Linux 软件免费装
Banner图

FluentAuth - Login Security, Two-Factor Authentication, Passkeys & Social Login

开发者 techjewel
wpmanageninja
adreastrian
更新时间 2026年10月7日 04:11
PHP版本: 7.3 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security login two factor authentication social login limit login attempts

下载

3.0.5 1.0.2 1.0.7 2.1.2 3.0.1 1.0.4 1.0.5 1.0.6 1.1.0 1.0.8 2.0.2 2.0.3 1.0.0 2.0.1 2.1.0 3.0.0 3.0.2 1.0.1 1.0.3 2.0.0 2.1.1 3.0.3 3.0.4

详情介绍:

FluentAuth is a login security plugin for WordPress. It protects the way people sign in to your site, and it tells you when something on your site has changed. You get two-factor authentication, passkeys, social login, magic login links, login attempt limits, IP access rules, a security checklist, file change scanning and a full audit log. All of it in one plugin, with no bloat and no slowdown. Highlighted Features [youtube https://www.youtube.com/watch?v=Tt9LHwHySmA] Two-Factor Authentication (2FA) Ask for a second step after the password. Three ways to do it, and you choose which roles may use each one. You can let a role set up a second factor or require it, and you choose how strong a required one has to be: a device factor only, meaning a passkey or an authenticator app, or any of the three. Anyone who must have one sets it up while they sign in, before a session is created for them, so the requirement cannot be walked past. An authenticator app also hands out ten single use recovery codes, and passkey users can fall back on those too. Everyone manages their own second factor from their WordPress profile screen, and an admin screen lists who has enrolled, what each person registered, and lets you reset anyone locked out. Authenticator secrets can be encrypted in your database with a key you keep in wp-config.php, so reading the database gets an attacker nothing. Passkey Login Passkeys are the strongest option here. The credential lives on the device and is bound to your domain by the browser, so phishing does not work against it: a copied login page has a different domain and the passkey will not answer. They can be the second step after a password, or the way in on their own - turn on passkey sign-in and the login form offers a button that signs the user in with no password at all. No third party service is involved: everything runs on your site. Social Login and Registration Let people sign in with the accounts they already have. Turn on the providers you want, paste the keys, and the buttons appear on your login and register forms. You can also stop social sign ups when registration is closed on your site. Magic Login by Email Users type their email address and get a one time login link. No password to remember and no reset flow to walk through. Make it the main way people sign in, or keep it as an extra option. Links are hashed, expire, are rate limited and can only be claimed once, and asking for a link never reveals whether an address has an account on your site. Limit Login Attempts Block brute force attacks by counting failed logins. Set how many attempts are allowed and over how many minutes, and FluentAuth locks the address out for a while. Every blocked attempt is logged, and you can be emailed when it happens. IP Allow List and Block List Two simple lists, one address or range per line. The block list refuses a login from those addresses outright. The allow list skips the attempt limit for addresses you trust, such as your office. You can also require that a role only signs in from an allow listed address. FluentAuth detects reverse proxies and Cloudflare, so the address it acts on is the real visitor address and not your proxy. Security Checklist FluentAuth checks your site and gives you a short list of what to look at. Each item says what is wrong, why it matters and what happens if you fix it, and most have a button that fixes it for you. Anything that does not apply can be waved away, and you can take that back later. It checks things like: File Change Scanning FluentAuth compares your files against the official copies published on WordPress.org. When a file has changed you can see a side by side diff against the original, put the original back with one click, or delete a file that should not be there. You can also flag a plugin or theme running a version that was never published, a common sign that files were swapped out. Activity and Audit Logs FluentAuth records every login, failed attempt and blocked address, and every plugin or theme activated, deactivated or updated, with who did it. Logs go in their own database tables, so your WordPress tables stay clean, and old entries are cleared on a schedule you pick. Email Notifications and Reports Get an email when an administrator or editor signs in, or when someone is blocked for too many failed attempts. You can also get a daily, weekly or monthly summary of what happened on your site. Recovery Tools If you think somebody has been in your site, one screen tells you what to do next. Everything done here is written to the audit log with the name of the person who did it. Login Redirects Send users to different pages after they log in or log out, based on their role. Set it up once and it applies to every login method, including social and magic login. Login and Signup Page Customizer Set your own logo, colours, background and form style on the WordPress login page, and see the result as you edit. You can also build login and registration forms anywhere on your site with shortcodes. Custom WordPress System Emails WordPress sends a lot of plain default emails. FluentAuth lets you rewrite them with your own wording and branding, and gives you one template design they all share. You can also turn off the admin notification that fires every time a new user signs up. Core Security Hardening Turn off the parts of WordPress your site does not use. Remote Auth for Multiple Sites Use one site as the login provider for your other sites. Users sign in once on the main site and land on the child site already logged in. Guided Setup A short setup wizard runs the first time you open FluentAuth. It asks a handful of questions, shows you what each answer changes, and turns on a sensible set of options. Skip it and nothing is written, and every answer is an ordinary setting you can change later. Built to Be Fast FluentAuth is one plugin doing the work of several, written to stay out of the way. The admin area is a single page Vue 3 app over the REST API, logs live in custom database tables, and no scanning agent sits in front of every request on your site. For Developers Another plugin can put its own login screen on FluentAuth's flows. It registers with the LoginBridge service, and from then on its custom form gets the attempt limits, the IP rules and the two-factor challenge, including an inline second step on a custom AJAX action. There are filters through the whole auth flow, and the site owner's settings always win over what an adopting plugin asks for.

