=== miniOrange's Google Authenticator - WordPress Two Factor Authentication - 2FA , Two Factor, OTP SMS and Email | Passwordless login ===

Contributors: twofactor, twofactorauthentication, hsn97,cyberlord92
Tags:  google authenticator, WordPress authentication, 2FA, 2-factor authentication, two-factor authentication, OTP Authentication, wp 2fa, two-factor, Remember Device, passwordless login, email verification, OTP login, OTP Over SMS and Email.
Donate link: https://miniorange.com/
Requires at least: 3.0.1
Tested up to: 6.4
Requires PHP: 5.3.0
Stable tag: 5.8.1
License: MIT/Expat
License URI: https://docs.miniorange.com/mit-license

Google Authenticator is a user-friendly plugin that allows you to add two-factor authentication - 2FA for your users to secure your site’s login page.

== Description ==

**A POWERFUL & USER-FRIENDLY 2FA PLUGIN - FREE TO USE** 
Secure your WordPress login by adding an additional security layer. Install miniOrange's Google Authenticator - WordPress Two Factor Authentication plugin to protect your website from unauthorized access. miniOrange WordPress 2FA plugin is a versatile and reliable security solution that secures your website against various threats like brute force attacks, dictionary attacks, and automated password guessing. 

Check out the following video to configure Google authenticator as your 2FA:

[youtube https://youtu.be/_nkMCkxLcIs]

miniOrange Google Authenticator and Two Factor Authentication plugin is feature-rich and provides multiple authentication methods one of the popular being Google Authenticator. This 2FA plugin is very easy to set up. Our easy-to-follow steps of the setup wizard guide you through the process, making it simple, quick, and easy requiring no technical knowledge. You will be able to configure 2FA in no time.

[Features](https://plugins.miniorange.com/2-factor-authentication-for-wordpress-wp-2fa?utm_source=wordpress&utm_medium=readme+link&utm_campaign=last+June#key-features)

**KEY-FEATURES AND CAPABILITIES OF GOOGLE AUTHENTICATOR - WordPress TWO FACTOR AUTHENTICATION PLUGIN ** 

*The Google Authenticator - 2FA plugin supports All-TOTP Authenticator Apps like 
[Google Authenticator](https://plugins.miniorange.com/2-factor-authentication-for-wordpress-wp-2fa?utm_source=wordpress&utm_medium=readme+link&utm_campaign=last+June),
[Microsoft Authenticator](https://plugins.miniorange.com/setup-microsoft-authenticator-for-wordpress-2fa), 
[Authy 2-Factor Authenticator](https://youtu.be/fV-VnC_5Q5c),
[LastPass Authenticator](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-user-registration-login-form), 
[miniOrange Authenticator](https://plugins.miniorange.com/setup-miniorange-authenticator-for-two-factor-authentication-wordpress-2fa),
[Duo Authenticator](https://youtu.be/AZnBjf_E2cA), 
FreeOTP Authenticator,
Okta verify etc.


* Two-Factor Authentication - 2FA allows authentication on the login page itself.
* OTP Over Email/2FA code Over email.(https://plugins.miniorange.com/otp-over-email-for-wordpress-two-factor-authentication-2fa-mfa)
* OTP Over SMS/2FA code Over SMS(https://plugins.miniorange.com/otp-over-sms-for-wordpress-two-factor-authentication-2fa-mfa)
* OTP over Telegram (https://plugins.miniorange.com/login-with-telegram-as-a-two-factor-method-for-wordpress)
* miniOrange Authenticator - QR Code Authentication, Push Notifications and soft Token(https://plugins.miniorange.com/setup-miniorange-authenticator-for-two-factor-authentication-wordpress-2fa)
* Security Questions
(https://plugins.miniorange.com/setup-security-questions-for-two-factor-authentication-wordpress-2fa)
* MFA option for users - users can configure multiple authentication methods.
* [User Profile 2FA](https://plugins.miniorange.com/how-to-set-up-2-factor-from-wordpress-user-profile-section)- Admin can setup 2FA for any user**
* 3 users free for a lifetime.
* Role-based 2FA - enable/disable 2FA for particular role.
* Recovery codes/Backup codes in case you are locked out.
* Language Translation Support for French, Spanish, Italian, German, and many other languages.


**Maintained & Supported by miniOrange**

We are experts in the field of security and have released various advanced WordPress solutions. [Visit to learn about other WordPress Products]([https://plugins.miniorange.com/wordpress]).


