Linux 软件免费装
Banner图

Passwordless X1280

开发者 passwordlessalliance
更新时间 2026年7月28日 12:25
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

security login authentication passwordless webauthn

下载

1.0.2

详情介绍:

Passwordless X1280 integrates WordPress with the X1280 Passwordless Authentication Server, enabling secure passwordless login through the biometric capabilities already built into your users' smartphones — Face ID and fingerprint recognition — based on the ITU-T X.1280 international standard. Forget passwords, password resets, and phishing risks. Instead of asking users to type a password, your site presents an automatic password that users simply verify and approve in the Passwordless X1280 mobile app. Why Passwordless X1280? How It Works Unlike traditional login systems where only the user is authenticated, X.1280 introduces mutual authentication:
  1. The WordPress login page displays a unique auto-password.
  2. The user checks that the same auto-password appears in the Passwordless X1280 mobile app.
  3. After confirming the service identity, the user approves the login with smartphone biometrics.
  4. Authentication completes securely — no password is typed or transmitted.
This ensures users are communicating with the legitimate website before any authentication takes place. Key Features Automatic Page Creation Upon activation, the plugin automatically creates the following pages: Both pages can be edited or reassigned from the WordPress admin panel if needed. Security Requirements External Services This plugin connects to an external service to enable passwordless authentication. Purpose: the service processes passwordless authentication requests using WebAuthn (passkeys). Data sent: Data received: When data is sent: About the Passwordless Alliance The Passwordless Alliance is a non-profit organization headquartered in Geneva that distributes Passwordless X1280 software free of charge to B2C online services worldwide. The underlying technology is standardized by the ITU-T as Recommendation X.1280.

安装:

  1. Upload the passwordless-x1280 folder to the /wp-content/plugins/ directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the Plugins menu in WordPress.
  3. Go to Dashboard → Passwordless X1280 and configure the following: Server Key (provided by X1280), Authentication Server Domain (port 11040), Push Server Domain (port 15010), and, optionally, disable password-based login.
  4. Ask your users to install the Passwordless X1280 mobile app and register their account on the automatically created Register / Unregister page.
  5. Log in through wp-login.php or the generated login page using the Passwordless option.

升级注意事项:

1.0.2 Initial stable release.

常见问题:

Is Passwordless X1280 free?

Yes. Passwordless X1280 is provided free of charge by the non-profit Passwordless Alliance for B2C (consumer-facing) online services worldwide. It is not licensed for internal systems whose users are employees, contractors, or agents of the operating organization. The companion mobile app is free for users and ad-supported, which is how the Alliance funds free distribution.

What do my users need?

A smartphone with the free Passwordless X1280 mobile app installed (App Store / Google Play). Biometric verification uses the phone's own Face ID or fingerprint sensor, so no extra hardware is needed on PCs or other devices. A single app can manage passwordless login for multiple online services.

Where do I get a Server Key?

Register (free of charge) as a Service Member of the Passwordless Alliance and submit a passwordless service application; a license key is issued after verification. For testing purposes, select "testing" as the purpose of use when applying and a key is issued automatically, although domain linking is not supported for test keys. See Become a member for details. The X1280 server application itself is distributed via Docker Hub.

Does my site need HTTPS?

Yes. WebAuthn only works on sites served over HTTPS, so a valid SSL/TLS certificate is required.

Can users still log in with a password?

Yes. By default, the standard password login remains available alongside the passwordless option on wp-login.php. Administrators can disable password-based login from the plugin settings if they want passwordless-only authentication.

What if a user loses or replaces their phone?

If password login is enabled, the user can regain access through WordPress's standard password recovery, then unregister the old device and register the new smartphone on the Register / Unregister page ([px1280_manage]).

Does the plugin modify WordPress core files?

No. It uses standard WordPress hooks only, and it is compatible with multisite environments as well as common caching and security plugins.

更新日志:

1.0.2