安装:

This section describes how to install the plugin and get it working.
  1. Search for FluentAuth in WordPress Plugins, then click install and activate.
OR
  1. Upload the plugin files to the /wp-content/plugins/fluent-auth directory, or install the plugin through the WordPress plugins screen.
  2. Activate the plugin through the 'Plugins' screen in WordPress.
  3. Go to FluentAuth and follow the short setup wizard, or open FluentAuth -> Settings to configure it yourself.

屏幕截图:

  • Login Security Settings
  • Passkey, Authenticator App and Email Two-Factor Authentication
  • Custom Login/Signup Shortcodes
  • Dynamic Login Redirects
  • Detailed Audit Logs
  • Social Login Settings
  • System Emails Customization
  • Login/Signup Page Customizer
  • WordPress Core Files Integrity Check
  • Account and File Recovery Tools
  • Passkey Sign-In Without a Password
  • Security Checklist With One-Click Fixes

升级注意事项:

3.0.0 A major release. Adds passkey sign-in and passkey two-factor authentication, authenticator app two-factor authentication, a security checklist, plugin and theme file scanning, IP access rules and recovery tools. Your existing settings carry over, and a role you had already marked as requiring a second factor keeps exactly the meaning it had before.

常见问题:

Is FluentAuth free?

Yes. Every feature described here is free. There is no paid version and no locked screens.

Does it slow my site down?

No. FluentAuth does not sit in front of every request the way a firewall plugin does. Logs are kept in their own database tables, so your WordPress tables stay small, and the admin area is a single page app that loads once.

Does two-factor authentication work with Google Authenticator?

Yes. The authenticator app option works with Google Authenticator, Authy, Microsoft Authenticator, 1Password, Bitwarden and any other app that supports TOTP.

What is a passkey?

A passkey lets someone sign in with Touch ID, Face ID, Windows Hello, a hardware security key or a password manager instead of typing a code. The browser ties it to your site's domain, so it cannot be used on a fake copy of your login page. FluentAuth supports passkeys as a second factor, and as a way to sign in on their own with no password at all.

Can I force two-factor authentication for administrators?

Yes. You can pick which roles may set up a second factor and which roles must have one. A user who must have one is asked to set it up while they sign in, before a session is created for them, so the requirement cannot be walked past by going straight to a page that is not the login form. You can also say how strong that factor has to be: a device factor only, meaning a passkey or an authenticator app, or any of the three including an emailed code.

Do I have to connect to an external service?

No. Two-factor authentication, passkeys, audit logs, login limits and the rest all run on your own site. Two things do reach out. Scanning asks WordPress.org for the official copy of your files, which is how it can tell whether a file changed, and it sends nothing about your site to do that. And there is an optional FluentAuth Alerts Service that handles scheduled scans and alert emails. It is off until you connect it, and the screen lists what would be sent before you decide. See the External Services section above.

Is it GDPR compliant?

Yes. All of your data stays in your WordPress database unless you choose to connect the optional alerts service, and what that sends is listed above in the External Services section.

Does it work with WooCommerce and membership plugins?

Yes. FluentAuth works on the standard WordPress login, so it covers logins from WooCommerce, LearnDash, membership plugins and custom login forms.

Can I use it on a multisite install?

Yes. FluentAuth runs per site on a multisite install, and it is aware of multisite when it decides whether a user may sign in to a given site. There is no network wide settings screen, so each site is configured on its own.

What happens if I lock myself out?

Use one of the recovery codes you were given when you set up your authenticator app. If you have lost those too, another administrator can reset your second factor from the 2FA Enrollment screen. If you are the only administrator and everything is gone, add define('FLUENT_AUTH_DISABLE_TWO_FA', true); to your wp-config.php and the second factor is lifted for the whole site. Put a username in place of true to lift it for that one account only. Take the line out once you are back in. While it is there the login screen says so, the dashboard warns you, and every sign-in that used it is written to the audit log.

Does the file scanner remove malware?

It is not a malware scanner. It tells you which files no longer match the official copy published on WordPress.org, shows you what changed, and lets you put the original back. That catches the file changes an attacker leaves behind, and it does it without a signature list to keep up to date.

更新日志:

3.0.5 - Date: Oct 7, 2026 3.0.4 - Date: Oct 2, 2026 3.0.3 - Date: Sep 20, 2026 3.0.2 - Date: Sep 18, 2026 3.0.1 - Date: Sep 17, 2026 3.0.0 - Date: Sep 16, 2026 2.1.2 - Date: Apr 28, 2026 2.1.1 - Date: Dec 03, 2025 2.0.3 - Date: Jun 11, 2025 2.0.2 - Date: Jun 11, 2025 2.0.0 - Date: Jun 09, 2025 1.1.0 - Date: Dec 16, 2014 1.0.8 - Date: Dec 02, 2024 1.0.7 - Date: Jul 26, 2024 1.0.6 - Date: Jan 28, 2024 1.0.5 - Date: May 04, 2023 1.0.4 - Date: Feb 04, 2023 1.0.2 - Date: Dec 17, 2022 1.0.2 - Date: Dec 16, 2022 1.0.0 - Date: Dec 12, 2022