**PREMIUM FEATURES AVAILABLE ON UPGRADE ** 

* [Google Authenticator - Two-Factor Authentication 2FA] - for all users and roles *( Site-based pricing )*

* **Two-Factor Authentication Methods:** 
Google Authenticator
Authy Authenticator
Microsoft Authenticator
LastPass Authenticator
Security Questions

OTP Authentication (OTP login using Email & OTP login using SMS),

Email Verification,

Mobile Verification *(SMS credits need to be purchased separately)*

* **Unlimited Email transactions**

* **For Unlimited Users**

* [Role based 2FA](https://docs.miniorange.com/documentation/specific-set-authentication-methods-based-role)

* **Backup Method:** - KBA (Security Questions), OTP login using Email, Backup codes.

* [User role-based redirection after Login](https://docs.miniorange.com/documentation/custom-redirect-login-url)

* [Customize account name in Google Authenticator app](https://docs.miniorange.com/documentation/google-authenticator-app-name)

* [Custom Security Questions (KBA)](https://docs.miniorange.com/documentation/custom-security-questions)

* [Force Two-factor authentication for users](https://docs.miniorange.com/documentation/enforce-2fa-users)

* [Email notification to users asking them to set up Two-Factor Authentication (2FA)](https://docs.miniorange.com/documentation/want-send-email-notification-users-setting-2-factor)

* [Remember Device to skip 2FA](https://docs.miniorange.com/documentation/remember-my-device)

* **Customizable Login UI Popup:** Using the Google Authentator plugin you can customize the user interface of the login popup as per your preference.

* Multisite compatible (up to 3 subsites)

* [Soft Token](https://developers.miniorange.com/docs/security/wordpress/wp-security/step-by-setup-guide-to-set-up-miniorange-soft-token),

* [Security Questions - KBA)](https://plugins.miniorange.com/how-to-setup-custom-security-questions-kba-from-wordpress-wp-2fa)

* OTP Authentication([OTP login using Email](https://developers.miniorange.com/docs/security/wordpress/wp-security/otp_over_email),

* [OTP login using SMS] or OTP Over SMS and Email*(SMS and Email credits need to be purchased separately)*),

[Email Verification],

[Hardware Token](https://mail.google.com/mail/u/0/?fs=1&tf=cm&source=mailto&su=TWO+FACTOR+WORDRESS+-+Hardware+Token+2FA+Method+.&to=2fasupport@xecurify.com&body=I+am+interested+in+the+Hardware+Token+method+of+the+2FA+plugin.+)

* **Backup Methods:** [KBA(Security Questions)] 

* [OTP login using Email](https://plugins.miniorange.com/otp-over-email-for-wordpress-two-factor-authentication-2fa-mfa), 

* [Backup Codes](https://plugins.miniorange.com/wordpress-two-factor-authentication-setup-guides#).

* **[Sync 2FA for multiple websites](https://plugins.miniorange.com/two-factor-authentication-2fa-for-multiple-wordpress-websites)**

* **Multisite compatible** for all WordPress 2FA methods

* Email notification to users asking them to set up Google Authenticator - Two-Factor Authentication - 2FA

* [**Role based redirection**](https://plugins.miniorange.com/how-to-enable-role-based-2fa-for-wordpress-two-factor-authentication#stepc) after Login,

* Custom Security Questions (KBA)(https://plugins.miniorange.com/how-to-setup-custom-security-questions-kba-from-wordpress-wp-2fa)

* customizable account name in Google Authenticator app(https://plugins.miniorange.com/how-to-setup-customize-plugin-name-wordpress-2fa)

* [Enable Two-Factor Authentication - 2FA/OTP for specific Users/User Roles](https://plugins.miniorange.com/how-to-enable-role-based-2fa-for-wordpress-two-factor-authentication#stepc)

* [RBA & Trusted Devices Management](https://plugins.miniorange.com/how-to-set-remember-device-with-two-factor-authentication-2fa),

* [White Labeling](https://plugins.miniorange.com/wordpress-two-factor-authentication-setup-guides#) 

* [Short Codes](https://plugins.miniorange.com/wordpress-two-factor-authentication-setup-guides#)

* [Session restriction](https://plugins.miniorange.com/wordpress-two-factor-authentication-setup-guides#)

* **[Multiple Login Options](https://docs.miniorange.com/documentation/login-username-2nd-factor-2)

** Username + password + two-factor (or) Username + two-factor i.e. [Passwordless login](https://plugins.miniorange.com/how-to-setup-custom-shortcode-wordpress-2fa)

* **Two-Factor Authentication** - 2FA for Ajax login forms like User Pro, [login with ajax](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-login-with-ajax-form), [Theme my login](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-theme-my-login-form), etc 

