login
    • IP Restriction: Limit users to login from specific IPs
    • Personalization Add-on Features
    • Custom UI of Two Factor Authentication (2FA) popups
    • Custom Email and SMS Templates
    • Customize ‘Powered by’ Logo
    • Customize Plugin Icon
    • Customize Plugin Name
  • Short Codes Add-on Features

    • Option to turn on/off 2-factor by user
    • Option to configure the Google Authenticator and Security Questions by user
    • Option to ‘Enable Remember Device’ from a custom login form
    • On-Demand ShortCodes for specific functionalities ( like for enabling 2FA for specific pages)

Apps Supported by the plugin

  • miniOrange Authenticator App.
  • Google Authenticator App.
  • Duo Authenticator App.
  • Microsoft Authenticator Authenticator App.
  • Authy 2-Factor Authentication App [STANDARD / PREMIUM FEATURE]

Useful blog posts about two factor authenticaion plugin

*Beginner’s Guide: How to Add Two-Factor Authentication to WordPress
*How to Add WordPress Two-Factor Authentication (2FA)

Customized solutions and Active support is available. Email us at info@miniorange.com or call us at +1 9786589387.

Note: The plugin is GDPR Compliant and supports wide variety of Language Translation

Imagens de tela

  • Setup different 2-Factor methods.
  • Enable or Disable 2-factor for Users.

Instalação

From your WordPress dashboard

  1. Navigate to Plugins > Add New from your WP Admin dashboard.
  2. Search for Ecommerce Two Factor Authentication.
  3. Install Ecommerce Two Factor Authentication and Activate the plugin.

From WordPress.org

  1. Search for Ecommerce Two Factor Authentication and download it.
  2. Unzip and upload the Ecommerce Two Factor Authentication directory to your /wp-content/plugins/ directory.
  3. Activate Ecommerce Two Factor Authentication from the Plugins tab of your admin dashboard.

Once Activated

  1. Select E-Commerce 2-Factor from the left menu and follow the instructions.
  2. Once, you complete your setup. Click on Log Out button.
  3. Enter the username and password. After the initial validation, you will be prompted for the 2-factor method you had set up.
  4. Validate yourself with the 2-factor authentication method you configured.

Video Guide :

FAQ

I have Woocommerce theme login page on my site. How can I enable Two Factor ?

If you have Woocommerce theme login then go to Advanced Options Tab and check Enable Two-Factor for Woocommerce Front End Login. If you need any help setting up 2-Factor for your Woocommerce theme login form, please submit a query in our Support Section in the plugin or you can contact us at info@miniorange.com.

How do I gain access to my website if I get locked out?

You can obtain access to your website by one of the below options:

  1. If you have an additional administrator account whose Two Factor is not enabled yet, you can login with it.
  2. If you had setup KBA questions earlier, you can use them as an alternate method to login to your website.
  3. Rename the plugin from FTP – this disables the Two-Factor (2FA) plugin and you will be able to login with your WordPress username and password.

For detailed information, Please check on our website. Locked Out.
You can also check our video Tutorial:

I want to enable Two-Factor Authentication (2FA) role wise ?

You can select the roles under Login Settings tab to enable the plugin role wise. [PREMIUM FEATURE]

I have enabled Two-Factor Authentication (2FA) for all users, what happens if an end user tries to login but has not yet registered ?

If a user has not setup Two-Factor yet, user has to register by inline registration that will be invoked during the login.

I want to enable only one authentication method for my users. What shloud I do?

You can select the authentication methods under Login Settings tab. The selected authentication methods will be shown to the user during inline registration. [PREMIUM FEATURE]

I am getting the fatal error of call to undefined function json_last_error(). What should I do?

Please check your php version. The plugin is supported in php version 5.3.0 or above. You need to upgrade your php version to 5.3.0 or above to use the plugin.

I did not recieve OTP while trying to register with miniOrange. What should I do?

The OTP is sent to your email address with which you have registered with miniOrange. If you can’t see the email from miniOrange in your mails, please make sure to check your SPAM folder. If you don’t see an email even in SPAM folder, please submit a query in our Support Section in the plugin or you can contact us at info@miniorange.com.

I want to configure 2nd factor by Google Authenticator.

Select the radio button next to Google Authenticator/Authy App and select the phone type and then scan the QR Code by Google Authenticator App. Enter the 6 digit code in the textbox and click on Save and verify buuton.

I want to configure 2nd factor by Authy 2-Factor Authentication App.

Select the radio button next to Google Authenticator/Authy App and select the phone type and then scan the QR Code by Authy 2-Factor Authentication App. Enter the 6 digit code from the Authy App into the textbox available and click on Save and Verifiy button.

I forgot the password of my miniOrange account. How can I reset it?

There are two cases according to the page you see –
1. Login with miniOrange screen: You should click on forgot password link. You will get a new password on your email address with which you have registered with miniOrange . Now you can login with the new password.

  1. Register with miniOrange screen: Enter your email ID and any random password in password and confirm password input box. This will redirect you to Login with miniOrange screen. Now follow first step.