* **[Passwordless login](https://plugins.miniorange.com/how-to-enable-enforce-2-factor-registration-for-users-at-login-time-wordpress-2fa)**

* **[Prevent account sharing](https://security.miniorange.com/restricting-users-from-sharing-their-login-credentials/):** 
Google Authenticator - The 2FA plugin allows the admin to restrict users from sharing WordPress login credentials. The Google Authenticator plugin also adds a session control feature that limits user sessions based on WordPress User activities

= User Identity Verification with Google Authenticator =
**Login and Registration:** Verify users on login with different TOTP login methods & other OTP/2FA methods like [OTP login using SMS], [OTP login using Email], [OTP over Telegram], [Google Authenticator], SMS Verification, [Email Verification], [Authy Authenticator], [Duo Authenticator], [Microsoft Authenticator], [Security Questions], and many others. OTP authentication can be done via either of the [OTP Login](https://plugins.miniorange.com/wp-2fa-otp-based-2fa-methods) methods (OTP login using Email or via OTP login using SMS).

= Plugin Integrations and Support for all “two-factor authentication methods” - 2FA =
Our Google Authenticator plugin is compatible with [popular plugins](https://plugins.miniorange.com/2-factor-authentication-for-wordpress-wp-2fa#integrations) such as:-

*[WooCommerce](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-woocommerce-login-form)
* [Ultimate member](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-ultimate-member-login-form)
* [User Registration](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-user-registration-login-form)
* [Restrict Content Pro](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-restrict-content-pro-login-form) 
* [Login Press](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-login-press-login-form)
* [Registration Magic](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-registrationmagic-form) 
* [Admin Custom Login](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-admin-custom-login-form)
* [Buddy Press](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-buddypress-login-form)
* [Theme My Login](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-theme-my-login-form)
* [Elementor Pro](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-elementor-pro-login-form)
* [Profile Builder](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-profile-builder-login-form)
* [Login With Ajax](https://plugins.miniorange.com/two-factor-authentication-2fa-mfa-for-login-with-ajax-form) and many more.


= Third-Party Custom SMS Gateway for OTP Over SMS - OTP Login  =
The premium Google Authenticator - 2FA plugin supports any third-party **custom SMS Gateway**. If you don't have your SMS gateway you can use the miniOrange gateway and send SMS - OTP over SMS for authentication.
[Here](https://plugins.miniorange.com/sms-email-gateways-supported-by-2fa-plugin) are some famous gateways supported for two-factor - 2FA/OTP.
[Test your gateway](https://login.xecurify.com/moas/login?redirectUrl=https://login.xecurify.com/moas/admin/customer/smsconfig)

= Why do you need to register for Google Authenticator? =
Google authenticator - The 2FA plugin uses miniOrange APIs to communicate between your WP and miniOrange. To keep this communication secure, we ask you to register and assign API keys specific to your account. This way your account and users’ calls can be only accessed by API keys assigned to you.

However, you can use most of the 2FA methods without registration but you must register yourself to use:-
OTP Over SMS
miniOrange Authenticator

= Useful blog posts about two-factor authentication - 2FA plugin =
* [Beginner’s Guide: How to Add Two-Factor Authentication to WordPress](https://themeisle.com/blog/how-to-add-two-factor-authentication-to-wordpress/)
* [How to Add WordPress Two-Factor Authentication 2FA](https://phppot.com/wordpress/how-to-add-wordpress-two-factor-authentication-2fa-using-google-authenticator-plugin/)
* [How to translate WordPress Two-Factor Authentication - 2FA](https://plugins.miniorange.com/the-plugin-translate-spanish-language-with-2-factor-wordpress)
* [Simple method to add Two-Factor Authentication in WordPress](https://wpastra.com/two-factor-authentication-wordpress/)
* [WordPress two-factor authentication – How to Setup 2FA](https://www.fixrunner.com/wordpress-two-factor-authentication/)
* [OTP over WhatsApp](https://plugins.miniorange.com/login-with-whatsapp-as-a-two-factor-method-for-wordpress?utm_source=wordpress&utm_medium=readme+link&utm_campaign=last+June)

Customized solutions and Active support are available. Email us at info@xecurify.com or call us at +1 9786589387.

== Installation ==

= From your WordPress dashboard =
1. Navigate to `Plugins > Add New` from your WP Admin dashboard.
2. Search for `miniOrange 2 Factor Authentication - 2FA`or `Google Authenticator.`
3. Install `miniOrange 2 Factor Authentication - 2FA` and activate the plugin.

= From WordPress.org =
1. Search for `miniOrange 2 Factor Authentication - 2FA` and download it.
2. Unzip and upload the `miniorange-2-factor-authentication - 2FA` directory to your `/wp-content/plugins/` directory.
3. Activate miniOrange 2 Factor Authentication - 2FA from the Plugins tab of your admin dashboard.

**Video Guide** :
[youtube https://youtu.be/_nkMCkxLcIs]

== Frequently Asked Questions ==

= How do I gain access to my website if I get locked out using the Google Authenticator? =

You can obtain access to your website by one of the below options:

1. If you have an additional administrator account whose Two-Factor - 2FA is not enabled yet, you can log in with it.
2. If you had set up KBA questions earlier, you can use them as an alternate method to log in to your website instead of 2FA.
3. Rename the plugin from FTP - this disables the Google Authenticator -- 2FA plugin and you will be able to login with your WordPress username and password.

For detailed information, Please check on our website. <a href="https://faq.miniorange.com/knowledgebase/how-to-gain-access-to-my-website-if-i-get-locked-out/" target="_blank">Locked Out</a>.<br>
You can also check our video Tutorial:
[youtube https://www.youtube.com/watch?v=wLFKakQkpk8]

= How do I enable Google Authenticator 2 Factor authentication - 2FA as the backup method? =

You can use Google Authenticator as the backup method for your specific user or all users in the premium version of the two-factor authentication. [PREMIUM FEATURE]

= I have enabled Two-Factor Authentication - 2FA for all users, what happens if an end-user tries to log in but has not yet registered? =

If a user has not set up Two-Factor yet, the user has to register by inline registration which will be invoked during the login.

= I want to enable only one authentication method for my users. What should I do? =

You can select the two-factor authentication methods under the Login Settings tab. The selected authentication methods will be shown to the user during inline registration for example if you select Google Authenticator it will be shown on login. [PREMIUM FEATURE]

= I have a custom/front-end login page on my site and I want the look and feel to remain the same when I add 2 factor. =

If you have a custom login form other than wp-login.php then we will provide you the shortcode. Shortcode will work only for the customized login page created from WordPress plugins. We are not claiming that it will work with all the customized login pages. In such a case, custom work is needed to integrate two-factor with your customized login page. You can submit a query in our <b>Support Section</b> in the plugin or you can contact us at info@xecurify.com for more details.

= If you are facing any issues while logging in with our Google Authenticator plugin or there is a conflict with any other plugin.  =

Our Google Authenticator plugin is compatible with most of the popular plugins, but if it is not working for you, please submit a query in our Support Section in the plugin or you can contact us at info@xecurify.com.

= If you are using any render-blocking javascript and CSS plugin like Async JS and CSS Plugin and you are not able to login with Two-Factor or your screen goes blank. =

If you are using Async JS and CSS Plugin. Please go to its settings add jQuery to the list of exceptions and save settings. It will work. If you are still not able to get it right, Please submit a query in our Support Section in the plugin or you can contact us at info@xecurify.com.

= I am upgrading my phone. =

You should go to <b>Setup Two-Factor 2FA </b> Tab and click on <b>Reconfigure</b> to reconfigure 2 Factor with your new phone.

== Screenshots ==

1. Google Authenticator (WP 2FA/OTP) - Setup Google Authenticator
2. Google Authenticator (WP 2FA/OTP) - Test configured 2-factor
3. Google Authenticator (WP 2FA/OTP) - Setup OTP Over Telegram
4. Google Authenticator (WP 2FA/OTP) - Setup OTP Over SMS
5. Google Authenticator (WP 2FA/OTP) - Enable login with all configured methods
6. Google Authenticator (WP 2FA/OTP) - How to install the Google Authenticator plugin?
7. Google Authenticator (WP 2FA/OTP) - Log in using QR authentication
8. Google Authenticator (WP 2FA/OTP) - Log in using a soft token
9. Google Authenticator (WP 2FA/OTP) - Log in using Push notification
10. Google Authenticator (WP 2FA/OTP) - miniOrange User Account
11. Google Authenticator (WP 2FA/OTP) - Remember device and white labeling add-ons

== Changelog ==

= 5.8.1 =
* Bug Fix- Show backup codes to users after configuring Email Verification
* Updated UI for Google Authenticator user configuration screens
* Updated UI of Setup Wizard

= 5.8 =
* Bug fix- 2FA method was getting updated when updating a user on user-edit page
* Updated UI for OTP over SMS, OTP over Email and OTP over Telegram configuration screens
* Added Email Varification authentication method