I have a custom / front-end login page on my site and I want the look and feel to remain the same when I add 2 factor ?

If you have a custom login form other than wp-login.php then we will provide you the shortcode. Shortcode will work only for the customized login page created from wordpress plugins. We are not claiming that it will work with all the customized login page. In such case, custom work is needed to integrate two factor with your customized login page. You can submit a query in our Support Section in the plugin or you can contact us at info@miniorange.com for more details.

I have installed plugins which limit the login attempts like Limit Login Attempt, Loginizer, Wordfence etc. Is there any incompatibilities with these kind of plugins?

The limit login attempt kind of plugins limit the number of login attempts and block the IP temporarily. So if you are using 2 factor along with these kind of plugins then you should increase the login attempts (minimum 5) so that you dont get locked out yourself.

If you are using any Security Plugin in WordPress like Simple Security Firewall, All in One WP Security Plugin and you are not able to login with Two-Factor.

Our Two-Factor plugin is compatible with most of the security plugins, but if it is not working for you. Please submit a query in our Support Section in the plugin or you can contact us at info@miniorange.com.

If you are using any render blocking javascript and css plugin like Async JS and CSS Plugin and you are not able to login with Two-Factor or your screen got blank.

If you are using Async JS and CSS Plugin. Please go to its settings and add jquery in the list of exceptions and save settings. It will work. If you are still not able to get it right, Please submit a query in our Support Section in the plugin or you can contact us at info@miniorange.com.

My users have different types of phones. What phones are supported?

We support all types of phones. Smart Phones, Basic Phones, Landlines, etc. Go to Setup Two-Factor Tab and select Two-Factor method of your choice from a range of 8 different options.

What if a user does not have a smart phone?

You can select OTP over SMS, Phone Call Verification or Email Verification as your Two-Factor method. All these methods are supported on basic phones.

What if a user does not have any phone?

You can select Email Verification or Security Questions (KBA) as your Two-Factor method.

What if I am trying to login from my phone ?

If your Security Questions (KBA) are configured then you will be asked to answer them when you are logging in from your phone.

I want to hide default login form and just want to show login with phone?

You should go to Login Settings Tab and check Login with Phone Only checkbox to hide the default login form.

My phone has no internet connectivity and configured 2nd factor with miniOrange App, how can I login?

You can login using our alternate login method. Please follow below steps to login:

  • Enter your username and click on login with your phone.
  • Click on Phone is Offline? button below QR Code.
  • You will see a textbox to enter one time passcode.
  • Open miniOrange Authenticator App and Go to Soft Token Tab.
  • Enter the one time passcode shown in miniOrange Authenticator App in textbox, just like Google authenticator.
  • Click on submit button to validate the otp.
  • Once you are authenticated, you will be logged in.

My phone is lost, stolen or discharged. How can I login?

You can login using our alternate login method. Click on the Forgot Phone link and you will get 2 alternate methods to login. Select “Send a one time passcode to my registered email” to authenticate by OTP over EMAIL or Select “Answer your Security Questions (KBA)” to authenticate by knowledge based authenticaion.

My phone has no internet connectivity and i am entering the one time passcode from miniOrange Authenticator App, it says Invalid OTP?

Click on the Settings Icon on top right corner in miniOrange Authenticator App and then press Sync button under ‘Time correction for codes’ to sync your time with miniOrange Servers. If you still can’t logged in then please email us at info@miniorange.com or Contact us.Soft Token method is just like google authenticator method.

I want to go back to default login with password?

You should go to Login Settings Tab and uncheck Enable Two-Factor plugin checkbox. This will disable 2-Factor and you can login using wordpress default login.

I am upgrading my phone.

You should go to Setup Two Factor Tab and click on Reconfigure to reconfigure 2-Factor with your new phone.

What If I want to use any other second factor like OTP Over SMS, Security Questions, Device Id, etc ?

miniOrange authentication service has 15+ authentication methods.One time passcodes (OTP) over SMS, OTP over Email, OTP over SMS and Email, Out of Band SMS, Out of Band Email, Soft Token, Push Notification, USB based Hardware token (yubico), Security Questions, Mobile Authentication (QR Code Authentication), Voice Authentication (Biometrics), Phone Verification, Device Identification, Location, Time of Access User Behavior. To know more about authentication methods, please visit https://miniorange.com/strong_auth . If you want to have any other 2-factor for your WordPress site, please email us at info@miniorange.com or Contact us.

Avaliações

Não existem avaliações para esse plugin.

Colaboradores e desenvolvedores

“Ecommerce – Two Factor Authentication” é um software com código aberto. As seguintes pessoas contribuíram para este plugin.

Colaboradores

Registro de alterações

1.0.0

First version of Two Factor Authentication ( 2FA ) plugin supported with mobile auhthentication for admin only.

1.0.1

Fixes – Conflict with other plugins

1.0.3

Fixes – Feedback form(ecommerce two factor authentication)