= 5.7.5 =
* Compatibility with WordPress 6.4

= 5.7.4 =
* Bug fix- Keep end users' 2FA configuration when the plugin is deactivated
* Bug fix- Attempts left for the OTP-based methods
* Bug fix- Display App Key for Google authenticator in 2FA inline registration

= 5.7.3 =
* Bug fixes for registration forms
* Compatibility with WordPress 6.3

= 5.7.2 =
* Updated flow of 2FA on registration form
* Minor bug fixes

= 5.7.1 =
* Bug fix - Users will be able to configure/reconfigure and reset cloud methods
* Bug fix - SMS Transactions will be credited when customers register in the plugin
* Bug fix - Fixed Email Transaction sync issue
* Added Resend OTP Button in case of OTP Over SMS, OTP over Telegram, OTP over Email methods
* Improvement - Enforced reconfiguration of the alternate method after login with backup code
* Feature Improvement - The 2FA prompt will be visible in case of TOTP method has not been set for the admin
* Updated plugin dashboard UI - Added My Account tab for miniOrange User Account

= 5.7.0 =
* Code Improvements according to WPCS
* Feature Improvement - Added role-based checks for login through new IP
* Improvement - Error handling for account creation

= 5.6.6 =
* Google Authenticator - Two-factor Authentication - 2FA, OTP :
* Bug fix - redirection issue for users in a Multisite environment
* Improvements - Removed External links from Google Authenticator
* Improvements - Mobile responsiveness of setup wizard
* Improvement for SMS/Email verification on the PaidMembership Proform
* Updated Pricing plan according to new use cases 
* Updated Add SMS notification/button check
* Updated feedback form
* Advertised OTP over WhatsApp

= 5.6.5 =
* Google Authenticator - Two-factor Authentication - 2FA, OTP :
* Bug fix - Save template for notifications on email
* Bug fix - Error in SMS authentication setup through plugin dashboard
* Updated Network Security removal notice message

= 5.6.4 =
* Google Authenticator - Two-factor Authentication - 2FA, OTP :
* Bug fix - headers already sent in messages.php

= 5.6.3 =
* Google Authenticator - Two-factor Authentication - 2FA, OTP :
* Skip-2 factor option removed from the inline setup
* Backup code button will always be shown
* Added login form and theme fields in the trial request form
* CSS-JS version added for all scripts and styles respectively
* Autofocus for many input fields and submit the form when Enter is hit

= 5.6.2 =
* Google Authenticator - Two-factor Authentication - 2FA, OTP :
* Vulnerability fixes
* Removed Network Security for new users
* Updated Pricing page UI

= 5.6.1 =
* Google Authenticator - Two-factor Authentication 2FA, OTP :
* Bug fix- Headers already sent
* Added SMTP check for sending backup codes on 2fa prompt 

For older changelog entries, please see the [additional changelog.txt file](https://plugins.svn.wordpress.org/miniorange-2-factor-authentication/trunk/changelog.txt) provided with the plugin.

== Upgrade Notice ==

= 5.8.1 =
* Bug Fix- Show backup codes to users after configuring Email Verification
* Updated UI for Google Authenticator user configuration screens
* Updated UI of Setup Wizard

= 5.8 =
* Bug fix- 2FA method was getting updated when updating a user on user-edit page
* Updated UI for OTP over SMS, OTP over Email and OTP over Telegram configuration screens
* Added Email Varification authentication method

= 5.7.5 =
* Compatibility with WordPress 6.4

= 5.7.4 =
* Bug fix- Keep end users' 2FA configuration when the plugin is deactivated
* Bug fix- Attempts left for the OTP-based methods
* Bug fix- Display App Key for Google authenticator in 2FA inline registration

= 5.7.3 =
* Bug fixes for registration forms
* Compatibility with WordPress 6.3

= 5.7.2 =
* Updated flow of 2FA on registration form
* Minor bug fixes

= 5.7.1 =
* Google Authenticator - Two-factor Authentication - 2FA, OTP :
* Bug fix - Users will be able to configure/reconfigure and reset cloud methods
* Bug fix - SMS Transactions will be credited when customers register in the plugin
* Bug fix - Fixed Email Transaction sync issue
* Added Resend OTP Button in case of OTP Over SMS, OTP over Telegram, OTP over Email methods
* Improvement - Enforced reconfiguration of the alternate method after login with backup code
* Feature Improvement - The 2FA prompt will be visible in case of TOTP method has not been set for the admin
* Updated plugin dashboard UI - Added My Account tab for miniOrange User 
